Supposing that they, y’know, try to keep their setups secure anyway. With how much you see about breaches of different sites, it’s hard to imagine individuals and smaller groups being able to keep their stuff secure.

Although, they may also benefit from being lower value targets in some respects, I suppose?

    • punkcoder@lemmy.world
      link
      fedilink
      English
      arrow-up
      6
      ·
      edit-2
      1 year ago

      The answer for this one is the zero trust platform, use it to restrict only what you want to allow in email or ip address. Just make sure that the machine that is hosting the service isn’t exposing outside of cloudflare.

      Edit: Also make sure you are backing up remember 3-2-1 for your backups.

        • Elle@lemmy.worldOP
          link
          fedilink
          English
          arrow-up
          1
          ·
          edit-2
          1 year ago

          I see Cloudflare suggested a lot & can understand why (they appear to be maybe one of the only services that has a free option), but are there no affordable alternatives in this space? I ask as I’m reminded of the Docker situation in terms of Docker Hub’s frequent suggestion and potential to throw folks off should they start limiting & charging for use.

          • Brendan McKenzie@lemmy.bmck.au
            link
            fedilink
            English
            arrow-up
            1
            ·
            1 year ago

            I don’t pay anything for Cloudflare. Tunnels and a good amount of protection is available on their free tier. Hopefully it stays that way.

  • Alteon@lemmy.world
    link
    fedilink
    English
    arrow-up
    5
    ·
    1 year ago

    So many hacks nowadays aren’t even people intending to target you. If you plugged your toaster into the internet, and left it on an unsecured server, both the toaster and the server would be hacked before the end of the day. Bots are constantly probing for unsecured cameras, security devices, laptops, servers, Wi-Fi networks, really anything that’s plugged into the internet. The easiest ones are cameras that are installed with a predetermined password that is shred betwee# n all sold devices. Of course the manufacturers will tell you to change the password, or something along those lines, but how often do people actually read the instructions?

    For your reading pleasure: https://www.theatlantic.com/technology/archive/2016/10/we-built-a-fake-web-toaster-and-it-was-hacked-in-an-hour/505571/

    • AnActualFossil@kbin.social
      link
      fedilink
      arrow-up
      1
      ·
      1 year ago

      Reading the logs for the incoming connection attempts of a fresh machine should be mandatory for everybody that wants to get a box online. It’s enlightening.
      And it already was scary twenty years ago.

  • Rikudou_Sage@lemmings.world
    link
    fedilink
    English
    arrow-up
    4
    ·
    1 year ago

    Usually very poorly. It’s pretty rare that a self-hosted or small site is secure. Just last week one of our clients needed help with some stuff and I was mortified when I looked at their production environment. Being obscure surely helps.

  • manitcor@lemmy.intai.tech
    link
    fedilink
    English
    arrow-up
    3
    ·
    1 year ago

    its not impossible, most of what these big companies use are the same OSS projects you can download and configure. there will be varying levels of security though. I expect some instances will eventually make it part of thier pitch.

  • redditcunts@lemmy.world
    link
    fedilink
    English
    arrow-up
    5
    arrow-down
    3
    ·
    edit-2
    1 year ago

    The vast majority of self hosted users would not be able to respond effectively to a coordinated or sophisticated attack. You might block off large swaths of domains, blocking big IP blocks, etc; but unless you are serving a very small number of users (White lists vs black lists) you’ll be fighting an uphill battle if someone decides to start going after your instance.

    • Quill0@lemmy.digitalfall.net
      link
      fedilink
      English
      arrow-up
      3
      ·
      1 year ago

      Usually selfhosters would have to talk to the upstream provider in case of DDoS attacks so the load can be shed or blackhoked

      • redditcunts@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        4
        ·
        1 year ago

        Yeah dude, good luck. Try getting actual ddos support from aws/cloudflare/azure without a paid SLA.

  • originalucifer@moist.catsweat.com
    link
    fedilink
    arrow-up
    2
    ·
    1 year ago

    many applications have a personal/business model that allows the personal install to benefit from business level security.

    nothing it impenetrable, but if you make it a big enough pain in the ass youre even less valuable.