I pay for the Nabu Casa subscription for remote access to Home Assistant. Mostly as a way to give them money for a great service, but it’s convenient and felt pretty secure. It should be the only remote way into Home Assistant. About an hour ago I got a login attempt notice that an IP was trying to access API/config. The IP is in some bad IP databases. What I found interesting was that the log shows an AI bot. A Google Gemini bot specifically. Makes me worry that AI is going to make yet another aspect of life frustrating and unfun.

  • Knossos@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    6 hours ago

    I had a reverse proxy and all services on the web for funsies, behind various security mechanisms. Authentik, CrowdSec…

    But in the age of AI, it feels far too dangerous.

    Now everything still has a DNS entry and is accessible in Lan with it through my pi hole and Tailscale resolves the local subnet too.

  • Reannlegge@lemmy.ca
    link
    fedilink
    English
    arrow-up
    1
    ·
    16 hours ago

    The only place that I use port 22, is my crowdsec pi. I use some other port than the traditional port for HA. I am slowly moving all my things out of the Apple ecosystem once I do I will setup some other blocking system for outgoing stuff, kinda like pihole but in reverse.

    Would highly recommend using an alternative port other than the default one for HA and 22.

  • Lka1988@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    4
    ·
    22 hours ago

    My router (unifi dream machine) offers regional blocking, so I block Russia, China, and a few others that I’ve gotten hits from. So far so good.

  • 0x4f1@lemmy.world
    link
    fedilink
    English
    arrow-up
    6
    ·
    edit-2
    1 day ago

    Wireguard can solve secure remote access without* passwords. Android and iPhone both have clients that can be configured to bring the VPN up once you leave wi-fi. Bringing a third party into your home is just not wise.

  • daniskarma@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    8
    ·
    1 day ago

    You have anything online you will be hammered by bots trying to get through. That’s the sad reality of the world we live on. It has been like that forever. I get hundreds of bot malicious scans on my server each day.

    All that’s left is to secure everything as hard as you can so they cannot break through.

    • SirLeToet@lemmy.world
      link
      fedilink
      English
      arrow-up
      5
      ·
      1 day ago

      It’s been that case since forever now. Nothing has really changed and the same rules still apply.

      I still remember ‘hacking’ my ISP ADSL router 2+ decades ago and listening to the WAN interface. Hundreds of thousands of attempts per day in the early 2000s. Mostly US, Russia and China.

      My personal #1 threat on the internet for the past 20 years has been DDOS and thanks to billions of IOT devices and privacy invading ‘smart’ appliances everywhere… The botnets have never been this plenty. DDOS as a Service for mere cents a day.

      LLM’s joined the fray in recent years but it still can’t do anything it hasn’t learned from us humans.

  • Godnroc@lemmy.world
    link
    fedilink
    English
    arrow-up
    5
    ·
    2 days ago

    104.28.222.47? That one showed up in a log yesterday for me. Super glad the latest update added the option to see the IP for login attempts.

    • gdog05@lemmy.worldOP
      link
      fedilink
      English
      arrow-up
      4
      ·
      2 days ago

      This one was 66.187.5.19. I tried to find a way to report their behavior on hostodo (the service they’re using) but they don’t seem to have a report option. I’m guessing because they don’t want to prevent this kind of thing.