this post was submitted on 27 Aug 2026
5 points (77.8% liked)
Self Hosted - Self-hosting your services.
20838 readers
2 users here now
A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.
Rules
- No harassment
- crossposts from c/Open Source & c/docker & related may be allowed, depending on context
- Video Promoting is allowed if is within the topic.
- No spamming.
- Stay friendly.
- Follow the lemmy.ml instance rules.
- Tag your post. (Read under)
Important
- Lemmy doesn't have tags yet, so mark it with [Question], [Help], [Project], [Other], [Promoting] or other you may think is appropriate. This is strongly encouraged!
Cross-posting
- !everything_git@lemmy.ml is allowed!
- !docker@lemmy.ml is allowed!
- !portainer@lemmy.ml is allowed!
- !fediverse@lemmy.ml is allowed if topic has to do with selfhosting.
- !selfhosted@lemmy.ml is allowed!
If you see a rule-breaker please DM the mods!
founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Not really. I mean it does the job, it's a real AV that will catch malware, but it's not a modern product. Its primary use is for corporations needing to meet a "you must have antivirus" compliance requirement.
The best defense against Linux malware is reviewing stuff before you run it. And not running random stuff as root. And not piping curl/wget to bash, especially not sudo bash.
And of course don't expose stuff to the Internet unless you have to. And if you do, isolate each service, so that an attacker can't pivot once they're in your network.
When I switched to Linux, I encased my computer in carbonite. Made it immutable and impenetrable, in one go!
what isolation is? is something like containerization (docker)sorry im noob. ty
yes like that. you set up your network and permissions and access in a whitelist so that your service can strictly only manipulate what's needed.
as in if it only needs access to these directories, or these endpoints that's all it's gonna get.
Network isolation. Internet-facing services should be in a DMZ, and unable to talk to each other unless specifically allowed.
Containerization is good too, but not a substitute.