I need the whole enchilada: DB, Web Server, Dynamic Languages, etc. Also, for a shipping, production application, with hundreds of users; where privacy and security are of paramount importance.
It's easy, sure. It's easy to create an insecure server, that can be pwned. I know of which I speak. I have done just that.
"A man who holds a cat by the tail, learns a lesson he can learn in no other way."
- Mark Twain
Use private keys. Use a firewall (ufw is really simple) and only expose your reverse proxy (e.g nginx or haproxy). Use docker to run your crap.
Any software engineer should be well capable of setting up a secure server. It really is simple.
The whole process takes maybe 30-60 minutes to setup for someone completely new and following guides.
Render's is simple, true, you just pay $300 for 1TB of bandwidth.
It's crazy how much Merchants of Complexity fooled devs into thinking that running your own server is complicated and you need to pay 1000x to save few minutes of your time.
I get that, a lot. It's the "No True Scotsman" of tech. This is also used as a way of validating college-style leetcode.
Let me introduce you to my GH Activity Graph[0]. See all that green? That's pretty much all coding in Swift; mostly in shipping apps and whatnot. There's a bit of PHP, for server-side stuff, but I like to spend a lot of time, coding frontend app stuff.
Every minute I spend, being a Linux admin, is a minute that I don't spend on executable code. I know that there's a number of folks, hereabout, that can code circles, around me, in Swift, and a few more, that can code circles around me, in PHP, but pretty much all of you, can run circles around me, in Linux admin. I'm not especially interested in competing, there; especially since a number of you are likely the folks that would Do Bad Things to my server, given an opening.
You don't have to be a linux admin to be able to setup a properly secure server, nowadays it's quite trivial. I bet you, that if you tried, you would be able to do so in less than an hour (at a relaxed pace).
We get lied to about the complexity of hosting by the cloud. I was able to host forums and game servers on VPSes when i was a young teenager, and I'm not technically gifted, it just wasn't complicated at all.
I tend to like shipping stuff, which means taking Responsibility for its operation, maintenance and security.
That often means a lot of "not fun." My servers are working servers. They have data and capabilities that are important to a lot of "not-Chris" people. It's my job to make sure that they get what they are [not] paying for (I write free stuff). That can be a bit stressful, at times; especially when some bad actor is making life miserable for me. I'd much rather that be someone else's problem, where I can write an email that says "Make it so, Numbah One!", instead of spending two days, wrestling with config files, and CLIs.
People are getting hacked a lot because of this, and docker doesn't seem to care all that much.
Firewalls are made for two things:
- packets alteration (iptable table mangle)
- applying filtering on behalf of a badly configured OS
So, if your case and if you want to prevent remote access to your database, you have a bad way: create a firewall rule to drop connections to tcp/3306And you have a good way: configure your sql to bind to ::1
The firewall way requires two configuration (hence: complexity) and hide your intent : the mysql say : "I accept connections from everybody", and then the firewall say "I deny all connections".
While the good way is clear and sane : one component who say : "I only accept connections from localhost"
I guess you gain some security, when you don't have to worry about some things. But you also lose some security, because of the added complexity.
sure it still needs work but much much less everyday
What a silly quote. “No other way” except all the other ones. Everyone watching the man and the cat will learn the same lesson. Everyone who hears the story will learn the same lesson.
I never held a cat by the tail, nor have i ever seen anyone foolish enough to attempt it, yet I am certain I know what happens next.
People FAFO when they should know better all the time.
I think the person in the original article was, at least for the sound file.
> I need the whole enchilada: DB, Web Server, Dynamic Languages, etc. Also, for a shipping, production application, with hundreds of users; where privacy and security are of paramount importance.
It seems quite simple to me, you either learn security, or pay for the expertise of someone that has. You need to decide whether it's worth your time.
I would suggest one thing, though - even with the likes of <big cloud>, they will only provide security in limited cases, i.e. DDoS. Nobody at <big cloud> is going to make sure your application logic works correctly - they clearly won't even make sure you use their resources within sensible bounds.