42

cross-posted from: https://infosec.pub/post/10908807

TLDR:

If I use SSH as a Tor hidden service and do not share the public hostname of that service, do I need any more hardening?

Full Post:

I am planning to setup a clearnet service on a server where my normal "in bound" management will be over SSH tunneled through Wireguard. I also want "out of bound" management in case the incoming ports I am using get blocked and I cannot access my Wireguard tunnel. This is selfhosted on a home network.

I was thinking that I could have an SSH bastion host as a virtual machine, which will expose SSH as a a hidden service. I would SSH into this VM over Tor and then proxy SSH into the host OS from there. As I would only be using this rarely as a backup connection, I do not care about speed or convenience of connecting to it, only that it is always available and secure. Also, I would treat the public hostname like any other secret, as only I need access to it.

Other than setting up secure configs for SSH and Tor themselves, is it worth doing other hardening like running Wireguard over Tor? I know that extra layers of security can't hurt, but I want this backup connection to be as reliable as possible so I want to avoid unneeded complexity.

you are viewing a single comment's thread
view the rest of the comments
[-] someonesmall@lemmy.ml 6 points 2 years ago

30 character password + fail2ban after one failed attempt. Why not?

[-] AbidanYre@lemmy.world 3 points 2 years ago
[-] someonesmall@lemmy.ml 0 points 2 years ago
[-] chaospatterns@lemmy.world 6 points 2 years ago

Accidentally typo your password and get blocked. And if you're tunneling over tor, you've blocked 127.0.0.1 which means now nobody can login.

[-] someonesmall@lemmy.ml 1 points 2 years ago

How would is a typo possible if one is using a password manager?

[-] baatliwala@lemmy.world 3 points 2 years ago

Not OP but I've accidentally fingered another key a split second before hitting enter a few times. It's not implausible.

[-] someonesmall@lemmy.ml 1 points 2 years ago

True, but I thought we are talking about security here...?

[-] wreckedcarzz@lemmy.world 1 points 2 years ago

30 character

You've gotta pump those numbers, those are rookie numbers. (I have a vps that has several times that figure)

[-] someonesmall@lemmy.ml 1 points 2 years ago

Did you read my message? After one failed attempt you will get banned.

[-] wreckedcarzz@lemmy.world 1 points 2 years ago

But

30 characters

:P

this post was submitted on 10 Apr 2024
42 points (93.8% liked)

Selfhosted

62801 readers
713 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

Detailed Rules Post

  1. Be civil.

  2. No spam.

  3. Posts are to be related to self-hosting.

  4. Don't duplicate the full text of your blog or readme if you're providing a link.

  5. Submission headline should match the article title.

  6. No trolling.

  7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.

  8. AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS