this post was submitted on 03 Oct 2025
608 points (98.3% liked)
Selfhosted
60024 readers
835 users here now
A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.
Rules:
-
Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.
-
No spam.
-
Posts here are to be centered around self-hosting. Please ensure it is clear in your post how it relates to self-hosting.
-
Don't duplicate the full text of your blog or git here. Just post the link for folks to click.
-
Submission headline should match the article title.
-
No trolling.
Resources:
- selfh.st Newsletter and index of selfhosted software and apps
- awesome-selfhosted software
- awesome-sysadmin resources
- Self-Hosted Podcast from Jupiter Broadcasting
Any issues on the community? Report it using the report flag.
Questions? DM the mods!
founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
I would be interested to see a figure of people with home servers that have had that happen to them. DoS & pwned yes, especially 15+ years ago before there were good resources, TLS, reverse proxies, or authentication front ends.
I would be very interested to see any stat whatsoever of selfhosters that have gottened murdered specifically because of their server.
It is extremely important to note that in those days, people just opened their, often out-of-date, servers completely to the internet via a DMZ or port forwarding, let ssh be open to the internet, didn't harden ssh at all, and most people didn't use a VPN for downloading.
That is literally like saying that people who light wall torches in their wooden home burned their house down, so let's not use lightbulbs or electricity.
Coming up on a year of self hosting the worst I've had happen is a copyright letter from my isp from dry downloading torrents lmao. Threw I behind a vpn and it's been fine since.
The problem is that now you can automate pwning, in batches. And given that there it’s at international scales, you need defense first before host.
Heck, Salt Typhoon pwnd nearly the entire world.