Topic
Security
Threat models that match how you actually work, not airline-grade compliance checklists. SSH the right way, firewalls that aren't theater, TLS without the foot-guns, secrets that don't end up in git, and authn/SSO patterns that scale from "me" to "the family WiFi." If your security plan starts with "it's behind WireGuard" — fair, but read these anyway.
160 articles in this topic.
Featured posts
-
Garrul: The Audit Found My Rate Limiter
A security audit of Garrul, my Cloudflare Workers comment system, found 2 critical bugs. Both had the same root cause as one I had already fixed in June.
14 min read -
Bots Ate 90% of My Worker Quota
A WordPress login bot burned 90% of my Cloudflare Workers free tier in two hours attacking a site that has never run PHP. Here's what actually stopped it.
13 min read -
rclone Crypt: Encrypted Cloud Buckets That Stay Yours
Client-side encryption with rclone crypt keeps your cloud backups opaque to providers. Key management, filename encryption, and restore drills for B2, S3, Drive.
10 min read -
The Free Tier Rug Pull
Free AI tiers are loans against a future price, paid in your data, your architecture, or your time. Here's the collateral to check before you build on one.
7 min read -
3-2-1-1-0: The Backup Strategy That Survives Ransomware
3-2-1 backups aren't enough anymore. The 3-2-1-1-0 rule adds immutable & offline copies plus verified restores, here's how to implement it.
9 min read -
SSH Bastion & Jump Host Patterns That Don't Hurt
Stop opening port 22 to the world. SSH bastion hosts, ProxyJump chains, session recording, and self-hosted Teleport alternatives that actually work.
9 min read
All Security articles
- Garrul: The Audit Found My Rate Limiter
- Bots Ate 90% of My Worker Quota
- rclone Crypt: Encrypted Cloud Buckets That Stay Yours
- The Free Tier Rug Pull
- 3-2-1-1-0: The Backup Strategy That Survives Ransomware
- SSH Bastion & Jump Host Patterns That Don't Hurt
- systemd-homed: Portable Encrypted Home Directories
- Local Voice Assistant: Whisper + Piper + Home Assistant
- SOCKS5 Over SSH: Selective Routing Without a VPN
- Your Agent Doesn't Need a Shell
- Sandstorm: Self-Hosted Apps in a Sandbox, Not Just a Container
- Where Should Your Coding Agent Run?
- Go on Scratch: Docker With No OS at All
- DIY Perplexity: SearXNG + Local LLM = Private Web Search
- Mozilla Sync Server Self-Hosted: Still Viable?
- Mullvad VPN Containers via Gluetun: Per-App VPN
- OPA & Rego: Policy as Code Beyond Kubernetes
- Vaultwarden Behind Authelia: 2FA That Holds
- Joplin Server vs Trilium vs Standard Notes
- Invidious, Piped, Redlib, Nitter: 2026 Status
- BTCPay Server: Self-Hosted Crypto Payments
- Tang & Clevis: LUKS Auto-Unlock Without a Typed Passphrase
- LibreSpeed: Hosting Your Own Speed Test
- LibreTranslate: Local Translation Without Google
- Collateral Freedom: Costly to Block
- SearXNG vs Whoogle: Private Search Frontends
- Meshtastic vs Reticulum
- Stirling-PDF: Stop Uploading Your Tax Returns to Sketchy Sites
- AdGuard DNS Sync Across Two Instances
- REALITY: Borrowing a TLS Handshake
- Self-Hosted Email Aliasing on Your Own Domain
- CryptPad vs EtherCalc: Privacy Collaboration
- nftables in 2026: Stop Pretending iptables Will Live Forever
- Why Your VPN Is Already Detected
- NextDNS vs Self-Hosted: When SaaS Wins
- Self-Hosted CAPTCHA Alternatives in 2026
- DNS-over-HTTPS at Home: cloudflared vs dnscrypt-proxy
- YubiKey + age: Hardware-Backed Encryption Without GPG
- Pangolin: Self-Hosted Cloudflare Tunnel Alternative
- Sigstore + Gitsign: Signed Commits Without GPG Pain
- Sealed Secrets vs External Secrets Operator
- Renovate vs Dependabot: Self-Hosted Dependency Bots
- Mesh VPN Showdown: Tailscale, Nebula, ZeroTier, NetBird
- Syncthing Through Untrusted VPS Relays
- Self-Hosted Email Gateways in 2026
- Assume Your App Gets Popped
- Kasm Workspaces: Browser Desktops
- Jitsi Meet Self-Hosted
- OPA & Gatekeeper: Policy as Code
- cert-manager: ACME at Scale
- Zeek for Home Lab Forensics
- ModSecurity vs Coraza WAF
- SOPS + age: Secrets in Git
- WebAuthn & Passkeys for Sysadmins
- Owntracks + Home Assistant: Private Location Tracking
- Claude Code + SearXNG: Private Web Search
- ZFS Encryption vs LUKS
- Syncthing vs Resilio vs Seafile
- OpenConnect vs AnyConnect
- Boundary vs Teleport
- stunnel vs spiped
- Container Escape: How to Stop It
- Cosign Keyless: Sign Without Keys
- age vs GPG: Modern File Encryption That Doesn't Make You Cry
- Sysbox vs gVisor vs Kata
- Trivy vs Grype vs Docker Scout
- Beyond Akismet: Spam Protection for 2026
- Sec-Fetch & UA Client Hints in 2026: What Actually Leaks
- Blog Comments: Self-Host or SaaS?
- CrowdSec Collections & Bouncers: fail2ban for 2026
- Distroless Images: When Minimal Goes Too Far
- Incident Response for Self-Hosters
- CVE-2026-31431: The 9-Year Linux Root Bug
- OpenCanary: Honeypots for Your Home Lab
- Pi-hole vs AdGuard Home: Block Ads for Your Whole Network
- nftables: Modern Linux Firewalling
- Suricata vs Snort: Network Intrusion Detection That Actually Works
- SBOMs and Supply Chain Security
- Authentik vs Authelia: SSO for Your Self-Hosted Stack
- Container Security: Scan and Sign Your Images Like You Mean It
- Falco: Catch Container Attacks at Runtime
- Cloudflare Tunnels: Beyond Port Forwarding
- Immich vs PhotoPrism: Escape Google Photos Without Losing Your Mind
- Trivy + Cosign: Scan and Sign Your Images
- Fail2ban vs CrowdSec: Blocking the Bots Actually Smartly
- 2FA for SSH and sudo via PAM
- WireGuard vs OpenVPN 2026: It's Not Even Close
- SSH CA: Finally Ditch authorized_keys
- Wazuh: Open Source SIEM for Your Home Lab
- LUKS Full Disk Encryption on Linux
- Rootless Docker: Run Without Root
- LinkedIn Is Searching Your Computer
- Linux Privilege Escalation: The Defensive Playbook
- De-Googling: Self-Hosted Replacements for Google Apps
- dotenv Files: The Mistakes That Leak Secrets
- Using AI to Find Security Bugs in Your Code
- Private Docker Registry with Harbor
- TLS 1.3: Modern Encryption Without the Existential Dread
- Let's Encrypt Without Certbot
- The Zero-Trust Home Lab
- Cloudflare WAF: Free Tier Firewall Rules
- Certificate Pinning: The Nuclear Option for TLS Security (Use With Caution)
- .gitignore Entries Every Project Actually Needs
- Vault vs Infisical: Secrets Management for Teams Who've Learned the Hard Way
- Open Source Licenses Explained: What You Can and Can't Do With Free Software
- mTLS Explained: When Regular TLS Isn't Paranoid Enough
- Port Knocking: Simple Obscurity for SSH Access
- Why Your VPN Isn't Routing What You Think
- Kernel Live Patching: Security Updates Without the 3am Reboot
- DNS Over HTTPS and TLS: Encrypt Your DNS Before Your ISP Sells It
- tcpdump Basics: Capture Traffic Without Wireshark
- AppArmor vs SELinux: Mandatory Access Control Without the Existential Dread
- Your Server Doesn't Know What Random Means (And That's a Problem)
- Caddy Advanced: Automatic HTTPS, Plugins, and Config That Doesn't Make You Cry
- Auditd & Audit Logging: Know Exactly Who Touched What on Your Server
- HashiCorp Vault: Stop Hardcoding Secrets Like It's 2012
- VPN Kill Switch and DNS Leak Prevention: Paranoia, Justified
- Suricata vs Snort: Intrusion Detection for the Paranoid Home Lab Owner
- Plausible vs Umami: Privacy-Friendly Analytics That Won't Creep Out Your Users
- nmap for Your Own Network: What You Should Be Scanning
- Vaultwarden Organization Sharing: Password Management for Your Whole Household (or Team)
- Reverse Proxy SSL: The Cert Chain Mistake Everyone Makes
- Linux Capabilities: Drop Root Without Breaking Everything
- Docker Security Hardening: 15 Things You're Doing Wrong Right Now
- UFW Advanced: Rate Limiting, Logging, and Rules That Actually Make Sense
- Open Source Security: Scanning Your Dependencies Before They Scan You
- DDoS Mitigation: Teaching Your Server to Say No Politely (Then Impolitely)
- SSH Hardening: Lock Down Remote Access Without Locking Yourself Out
- Vaultwarden vs Bitwarden: Own Your Passwords Before Someone Else Does
- Proxy Chains and Anonymization: What Actually Works and What's Just Theater
- Linux Audit Log: What's Really Happening on Your Server
- The sudoers Mistake Everyone Makes Once
- Why Your TLS Certificate Isn't Trusted
- Certificate Expiry: Monitor Before the 3 AM Call
- The Firewall Rule Order That's Breaking Your Setup
- Sticky Bit, Setuid, Setgid: Linux Special Permissions Explained
- Is fail2ban Actually Working? Here's How to Check
- SSHFS: Ditch SCP & Access Remote Files
- SSH Agent Forwarding: How It Works
- Why Your SSH Connection Keeps Dropping
- SSH Multiplexing: Stop Reconnecting Every Time
- Stop Putting Passwords in Docker ENV
- The SSH Config File: The Shortcut You're Not Using
- The umask You've Been Ignoring
- Running Docker Containers as Non-Root (And Why You Should)
- Disabling Discord’s Activity Tracking
- The Role of Antivirus and Endpoint Detection and Response Systems
- Certificate Pinning: A Secure Connection Guide
- Understanding the regreSSHion Vulnerability in OpenSSH
- How to securely deploy Cloudflare Tunnels
- Advanced UFW Techniques: Enhancing Firewall Security
- UFW Basics: Setting Up Your Linux Firewall
- SSH Tunneling: A Secure Conduit for Your Data
- User and Group Management in Linux
- Linux Home Lab Security: Planning for the Unexpected
- Wireguard VPN Server in Docker
- Ed25519 SSH Keys: Ditch RSA for Good
- Install Caddy reverse proxy via Docker
- Linux su with custom shell
- SSH keys and secure file copy