zlacker

[parent] [thread] 0 comments
1. 6ak74r+(OP)[view] [source] 2025-01-05 16:04:22
> I think it's a relatively small attack surface.

Plus, you can obfuscate that too by using a random port for Wireguard (instead of the default 51820): if Wireguard isn't able to authenticate (or pre-authenticate?) a client, it'll act as if the port is closed. So, a malicious actor/bot wouldn't even know you have a port open that it can exploit.

[go to top]