chaplin2@alien.topBtoSelf-Hosted Main@selfhosted.forum•Worst case scenario after an attackEnglish
1·
1 year agoYou are doing it wrong: SSH with key authentication is the most secure piece, and could even be public. Immich and Jellyfin surely have zero days and should be behind VPN
I’m referring to ZERO DAYs. OpenSSH is a serious security product. Those web apps are written by random people and probably riddled with vulnerabilities not known to public.
Here is the rule. Only a trusted vpn and ssh key authentication can be public.