• sanzky@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      4 hours ago

      and then you are giving access to your lan to people whose computer you don’t control and might be full of malware.

      • FauxLiving@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        4 hours ago

        You only have to give them access to a specific port on a specific machine, not your entire LAN.

        My VPN has a ‘media’ usergroup who can only access the, read-only, NFS exports of my media library.

        If you’re just installing Wireguard and enabling IP forwarding, yeah it would not be secure. But using a mesh VPN, like Tailscale/Headscale, gives you A LOT more tools to control access.

    • Hammersamatom@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      2
      ·
      edit-2
      5 hours ago

      Oh absolutely, difference being that you only need to expose the service once, versus helping however many people set up VPNs to access the service on your LAN

      I know way too many people who won’t remember to toggle it on, or just won’t deal with it

      It’s just not convenient enough