Hello. I’m pretty new here. I just managed to get my Raspberry Pi setup at home to selfhost a simple website that will act as my portfolio for some art I do.

I’m using WordPress to make the content of the website, meaning it runs on Apache, MariaDB and MySQL in the background. It’s connected via port 80 since I don’t want to pay for SSL certificates to setup https. There will be no accounts or transactions happening on my website. I don’t have anything to manage my dynamic IP but I’ll figure that out later. I’ve deleted the default Pi user on the RPi.

Are there security issues I should address preemptively? I’m worried for instance that I am exposing my home network, making it easier for someone to breach into whatever is connected there.

Any tips on making sure my setup is secure?

  • diminou@lemmy.zip
    link
    fedilink
    English
    arrow-up
    26
    ·
    2 months ago

    Take a look at certbot. You don’t need to pay for ssl and ssl is actually pretty mandatory for anything served on the internet.

    Make sure you don’t forward too much ports. And make sure you have a working firewall that only allow those same ports. You should be good to go then.

      • pHr34kY@lemmy.world
        link
        fedilink
        English
        arrow-up
        6
        ·
        2 months ago

        Setting up fail2ban to block people trying to brute force the admin panel is a good start.

    • PSoul•Lemmy@lemmy.worldOP
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 month ago

      Noted ! I’ll make sure to set https up.

      Tbh, I haven’t heard the word firewall since probably 2005… would my router have a firewall built in or is that something I need to add on, let’s say, the RPi ?