price's recent activity
-
Comment on What’s your preferred work monitor setup? in ~comp
-
Comment on I need a sanity check from security experts (opening ports on the router) in ~tech
price LinkSort of, pretty much by opening those ports you are allowing a hacker who knows your ip address and the port that is open an opportunity to test the security of that application exposed on that...Sort of, pretty much by opening those ports you are allowing a hacker who knows your ip address and the port that is open an opportunity to test the security of that application exposed on that port. IP addresses are always scanned for common ports. Less common ports are also scanned just at a slightly lower frequency. After scanning for ports, any discovered ports are then attempted to be exploited for very common vulnerabilities. If your application doesn’t have these vulnerabilities you are likely fine.
In direct answer to your question:
-
You give them a chance to compromise your machine if there is a known exploit. Uncommon if you are using a widely used and frequently patched software but possible. If they compromise your raspberry pi they can theoretically move across your other devices with known exploits.
-
You can segment that device on its own network and only allow traffic to come in to those ports and don’t allow anything to leave on other ports. This is kind of like a DMZ, but less secure.
-
If you want to be extra secure you should front your application with a well known application that is patched often for known exploits such as nginx. You are right to be paranoid if you don’t know the answer to these questions.
The absolute best solution here is to use a vpn and don’t open ports. This sounds like what you are doing and should continue to do. If you are using a vpn don’t open any ports because you don’t need to.
Most bad actors out there are just using common exploits that have scripts built to exploit them. If you don’t have these vulnerabilities then you are probably ok for the most part.
-
I have a 40 inch ultra wide 5k2k and it’s the best setup I have had yet. Prior setups have included: