Hello all! I’ve been getting into self-hosting stuff and ran into an issue with port forwarding my services to the internet. I don’t have access to my router’s config (provided by ISP), so I researched tunnels and there is ngrok, Cloudflare Tunnel and other more well-known reverse proxy services, but I also stumbled upon loophole.cloud. I can’t find more information about it except a few Reddit comments here and there. Has anyone here actually used it and can say a few words about it?

  • ikidd@lemmy.world
    link
    fedilink
    English
    arrow-up
    5
    ·
    1 day ago

    Use tailscale and keep your services behind the VPN. Opening up your services, even behind a tunnel, isn’t a thing you should get into early in your self-hosting journey.

    • uzay@infosec.pub
      link
      fedilink
      English
      arrow-up
      1
      ·
      21 hours ago

      This. There’s plenty of stuff that can go wrong just exposing your stuff to the open internet.

  • irotsoma@lemmy.blahaj.zone
    link
    fedilink
    English
    arrow-up
    4
    ·
    1 day ago

    It’s just a hosted reverse proxy with a proprietary server backend, as far as I can tell. I don’t usually trust “free” things lime that. It’s not that expensive to do it yourself, the real expense come in high bandwidth flowing through the proxy which most self hosted applications for personal use don’t really do.

    Anyway, with a reverse proxy on the security end there’s a chance of man in the middle attacks depending on the configuration. And on the privacy end, they will have the ability to log all connections. That may be where they’re planning to make money by selling that info and/or allowing MiTM attacks to inject ads like many ISPs have talked about. But “free” stuff usually isn’t actually free in the long term even if it is now while it’s being tested. Usually just takes a sale to a large corporation for it to become less free even of the original intent wasn’t to do that.

    • blamster19@programming.devOP
      link
      fedilink
      English
      arrow-up
      3
      ·
      1 day ago

      Thank you, you brought up a good point about them selling data. What alternatives do you suggest to expose my service to the internet for personal use away from home?

      • irotsoma@lemmy.blahaj.zone
        link
        fedilink
        English
        arrow-up
        3
        ·
        1 day ago

        If you want something similar, you could set up a cheap VPS with your own reverse proxy making sure that all of your connections are secure between the servers and VPS. But it really depends on your situation. If you have an ISP that assigns you a block of static IPv6 addresses, it’s fairly easy to then get a domain and direct based on subdomains to those addresses. I’m not lucky enough to have a halfway decent ISP available in my area, so I can’t get that or even a reasonably priced single IPv4 address for residential service, so I have to make due with dynamic DNS which makes things more complex. I fortunately don’t have an ISP that forces double NAT on me at least. So I have set up a VPS with a reverse proxy and Wireguard VPN tunnel and I use cloudflare as my domain registrar and their DDNS which I update using my OPNSense router which is also the endpoint of the VPN. I’ve been considering moving to hosting headscale on the VPS instead, but haven’t gotten around to it. It really depends on how many servers, his many services, if you have a domain, if you have a VPS or itger server outside of your home network, if your ISP gives static IPs, and you are behind a double nat kind of situation. Also depends a lot on your bandwidth. Having low upload speeds is a common problem especially if you have cable internet service. I’m lucky enough to have symmetrical fiber direct to my modem even if the ISP is way behind and doesn’t offer IPv6 other than 6rd which was meant to be a transitional system like two decades ago and is barely functional.