Web & Internet

Don't Trust, Verify

Following up from my last post, where I talked a bit about proxy TLS termination and third-party interception, I think it raised an obvious question: if TLS (as it is typically used today) can’t be 100% relied on to verify origin, what can?

A Cloudflare Proxy and TLS Demonstration

I mentioned in a previous post that using Cloudflare’s reverse proxy services (such as “tunnels” or “proxied domains”) comes with certain security and privacy implications. Essentially, to function as a reverse proxy, CF must be able to intercept and decrypt your traffic. This Man-In-The-Middle position gives CF the ability to hypothetically capture or alter your traffic without any obvious indication.
In this post, I’d like to demonstrate how that would work.

Maintenance Page

I will be relocating my servers again in the next few months. These servers host this blog, a couple websites, my Fediverse server, and various internal services. My internal services will simply be down during this process, but for the external-facing services, I wanted something a little more elegant. Namely, a proper maintenance page.

Adventures in mTLS

For a while now, I’ve followed a pretty strict rule: public services are public, and private services are private.
For me, that meant that the only things on my network that were exposed to the public internet are my blog and public websites. Private services, like Home Assistant or Navidrome, are only accessible from my local network (or remotely via VPN).

Today I changed that a bit…

A sneaky demonstration of the dangers of curl | bash

Most linux users are probably familiar with the curl | bash syntax. It’s used as a convenient way to download a script and immediately run it on your system. Most users are also familiar with the frequent warnings telling them that they should never do that.

You might be thinking, though: “I’m safe. I always check the source first, so I know what it’s going to do before I run it.”

…but what if the source was lying to you?

About this Site

Purpose

This blog is intended to serve as:

  1. a public journal of my hobbies.
  2. a writing exercise (I’m a terrible writer)
  3. a learning journey in self-hosting and web-crafting

Content

I intend to share thoughts, opinions, how-tos, reviews and various utterances relating to my general hobbies of:

  • RF signals and Amateur Radio;
  • Self-hosting and web-crafting; and
  • Occasional games and general geekery.

All written content (for better or worse) is created by me. I do occasionally use an LLM to troubleshoot CSS and Hugo short-codes, but never to generate any content itself.

CompuServe 7.0

I recently learned that the CompuServe website is not only still online, but features current events, news, and photos.

Wait, what?!,” you may by thinking, “didn’t they go out of business in the 2000s?”

Let’s explore a bit.