• 0 Posts
  • 9 Comments
Joined 1 year ago
cake
Cake day: January 9th, 2025

help-circle
  • how to access crypto easily while at the same keep it private and safe?

    These are conflicting requirements, true for all valuables: more accessible is less safe, more secure is harder to access. The solution is to split up your money in levels.

    • Some hot crypto on your phone, like cash in your wallet. I keep about $100 of monero on my phone, ready to spend if I meet an accepting merchant.

    • Similarly, leave some hot crypto on the exchange if you trade regularly.

    • Some warm crypto on your pc, locked, secured, protected by dog and gun. This is like your checking account, ready to send to an exchange if fiat is needed on a rainy day.

    • Everything else in air-gapped cold storage. Bury the seed phrases and tell no one. This is your “savings account”, the stuff you will hodl and pass on to your kin, with no plans to ever sell.









  • I think I have the same protectli as you and it is awesome. Need it for my 2.5gb uplink. I use openwrt on it… Didn’t really like opnsense. I am more used to linux than bsd.

    I host lots of services and get bombarded by scrapers, scanners, and skids both at home and on my VPSs.

    I use ipset for the usual blocklists which I download regularly. I also have tarpits on 22/tcp (endlessh). I pipe the IPs from the endlessh logs into fail2ban which feeds the ipsets. I have ipset blocks and fail2ban on my home firewall and all VPSs and coordinate over mqtt. So any fail2ban trigger > mqtt > every ipset block. Touch my 22/tcp anywhere and you get banned instantly everywhere. The program I use for this is called vallumd and it runs on openwrt.

    I also put maltrail everywhere but I’m not totally sure how to interpret and respond to the results. Probably will implement a pipe from maltrail to my mqtt > blocklist setup.

    I don’t do any network-level adblocking… Might be a future project.