The post this replies to couldn't be fetched from tkohhh.social.
Open the original postReplying to a post on tkohhh.social
I’m somewhere in the middle, because comments like yours actually reinforce my concerns. A reverse proxy isn’t really doing anything to make you more secure, unless you’re using it for some sort of access control. It hides which ports you’re using, and allows you to encrypt your traffic with TLS… But it doesn’t add any additional security to the services you are exposing.
Maybe if you use it for access control, to add a secondary username/password to the services. But that breaks most legitimate things (apps, mostly) that try to reach the double-password-protected service. Because a user on a web browser may be able to type in two passwords, (one for the reverse proxy, and then one for the service itself) but an app will try to pass that info automatically using headers.
Any vulnerabilities in the services will still become potential attack vectors. Anyone who remembers the Huntarr debacle will know exactly what I’m talking about, because a single service being vulnerable can do a lot of damage. Yes, containerization does a lot to help mitigate damage by excluding access to everything except what you give it. But it won’t completely stop things from going wrong.
Replying to @Carl@anarchist.nexus
Those devices should most certainly be on two separate networks. Internet facing devices should be on a DMZ and not be allowed to talk to your internal network. You can then allow your internal network reach your DMZ devices, but only allow return traffic from the DMZ.
I use mTLS and vlans whenever I expose things to the internet.