Aussie living in the San Francisco Bay Area.
Coding since 1998.
.NET Foundation member. C# fan
https://d.sb/
Mastodon: @dan@d.sb

  • 5 Posts
  • 581 Comments
Joined 3 years ago
cake
Cake day: June 14th, 2023

help-circle
  • Makes sense! I didn’t realise it has a UI.

    I’ve got a bunch of snippets in /etc/nginx/snippets/, so for example I just need to add include snippets/proxy.conf to a server block to add most of the configuration needed for a reverse proxy. I’ve been using Nginx for long enough that I just write the rest of the server block by hand.




  • dan@upvote.autoSelfhosted@lemmy.world•Anyone using 6-day certs yet?
    link
    fedilink
    English
    arrow-up
    8
    arrow-down
    1
    ·
    edit-2
    4 days ago

    A private key leaking is bad, since anyone with the private key can decrypt data that was encrypted with it.

    Traditionally, the way that leaked certs were handled was via Certificate Revocation Lists (CRL). CRLs contain lists of revoked certificates - their serial number, revocation date, and the reason why they were revoked.

    However, CRLs are imperfect. Checking for revoked certificates every time you go to a site would slow things down a lot, as the lists are now too large to check and download real-time. Modern browsers and other TLS clients periodically download the lists in the background. Also, it might take a while between when the certificate is compromised and when the company notices the compromise.

    Because of this, the CA/Browser forum (a group with all the major browser and TLS certificate vendors) have started dropping the max lifetime of certificates. The idea is that even if a private key does leak, the time frame that it’s usable for will be significantly shorter and any leaks should (in theory) cause less damage.

    • The original maximum duration was 39 months: Three years plus an extra three months leeway for obtaining and deploying new certificates.
    • March 2018: Reduced to 825 days
    • September 2020: Reduced to 398 days
    • March 2026: Reduced to 200 days
    • March 2027: Planned to reduce to 100 days
    • March 2028: Planned to reduce to 47 days

    All modern deployments, regardless of if they’re using free or paid certs, should have their renewals fully-automated, so in theory the validity period shouldn’t matter as much as it did in the past. All major vendors (Let’s Encrypt, DigiCert, Sectigo, GlobalSign, AWS, SSL .com, etc) support ACME now. Reducing the validity is also a forcing function t o ensure automation is actually implemented.

    somehow else in the middle and just can “ignore” certs renewals?

    I’m not sure that’s possible, since an attacker in the middle shouldn’t be able to obtain a valid certificate for the domain. Certificates have a “not valid after” date encoded into them, after which the certificate is considered invalid and you get an error.



  • Makes sense! 30W is great for your system. My home server has an older 10Gbps NIC that uses an Aquantia AQC107 chip, which has poor support for ASPM and prevents the CPU from entering lower C states. I’ve been considering swapping it out for something newer (like an AQC113), I just need to work out whether it’s actually worth it.

    Mine used to cost $0 in electricity since I’ve got solar panels, but we’ve got two EVs now (my wife has a BMW iX and I’ve got an i4) so we’re back to having to pay the electricity company again.


  • Creating a cluster could help me self host more websites I create as I want to move away from using hosting services

    Just jeep an eye on electricity prices. This is probably not an issue with a phone server, but for me, hosting at home with a decent server PC costs more per month just in electricity compared to using a cheap VPS. Continuous draw of 50W 24/7 is ~37kWh per month which can cost $15 or more in California.

    I do still host some things at home, but all my sites are on VPSes. The enterprise hardware and fast, data center grade internet connection is worth it for me. Some of my VPSes are only $40/year.




  • Definitely true. The Pi 5 is especially powerful compared to older versions, but it can get kinda expensive once you add things you’d want for a server, like a case, SSD hat, etc.

    Ex-office mini and small form factor PCs (Lenovo Tiny/ThinkCentre, HP ProDesk/EliteDesk, Dell Optiplex, etc) can be a better deal than a Pi. In the US at least, you can often find 9th or 10th gen Core i5 systems for less than $150 on eBay. Works great as a server.

    A lot of companies have a 3-4 year refresh cycle, after which the hardware is fully depreciated (essentially meaning its value to the company is $0) and they have e-waste companies collect them. The e-waste recyclers test them, refurbish the ones that still work, and list them on marketplaces like eBay.


  • I forgot to mention - stay far away from SSDNodes. Their prices look good, but they massively oversell their RAM. They use ballooning (virtio_balloon) to overallocate RAM, and require you to use their customized Linux distro images that have it enabled. Ballooning means that they take unused RAM from your VM and lend it to other VMs to use. If you try to use all your RAM, they shut down your VPS.

    GreenCloud, HostHatch, and RackNerd all let you install whatever OS you want, by mounting an ISO, connecting to the VPS via VNC, and going through the normal setup process just like you would on a regular computer. They do have pre-built images, but I always prefer to install from my own ISO so I know that the installation doesn’t have any non-standard modifications.

    Thankfully, most VPS providers don’t oversell RAM or disk space.




  • I use GreenCloudVPS for a bunch of things. They used to have VPSes starting at $15/year for 2GB RAM and 20GB disk, but their current budget deals are still good (starts at $25/year for 4GB RAM and 35GB disk). These are on older hardware (mostly AMD EPYC Rome Zen 2 systems, ~5 years old) which is why they haven’t been affected by increased RAM and storage prices yet. https://greencloudvps.com/billing/store/budget-kvm-sale

    They also have “premium” plans which are newer (AMD EPYC Milan Zen 3 or Genoa Zen 4, and PCIe 4.0 NVMe storage in RAID10): https://greencloudvps.com/billing/store/premium-kvm-sale

    HostHatch is good too. Their regular pricing aims to compete with Hetzner, but in 13 locations worldwide. https://hosthatch.com/products. They do sometimes have sales on LowEndTalk with pricing similar to GreenCloud’s “premium” plans.

    RackNerd sometimes have good deals, although they’ve discontined quite a few of them recently. You can use https://racknerdtracker.com/ to see currently active deals. I still see a 2GB RAM + 35GB storage deal for $35/year for example.

    I suspect all the very cheap ones (<$50/year) will eventually increase pricing. GreenCloud and HostHatch own all their hardware. Right now they use older hardware that’s already reached break-even, but all hardware needs to be replaced eventually, and the replacement cost for things like enterprise SSDs is a lot higher than it was in the past.


    If you want to stick to big names, OVHcloud and Hetzner both have pretty good VPS pricing. OVH runs theirs on very old hardware like Haswell (2014/2015 era) Xeon E5 CPUs which is the main reason why they have cheaper pricing that Hetzner.

    There’s also AWS Lightsail that’s essentially Amazon’s version of a VPS. Storage and data transfer are included in the monthly price, unlike EC2 where it costs extra. I’d only use it if you like AWS or want the comfort of using a very big company though - performance is notably worse than a provider like GreenCloudVPS or Hetzner.


    I’m not affiliated with any of these companies. This is just my personal experience :)




  • Do you want to run TensorFlow Lite / LiteRT models? PyTorch Mobile? TensorRT? onnx? YOLO? vLLM? Something else? The recommendations will vary based on your use case.

    Google Coral was decent for TensorFlow Lite, but it’s EOL (end of life) now. I’ve got the dual TPU Mini PCIe version in my home server, via a PCIe adapter board. I use it for object detection with Blue Iris + CodeProject AI and it works pretty well for that use case.

    Hailo-8 is supposed to be like a more powerful version of the Coral, but I don’t have experience with it. It supports a bunch of frameworks: TensorFlow, TensorFlow Lite, Keras, PyTorch and ONNX. I’d be interested in hearing other people’s thoughts on it.

    I don’t know if any of these work over USB though. They’re usually internal devices. Google marketed the Coral USB as being for development and testing only, pointing people to the M.2 and PCIe versions for production usage.

    As for something totally different… There’s the Nvidia Jetson single board computer which supports TensorRT, but I don’t have experience with it either. I also think it’s a bit older too. You could also consider getting a newer mini PC with a AMD Ryzen AI processor in it, or an Nvidia DGX Spark.

    Google’s latest TPUs are only available in their cloud - they’re not selling the hardware to end users any more.


  • And I don’t ever know if it’ll get better because you need to know why you want to build something someway.

    The major issue I’m seeing with junior (and even intermediate) developers is that they trust that the AI will always do things the correct way and don’t question its approach, and they don’t develop proper debugging skills and just rely on the AI to attempt it.

    To get decent quality output out of an AI model, you need to have critical thinking skills, at least basic knowledge of the overall architecture for whatever you’re trying to build, and enough knowledge to question the model when it does something wrong.

    Blindly trusting AI is why so many old security issues are coming back - stored/reflected XSS, SQL injection, exposing databases directly to the internet with no password, things like that. Newer frameworks mostly got rid of them, and now AI is bringing them back. It’s a fun time for red teams at least.