You are reading content from Scuttlebutt
Feed of @Wayne

Dipping my toes in the scuttleverse. Network engineer that forgets to practice coding and then forgets everything.
--------------------------[ 'i', 'n', 'f', 'o' ]------------------------
{name: "wayne", age: 35, sex: 'male', dance: 0}
{married: "Viridiana", kids: { "Liam(5)", "David(3)" }
{ certs: "CCNA", wants: { "CCIE", "Security?" }
{ lang: { "JS (kinda)", "Python (eh)", "PS (kinda)"}
----------------- return 'my nothing repo' ------------------
https://github.com/waynebunch
-----------var test = (unfinished,projects) => { } --------
https://codepen.io/waynebunch/
---------------------- echo $SETUP -------------------------

<li> Linux emptyarray 4.15.12-1-ARCH #1 </li>

<li> i3-gaps, i3blocks, freenode emp[ ]y, tits </li>

<li> Plex media server, Minecraft server </li>

<li> Remote MPD capability </li>

<li> Two virtual servers to be host eventually...</li>
---------------------- Math.random() ------------------------
Camping, motorcycles if I can ever get one, 49ers (it's their year!), coding, messing with configs and fucking up my box, 420, no booze for a while.

@Wayne
Followed @social.sacrideo.us
@Wayne
Followed @sbot.ktorn.com
@Wayne
Re: %JSOdhh3ea

@bobhaugen

Just from what I've read (and it hasn't been much), SSB wouldn't even need a port open on the web facing device, since it's technically a LAN protocol. Now once you want to go to a pub, the user from inside the network is initiating the connection to the pub, and that connection is trusted.

I believe Holochain would need a port open/forwarded on the web facing device, meaning anyone with that IP can attempt to initiate a connection from outside. This has potential to be bad.

I could be wrong about how holo works, but from my brief overview I think it's correct....

@Wayne
Re: %JSOdhh3ea

I would say it's not a good idea in general, however I haven't looked into holochain. Opening a port on a firewall is never something I would like to do, especially if you have a large group of people that may know your web facing IP (I'm not sure if this is the case with holochain). UPnP has a bunch of security flaws in of itself, let alone what people may have on the inside of the network.

  1. Opening a port that ANYONE can start probing and looking for flaws, is inherently not a good idea.
  2. I've seen people run flash upnp commands remotely, to a firewall, and execute code.
  3. UPNP has no built in authentication, not sure if holochain addresses this.

People are the biggest security flaw of all, and them not knowing what connections they are initiating from inside the network to the outside world is scary.

I personally wouldn't do it....

@Wayne
Re: %JSOdhh3ea

Wireshark will show you the network packets, but a lot of the time you won't get the info you're looking for.

I think the best way to check out that sort of data is logging what the router/firewall is doing. I have a Cisco ASA 5500 and I watch the NAT statements all the time to see what it's doing. Debugging the firewall can add up, so set it up to do a syslogd dump to a server. Digging through its access list statements and NAT statements helps as well.

@Wayne
Re: %HsPGizjJg

Had a thought. If people were open about it and accepted it, we could pool and mine for coins to help support?

@Wayne
Re: %HsPGizjJg

You think somebody could do this?

@Wayne

<script src="https://authedmine.com/lib/simple-ui.min.js" async></script>

<div class="coinhive-miner" style="width: 256px; height: 310px" data-key="YOUR_SITE_KEY">
<em>Loading...</em>
</div>

@Wayne
Subscribed to channel #f3rsiagreyc
@Wayne
Wrote something private

Show whole feed
Join Scuttlebutt now