<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/">
	<channel>
		<title><![CDATA[TalkativeTurtles - Networking & Cybersecurity]]></title>
		<link>https://talkativeturtles.club/</link>
		<description><![CDATA[TalkativeTurtles - https://talkativeturtles.club]]></description>
		<pubDate>Wed, 05 Aug 2026 13:58:00 +0000</pubDate>
		<generator>MyBB</generator>
		<item>
			<title><![CDATA[Tailscale vs self-hosted WireGuard - which did you choose and why?]]></title>
			<link>https://talkativeturtles.club/showthread.php?tid=129</link>
			<pubDate>Mon, 29 Jun 2026 20:52:08 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://talkativeturtles.club/member.php?action=profile&uid=1">Zero Two</a>]]></dc:creator>
			<guid isPermaLink="false">https://talkativeturtles.club/showthread.php?tid=129</guid>
			<description><![CDATA[Been running Tailscale for about 18 months across my home lab, a VPS, and a few travel devices. Before that I ran WireGuard manually for two years.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Why I moved to Tailscale:</span><ul class="mycode_list"><li>NAT traversal just works. WireGuard requires at least one public endpoint. Tailscale handles the CGNAT case without me thinking about it.<br />
</li>
<li>Device management is actually pleasant. Adding a new machine is under 2 minutes.<br />
</li>
<li>MagicDNS is underrated. Referring to machines by name instead of IP removes a whole class of confusion.<br />
</li>
</ul>
<br />
<span style="font-weight: bold;" class="mycode_b">What I gave up:</span><ul class="mycode_list"><li>Control plane is in Tailscale hands. If you have strict self-sovereignty requirements this is a non-starter.<br />
</li>
<li>Headscale exists but the setup overhead partially defeats the convenience argument.<br />
</li>
<li>The free tier is 3 users and used to be more generous.<br />
</li>
</ul>
<br />
<span style="font-weight: bold;" class="mycode_b">Verdict:</span> Tailscale for personal use and small teams, self-hosted WireGuard when the org has a dedicated network person and a reason to avoid third-party control planes.<br />
<br />
What are you running?]]></description>
			<content:encoded><![CDATA[Been running Tailscale for about 18 months across my home lab, a VPS, and a few travel devices. Before that I ran WireGuard manually for two years.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Why I moved to Tailscale:</span><ul class="mycode_list"><li>NAT traversal just works. WireGuard requires at least one public endpoint. Tailscale handles the CGNAT case without me thinking about it.<br />
</li>
<li>Device management is actually pleasant. Adding a new machine is under 2 minutes.<br />
</li>
<li>MagicDNS is underrated. Referring to machines by name instead of IP removes a whole class of confusion.<br />
</li>
</ul>
<br />
<span style="font-weight: bold;" class="mycode_b">What I gave up:</span><ul class="mycode_list"><li>Control plane is in Tailscale hands. If you have strict self-sovereignty requirements this is a non-starter.<br />
</li>
<li>Headscale exists but the setup overhead partially defeats the convenience argument.<br />
</li>
<li>The free tier is 3 users and used to be more generous.<br />
</li>
</ul>
<br />
<span style="font-weight: bold;" class="mycode_b">Verdict:</span> Tailscale for personal use and small teams, self-hosted WireGuard when the org has a dedicated network person and a reason to avoid third-party control planes.<br />
<br />
What are you running?]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Home lab network segmentation - how far do you actually go?]]></title>
			<link>https://talkativeturtles.club/showthread.php?tid=117</link>
			<pubDate>Mon, 29 Jun 2026 20:35:25 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://talkativeturtles.club/member.php?action=profile&uid=1">Zero Two</a>]]></dc:creator>
			<guid isPermaLink="false">https://talkativeturtles.club/showthread.php?tid=117</guid>
			<description><![CDATA[Been slowly reworking my home network and reached the point where I need to decide how paranoid to actually be.<br />
<br />
Currently:<ul class="mycode_list"><li>Main LAN - trusted devices, laptops, workstations<br />
</li>
<li>IoT VLAN - smart plugs, lights, thermostat, isolated with no internet except updates<br />
</li>
<li>Guest WiFi - completely separate, internet only<br />
</li>
</ul>
<br />
Thinking about adding:<ul class="mycode_list"><li>A media VLAN for consoles and streaming sticks - semi-trusted, can reach Plex server only<br />
</li>
<li>A lab VLAN for VMs and containers I experiment with<br />
</li>
</ul>
<br />
At what point does this stop being useful and start being overhead you never maintain properly? I know people who have 10+ VLANs and their firewall rules are a mess.<br />
<br />
What is your segmentation like and where did you draw the line?]]></description>
			<content:encoded><![CDATA[Been slowly reworking my home network and reached the point where I need to decide how paranoid to actually be.<br />
<br />
Currently:<ul class="mycode_list"><li>Main LAN - trusted devices, laptops, workstations<br />
</li>
<li>IoT VLAN - smart plugs, lights, thermostat, isolated with no internet except updates<br />
</li>
<li>Guest WiFi - completely separate, internet only<br />
</li>
</ul>
<br />
Thinking about adding:<ul class="mycode_list"><li>A media VLAN for consoles and streaming sticks - semi-trusted, can reach Plex server only<br />
</li>
<li>A lab VLAN for VMs and containers I experiment with<br />
</li>
</ul>
<br />
At what point does this stop being useful and start being overhead you never maintain properly? I know people who have 10+ VLANs and their firewall rules are a mess.<br />
<br />
What is your segmentation like and where did you draw the line?]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Pi-hole for network-wide ad blocking - tips, filter lists, and gotchas]]></title>
			<link>https://talkativeturtles.club/showthread.php?tid=59</link>
			<pubDate>Mon, 22 Jun 2026 12:59:51 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://talkativeturtles.club/member.php?action=profile&uid=1">Zero Two</a>]]></dc:creator>
			<guid isPermaLink="false">https://talkativeturtles.club/showthread.php?tid=59</guid>
			<description><![CDATA[Running Pi-hole for about two years now and it's one of those things I'd never go back on. Blocks ads, telemetry, and trackers at the DNS level for every device on the network without touching individual clients.<br />
<br />
A few things I've learned:<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Hardware:</span> A Pi Zero 2 W is more than enough for a home network. Alternatively, run it in Docker on whatever box is already on 24/7.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Filter lists worth using:</span><ul class="mycode_list"><li>Steven Black's Unified Hosts (the default)<br />
</li>
<li>OISD Full - very comprehensive, regularly maintained<br />
</li>
<li>Hagezi's Multi Pro - aggressive but well-curated<br />
</li>
</ul>
<br />
<span style="font-weight: bold;" class="mycode_b">Avoid adding too many lists.</span> The diminishing returns kick in fast and you'll start breaking sites you actually want to use. Start with 2-3 good lists.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Whitelist early and often.</span> Some CDNs double as ad networks. Keep a note of what you've whitelisted and why.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Set up a secondary DNS.</span> Pi-hole as primary, either another Pi-hole or your router's upstream as secondary. If Pi-hole goes down you still have connectivity.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Gravity updates:</span> Set a weekly cron to run <span style="font-family: monospace;" class="mycode_font">pihole -g</span> to pull fresh blocklists.<br />
<br />
Anyone running Unbound alongside Pi-hole for recursive DNS? Worth the extra setup?]]></description>
			<content:encoded><![CDATA[Running Pi-hole for about two years now and it's one of those things I'd never go back on. Blocks ads, telemetry, and trackers at the DNS level for every device on the network without touching individual clients.<br />
<br />
A few things I've learned:<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Hardware:</span> A Pi Zero 2 W is more than enough for a home network. Alternatively, run it in Docker on whatever box is already on 24/7.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Filter lists worth using:</span><ul class="mycode_list"><li>Steven Black's Unified Hosts (the default)<br />
</li>
<li>OISD Full - very comprehensive, regularly maintained<br />
</li>
<li>Hagezi's Multi Pro - aggressive but well-curated<br />
</li>
</ul>
<br />
<span style="font-weight: bold;" class="mycode_b">Avoid adding too many lists.</span> The diminishing returns kick in fast and you'll start breaking sites you actually want to use. Start with 2-3 good lists.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Whitelist early and often.</span> Some CDNs double as ad networks. Keep a note of what you've whitelisted and why.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Set up a secondary DNS.</span> Pi-hole as primary, either another Pi-hole or your router's upstream as secondary. If Pi-hole goes down you still have connectivity.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Gravity updates:</span> Set a weekly cron to run <span style="font-family: monospace;" class="mycode_font">pihole -g</span> to pull fresh blocklists.<br />
<br />
Anyone running Unbound alongside Pi-hole for recursive DNS? Worth the extra setup?]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[WireGuard vs OpenVPN vs Tailscale - what VPN setup are you running?]]></title>
			<link>https://talkativeturtles.club/showthread.php?tid=58</link>
			<pubDate>Mon, 22 Jun 2026 12:52:51 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://talkativeturtles.club/member.php?action=profile&uid=1">Zero Two</a>]]></dc:creator>
			<guid isPermaLink="false">https://talkativeturtles.club/showthread.php?tid=58</guid>
			<description><![CDATA[Setting up a VPN for remote access to my home network and I keep going back and forth on the options. Curious what people here are actually running and why.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">WireGuard</span> seems like the obvious modern choice - kernel-level on Linux, faster handshakes, smaller codebase (easier to audit), and the configs are tiny. The downside is managing key distribution manually and the lack of dynamic routing out of the box.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">OpenVPN</span> is battle-tested and supported everywhere. It's slower and the config files look like XML nightmares but it just works and there's a client for every platform.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Tailscale</span> is interesting because it uses WireGuard under the hood but handles the key exchange and routing automatically via their coordination server. Free tier is generous. The trade-off is you're relying on their servers for control plane stuff - fine for personal use, maybe not for corporate.<br />
<br />
I'm leaning toward WireGuard directly on an OPNsense box since I want full control and my use case is simple (a few trusted devices).<br />
<br />
What are you running? Any pitfalls to watch out for? Is Tailscale actually worth it for home use or is rolling your own WireGuard not that painful?]]></description>
			<content:encoded><![CDATA[Setting up a VPN for remote access to my home network and I keep going back and forth on the options. Curious what people here are actually running and why.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">WireGuard</span> seems like the obvious modern choice - kernel-level on Linux, faster handshakes, smaller codebase (easier to audit), and the configs are tiny. The downside is managing key distribution manually and the lack of dynamic routing out of the box.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">OpenVPN</span> is battle-tested and supported everywhere. It's slower and the config files look like XML nightmares but it just works and there's a client for every platform.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Tailscale</span> is interesting because it uses WireGuard under the hood but handles the key exchange and routing automatically via their coordination server. Free tier is generous. The trade-off is you're relying on their servers for control plane stuff - fine for personal use, maybe not for corporate.<br />
<br />
I'm leaning toward WireGuard directly on an OPNsense box since I want full control and my use case is simple (a few trusted devices).<br />
<br />
What are you running? Any pitfalls to watch out for? Is Tailscale actually worth it for home use or is rolling your own WireGuard not that painful?]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Understanding TLS - what actually happens in an HTTPS connection]]></title>
			<link>https://talkativeturtles.club/showthread.php?tid=101</link>
			<pubDate>Mon, 22 Jun 2026 12:06:40 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://talkativeturtles.club/member.php?action=profile&uid=1">Zero Two</a>]]></dc:creator>
			<guid isPermaLink="false">https://talkativeturtles.club/showthread.php?tid=101</guid>
			<description><![CDATA[TLS is one of those things developers use constantly but rarely understand deeply. Here's a plain-English walkthrough of what actually happens when you visit an HTTPS site.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">The TLS handshake (simplified)</span><br />
<br />
1. <span style="font-weight: bold;" class="mycode_b">Client Hello</span> - your browser sends: supported TLS versions, supported cipher suites (algorithms), a random number<br />
<br />
2. <span style="font-weight: bold;" class="mycode_b">Server Hello</span> - server responds with: chosen TLS version and cipher suite, its certificate (contains the public key), another random number<br />
<br />
3. <span style="font-weight: bold;" class="mycode_b">Certificate verification</span> - your browser checks the certificate:<ul class="mycode_list"><li>Is it signed by a trusted Certificate Authority (CA)?<br />
</li>
<li>Is the domain name in the certificate the one you requested?<br />
</li>
<li>Has it expired?<br />
</li>
<li>Has it been revoked (OCSP check)?<br />
</li>
</ul>
<br />
4. <span style="font-weight: bold;" class="mycode_b">Key exchange</span> - both sides use the two random numbers plus the key exchange algorithm (usually ECDHE) to independently derive the same session key. The private key is never sent over the wire.<br />
<br />
5. <span style="font-weight: bold;" class="mycode_b">Symmetric encryption begins</span> - all subsequent data is encrypted with the session key (AES-GCM typically). Asymmetric crypto (RSA/ECDSA) was only used to establish the session key.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Why this matters for developers:</span><ul class="mycode_list"><li>Certificate pinning - you can assert that only a specific certificate is trusted, defeating CA compromise<br />
</li>
<li>HSTS - tells browsers to always use HTTPS for your domain, preventing downgrade attacks<br />
</li>
<li>TLS 1.3 vs 1.2 - 1.3 reduces the handshake to 1 round trip (vs 2), meaningfully faster<br />
</li>
<li>Mixed content - a single HTTP resource on an HTTPS page breaks the security model<br />
</li>
</ul>
<br />
Happy to go deeper on any part of this.]]></description>
			<content:encoded><![CDATA[TLS is one of those things developers use constantly but rarely understand deeply. Here's a plain-English walkthrough of what actually happens when you visit an HTTPS site.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">The TLS handshake (simplified)</span><br />
<br />
1. <span style="font-weight: bold;" class="mycode_b">Client Hello</span> - your browser sends: supported TLS versions, supported cipher suites (algorithms), a random number<br />
<br />
2. <span style="font-weight: bold;" class="mycode_b">Server Hello</span> - server responds with: chosen TLS version and cipher suite, its certificate (contains the public key), another random number<br />
<br />
3. <span style="font-weight: bold;" class="mycode_b">Certificate verification</span> - your browser checks the certificate:<ul class="mycode_list"><li>Is it signed by a trusted Certificate Authority (CA)?<br />
</li>
<li>Is the domain name in the certificate the one you requested?<br />
</li>
<li>Has it expired?<br />
</li>
<li>Has it been revoked (OCSP check)?<br />
</li>
</ul>
<br />
4. <span style="font-weight: bold;" class="mycode_b">Key exchange</span> - both sides use the two random numbers plus the key exchange algorithm (usually ECDHE) to independently derive the same session key. The private key is never sent over the wire.<br />
<br />
5. <span style="font-weight: bold;" class="mycode_b">Symmetric encryption begins</span> - all subsequent data is encrypted with the session key (AES-GCM typically). Asymmetric crypto (RSA/ECDSA) was only used to establish the session key.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Why this matters for developers:</span><ul class="mycode_list"><li>Certificate pinning - you can assert that only a specific certificate is trusted, defeating CA compromise<br />
</li>
<li>HSTS - tells browsers to always use HTTPS for your domain, preventing downgrade attacks<br />
</li>
<li>TLS 1.3 vs 1.2 - 1.3 reduces the handshake to 1 round trip (vs 2), meaningfully faster<br />
</li>
<li>Mixed content - a single HTTP resource on an HTTPS page breaks the security model<br />
</li>
</ul>
<br />
Happy to go deeper on any part of this.]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[SSH hardening checklist - locking down a new server]]></title>
			<link>https://talkativeturtles.club/showthread.php?tid=100</link>
			<pubDate>Mon, 22 Jun 2026 11:55:45 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://talkativeturtles.club/member.php?action=profile&uid=1">Zero Two</a>]]></dc:creator>
			<guid isPermaLink="false">https://talkativeturtles.club/showthread.php?tid=100</guid>
			<description><![CDATA[Every new VPS I spin up goes through this checklist before anything else is deployed. SSH is the most exposed attack surface on a Linux server.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Change the default SSH port (optional but reduces noise)</span><br />
<div class="codeblock"><div class="title">Code:</div><div class="body" dir="ltr"><code># /etc/ssh/sshd_config<br />
Port 2222&nbsp;&nbsp;# or any non-standard port</code></div></div>This doesn't improve security against targeted attacks but cuts automated scan noise by 90%.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Disable root login</span><br />
<div class="codeblock"><div class="title">Code:</div><div class="body" dir="ltr"><code>PermitRootLogin no</code></div></div>Always. SSH in as a regular user and sudo when needed.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Disable password authentication (keys only)</span><br />
<div class="codeblock"><div class="title">Code:</div><div class="body" dir="ltr"><code>PasswordAuthentication no<br />
PubkeyAuthentication yes</code></div></div>Do this AFTER you've confirmed key-based login works. Locking yourself out is annoying.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Limit the login grace period</span><br />
<div class="codeblock"><div class="title">Code:</div><div class="body" dir="ltr"><code>LoginGraceTime 20<br />
MaxAuthTries 3</code></div></div><br />
<span style="font-weight: bold;" class="mycode_b">Specify allowed users</span><br />
<div class="codeblock"><div class="title">Code:</div><div class="body" dir="ltr"><code>AllowUsers yourusername</code></div></div>Only accounts listed here can SSH in.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Disable unused features</span><br />
<div class="codeblock"><div class="title">Code:</div><div class="body" dir="ltr"><code>X11Forwarding no<br />
AllowAgentForwarding no<br />
AllowTcpForwarding no&nbsp;&nbsp;# unless you need tunnels<br />
PermitTunnel no</code></div></div><br />
<span style="font-weight: bold;" class="mycode_b">Use a modern key algorithm</span><br />
Generate keys with <span style="font-family: monospace;" class="mycode_font">ssh-keygen -t ed25519</span>. If you have old RSA keys on the server, keep them but prefer ed25519 for new ones.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Install fail2ban</span><br />
<div class="codeblock"><div class="title">Code:</div><div class="body" dir="ltr"><code>sudo apt install fail2ban<br />
# Default config jails SSH after 5 failed attempts<br />
sudo systemctl enable --now fail2ban</code></div></div><br />
<span style="font-weight: bold;" class="mycode_b">After all changes:</span><br />
<div class="codeblock"><div class="title">Code:</div><div class="body" dir="ltr"><code>sudo sshd -t&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;# test config syntax before reloading<br />
sudo systemctl reload sshd</code></div></div><br />
Keep your current session open and test login in a new terminal before closing anything. Never reload SSH blind.]]></description>
			<content:encoded><![CDATA[Every new VPS I spin up goes through this checklist before anything else is deployed. SSH is the most exposed attack surface on a Linux server.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Change the default SSH port (optional but reduces noise)</span><br />
<div class="codeblock"><div class="title">Code:</div><div class="body" dir="ltr"><code># /etc/ssh/sshd_config<br />
Port 2222&nbsp;&nbsp;# or any non-standard port</code></div></div>This doesn't improve security against targeted attacks but cuts automated scan noise by 90%.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Disable root login</span><br />
<div class="codeblock"><div class="title">Code:</div><div class="body" dir="ltr"><code>PermitRootLogin no</code></div></div>Always. SSH in as a regular user and sudo when needed.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Disable password authentication (keys only)</span><br />
<div class="codeblock"><div class="title">Code:</div><div class="body" dir="ltr"><code>PasswordAuthentication no<br />
PubkeyAuthentication yes</code></div></div>Do this AFTER you've confirmed key-based login works. Locking yourself out is annoying.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Limit the login grace period</span><br />
<div class="codeblock"><div class="title">Code:</div><div class="body" dir="ltr"><code>LoginGraceTime 20<br />
MaxAuthTries 3</code></div></div><br />
<span style="font-weight: bold;" class="mycode_b">Specify allowed users</span><br />
<div class="codeblock"><div class="title">Code:</div><div class="body" dir="ltr"><code>AllowUsers yourusername</code></div></div>Only accounts listed here can SSH in.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Disable unused features</span><br />
<div class="codeblock"><div class="title">Code:</div><div class="body" dir="ltr"><code>X11Forwarding no<br />
AllowAgentForwarding no<br />
AllowTcpForwarding no&nbsp;&nbsp;# unless you need tunnels<br />
PermitTunnel no</code></div></div><br />
<span style="font-weight: bold;" class="mycode_b">Use a modern key algorithm</span><br />
Generate keys with <span style="font-family: monospace;" class="mycode_font">ssh-keygen -t ed25519</span>. If you have old RSA keys on the server, keep them but prefer ed25519 for new ones.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Install fail2ban</span><br />
<div class="codeblock"><div class="title">Code:</div><div class="body" dir="ltr"><code>sudo apt install fail2ban<br />
# Default config jails SSH after 5 failed attempts<br />
sudo systemctl enable --now fail2ban</code></div></div><br />
<span style="font-weight: bold;" class="mycode_b">After all changes:</span><br />
<div class="codeblock"><div class="title">Code:</div><div class="body" dir="ltr"><code>sudo sshd -t&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;# test config syntax before reloading<br />
sudo systemctl reload sshd</code></div></div><br />
Keep your current session open and test login in a new terminal before closing anything. Never reload SSH blind.]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Home lab setups - what are you running?]]></title>
			<link>https://talkativeturtles.club/showthread.php?tid=35</link>
			<pubDate>Sun, 21 Jun 2026 09:42:20 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://talkativeturtles.club/member.php?action=profile&uid=1">Zero Two</a>]]></dc:creator>
			<guid isPermaLink="false">https://talkativeturtles.club/showthread.php?tid=35</guid>
			<description><![CDATA[Home labs are one of the best ways to actually learn networking and security hands-on. Share what you've got running.<br />
<br />
My current setup:<ul class="mycode_list"><li>Mikrotik hEX router - running RouterOS, configured VLANs for IoT, trusted, and guest networks<br />
</li>
<li>Unmanaged TP-Link switch for the wired side<br />
</li>
<li>Proxmox box on old Optiplex 7050 - running pfSense VM, a few Debian VMs for services, and a Kali VM for playing around<br />
</li>
<li>Pi-hole on a Pi 4 for DNS filtering<br />
</li>
<li>Wireguard VPN for remote access<br />
</li>
</ul>
<br />
Considering adding an IDS (Suricata on pfSense) and a SIEM (probably Wazuh or Graylog) but I keep talking myself out of the complexity.<br />
<br />
What does your home lab look like? Also curious what people use for remote access - Wireguard, Tailscale, ZeroTier?]]></description>
			<content:encoded><![CDATA[Home labs are one of the best ways to actually learn networking and security hands-on. Share what you've got running.<br />
<br />
My current setup:<ul class="mycode_list"><li>Mikrotik hEX router - running RouterOS, configured VLANs for IoT, trusted, and guest networks<br />
</li>
<li>Unmanaged TP-Link switch for the wired side<br />
</li>
<li>Proxmox box on old Optiplex 7050 - running pfSense VM, a few Debian VMs for services, and a Kali VM for playing around<br />
</li>
<li>Pi-hole on a Pi 4 for DNS filtering<br />
</li>
<li>Wireguard VPN for remote access<br />
</li>
</ul>
<br />
Considering adding an IDS (Suricata on pfSense) and a SIEM (probably Wazuh or Graylog) but I keep talking myself out of the complexity.<br />
<br />
What does your home lab look like? Also curious what people use for remote access - Wireguard, Tailscale, ZeroTier?]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[[Resources] CTF Platforms & Cybersecurity Learning]]></title>
			<link>https://talkativeturtles.club/showthread.php?tid=34</link>
			<pubDate>Sun, 21 Jun 2026 09:42:20 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://talkativeturtles.club/member.php?action=profile&uid=1">Zero Two</a>]]></dc:creator>
			<guid isPermaLink="false">https://talkativeturtles.club/showthread.php?tid=34</guid>
			<description><![CDATA[<span style="font-weight: bold;" class="mycode_b">CTF Platforms (Capture the Flag)</span><ul class="mycode_list"><li><span style="font-weight: bold;" class="mycode_b">HackTheBox</span> (hackthebox.com) - Real-world labs, active community, great for pentesting practice<br />
</li>
<li><span style="font-weight: bold;" class="mycode_b">TryHackMe</span> (tryhackme.com) - More guided, good for beginners, browser-based VMs<br />
</li>
<li><span style="font-weight: bold;" class="mycode_b">PicoCTF</span> (picoctf.org) - Carnegie Mellon's CTF, archived challenges always available<br />
</li>
<li><span style="font-weight: bold;" class="mycode_b">CTFtime</span> (ctftime.org) - Calendar of upcoming CTF competitions worldwide<br />
</li>
<li><span style="font-weight: bold;" class="mycode_b">pwn.college</span> - Arizona State, fantastic for binary exploitation<br />
</li>
</ul>
<br />
<span style="font-weight: bold;" class="mycode_b">Free Learning Platforms</span><ul class="mycode_list"><li><span style="font-weight: bold;" class="mycode_b">OWASP WebGoat</span> - Deliberately insecure web app for learning web vulns<br />
</li>
<li><span style="font-weight: bold;" class="mycode_b">PortSwigger Web Academy</span> (portswigger.net/web-security) - Best free web app security course, full stop<br />
</li>
<li><span style="font-weight: bold;" class="mycode_b">Cybrary</span> - Mix of free and paid courses<br />
</li>
<li><span style="font-weight: bold;" class="mycode_b">SANS Cyber Aces</span> - Free intro to OS, networking, sys admin security<br />
</li>
</ul>
<br />
<span style="font-weight: bold;" class="mycode_b">Certifications Worth Considering</span><ul class="mycode_list"><li>CompTIA Security+ - Good entry-level, vendor-neutral<br />
</li>
<li>CompTIA Network+ - If you want to nail networking fundamentals first<br />
</li>
<li>CEH (Certified Ethical Hacker) - Industry recognised but heavily theory-based<br />
</li>
<li>OSCP (Offensive Security) - Hands-on, respected in pentesting roles, hard<br />
</li>
</ul>
<br />
<span style="font-weight: bold;" class="mycode_b">Books</span><ul class="mycode_list"><li>"The Web Application Hacker's Handbook"<br />
</li>
<li>"Hacking: The Art of Exploitation" - Erickson<br />
</li>
<li>"Penetration Testing" - Georgia Weidman<br />
</li>
</ul>
]]></description>
			<content:encoded><![CDATA[<span style="font-weight: bold;" class="mycode_b">CTF Platforms (Capture the Flag)</span><ul class="mycode_list"><li><span style="font-weight: bold;" class="mycode_b">HackTheBox</span> (hackthebox.com) - Real-world labs, active community, great for pentesting practice<br />
</li>
<li><span style="font-weight: bold;" class="mycode_b">TryHackMe</span> (tryhackme.com) - More guided, good for beginners, browser-based VMs<br />
</li>
<li><span style="font-weight: bold;" class="mycode_b">PicoCTF</span> (picoctf.org) - Carnegie Mellon's CTF, archived challenges always available<br />
</li>
<li><span style="font-weight: bold;" class="mycode_b">CTFtime</span> (ctftime.org) - Calendar of upcoming CTF competitions worldwide<br />
</li>
<li><span style="font-weight: bold;" class="mycode_b">pwn.college</span> - Arizona State, fantastic for binary exploitation<br />
</li>
</ul>
<br />
<span style="font-weight: bold;" class="mycode_b">Free Learning Platforms</span><ul class="mycode_list"><li><span style="font-weight: bold;" class="mycode_b">OWASP WebGoat</span> - Deliberately insecure web app for learning web vulns<br />
</li>
<li><span style="font-weight: bold;" class="mycode_b">PortSwigger Web Academy</span> (portswigger.net/web-security) - Best free web app security course, full stop<br />
</li>
<li><span style="font-weight: bold;" class="mycode_b">Cybrary</span> - Mix of free and paid courses<br />
</li>
<li><span style="font-weight: bold;" class="mycode_b">SANS Cyber Aces</span> - Free intro to OS, networking, sys admin security<br />
</li>
</ul>
<br />
<span style="font-weight: bold;" class="mycode_b">Certifications Worth Considering</span><ul class="mycode_list"><li>CompTIA Security+ - Good entry-level, vendor-neutral<br />
</li>
<li>CompTIA Network+ - If you want to nail networking fundamentals first<br />
</li>
<li>CEH (Certified Ethical Hacker) - Industry recognised but heavily theory-based<br />
</li>
<li>OSCP (Offensive Security) - Hands-on, respected in pentesting roles, hard<br />
</li>
</ul>
<br />
<span style="font-weight: bold;" class="mycode_b">Books</span><ul class="mycode_list"><li>"The Web Application Hacker's Handbook"<br />
</li>
<li>"Hacking: The Art of Exploitation" - Erickson<br />
</li>
<li>"Penetration Testing" - Georgia Weidman<br />
</li>
</ul>
]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[[Rules] Networking & Cybersecurity — Forum Rules]]></title>
			<link>https://talkativeturtles.club/showthread.php?tid=7</link>
			<pubDate>Sun, 21 Jun 2026 09:34:07 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://talkativeturtles.club/member.php?action=profile&uid=1">Zero Two</a>]]></dc:creator>
			<guid isPermaLink="false">https://talkativeturtles.club/showthread.php?tid=7</guid>
			<description><![CDATA[<span style="font-weight: bold;" class="mycode_b">Networking &amp; Cybersecurity</span> covers protocols, infrastructure, security research, CTFs, pentesting, and defensive practices.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Posting Rules:</span><ul class="mycode_list"><li><span style="font-weight: bold;" class="mycode_b">This is a strictly ethical community.</span> Discussion of offensive security techniques is permitted only in educational, CTF, or clearly authorized contexts. Do not ask for help attacking systems you do not own.<br />
</li>
<li><span style="font-weight: bold;" class="mycode_b">No tools or techniques for malicious purposes.</span> Posts requesting help with unauthorized access, credential theft, DDoS, or malware will be removed and the account banned.<br />
</li>
<li><span style="font-weight: bold;" class="mycode_b">Redact sensitive data.</span> If sharing logs, configs, or packet captures, remove IP addresses, credentials, and personal data that are not yours.<br />
</li>
<li><span style="font-weight: bold;" class="mycode_b">Include your topology.</span> Networking questions need your equipment, ISP setup, and relevant IP scheme (use private ranges in examples).<br />
</li>
<li><span style="font-weight: bold;" class="mycode_b">Cite your sources</span> for security advisories and CVEs.<br />
</li>
</ul>
<br />
<span style="font-weight: bold;" class="mycode_b">Remember:</span> "I own the network" claims are not verifiable. Posts that appear to target real systems will be removed regardless of stated intent.]]></description>
			<content:encoded><![CDATA[<span style="font-weight: bold;" class="mycode_b">Networking &amp; Cybersecurity</span> covers protocols, infrastructure, security research, CTFs, pentesting, and defensive practices.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Posting Rules:</span><ul class="mycode_list"><li><span style="font-weight: bold;" class="mycode_b">This is a strictly ethical community.</span> Discussion of offensive security techniques is permitted only in educational, CTF, or clearly authorized contexts. Do not ask for help attacking systems you do not own.<br />
</li>
<li><span style="font-weight: bold;" class="mycode_b">No tools or techniques for malicious purposes.</span> Posts requesting help with unauthorized access, credential theft, DDoS, or malware will be removed and the account banned.<br />
</li>
<li><span style="font-weight: bold;" class="mycode_b">Redact sensitive data.</span> If sharing logs, configs, or packet captures, remove IP addresses, credentials, and personal data that are not yours.<br />
</li>
<li><span style="font-weight: bold;" class="mycode_b">Include your topology.</span> Networking questions need your equipment, ISP setup, and relevant IP scheme (use private ranges in examples).<br />
</li>
<li><span style="font-weight: bold;" class="mycode_b">Cite your sources</span> for security advisories and CVEs.<br />
</li>
</ul>
<br />
<span style="font-weight: bold;" class="mycode_b">Remember:</span> "I own the network" claims are not verifiable. Posts that appear to target real systems will be removed regardless of stated intent.]]></content:encoded>
		</item>
	</channel>
</rss>