mkb is a user on mastodon.social. You can follow them or interact with them if you have an account anywhere in the fediverse. If you don't, you can sign up here.
mkb @mkb

I am setting up a couple relays and automating everything so it is reproducible. The host OS is since that's the only BSD offers.

I've got existing automation which provisions a via / . ZNC runs inside . This all works great though Chef annoys me in some ways.

For the Tor boxen I'm considering two changes:
- Swap Docker for BSD jail
- Swap Chef for or a straight shell script.

Thoughts?

· Web · 0 · 0

@mkb Please don't use DO for Tor relays. The #Tor network is already saturated with relays running on DO, OVH, and Amazon. Please consider using a different hosting provider.

@lattera Good to know.

The information I've found about Tor--friendly providers is all somewhat old. What providers do you like?

Am I correct in thinking adding relays to a saturated provider is still helpful but just not as helpful as adding one elsewhere?

Thanks for the info!

@mkb it would probably be best to go with another provider altogether given Tor's target audience. Oversaturating a provider makes an easier target for adversaries.

@lattera Fair enough. Who do you like?

@mkb I self-host my non-exit relay out of my home. I'm a fan of RootBSD for VPS hosting in general, though.

The other thing to take into account is the security of the operating environment for Tor. It would be best to run Tor on an OS that has exploit mitigations, like HardenedBSD or OpenBSD.

Tor's unique threat landscape and audience requires relay operators pay special attention to every aspect of security. People's lives are at stake.

@lattera @mkb But don't use the Tor installation comes by default in your BSD's, it's often already outdated by a series.