diff --git a/README.md b/README.md index 57158d2..695e4e4 100644 --- a/README.md +++ b/README.md @@ -316,8 +316,8 @@ the tools of your selected mode already in place. Prefer to keep using Windows, macOS, Linux, Android, or iOS? Install Sovran_SystemsOS on a separate computer and let it run quietly on your local network, with or without a monitor. From any other device on the same network, -open a browser, visit `http://sovransystemsos.local`, and manage everything -from [The Sovran Hub](#the-sovran-hub). +open a browser, visit `http://sovransystemsos.local:8937`, and manage +everything from [The Sovran Hub](#the-sovran-hub). Your existing devices stay familiar. Sovran_SystemsOS provides the independent infrastructure behind them. @@ -354,7 +354,7 @@ From one place, the Hub helps you: │ │ │ Windows laptop Phone or tablet Mac or Linux │ │ │ - └──────── Browser: sovransystemsos.local ────┘ + └─────── Browser: sovransystemsos.local:8937 ─┘ │ ▼ ┌──────────────────────────┐ @@ -376,9 +376,10 @@ Keep using the devices you already own. Sovran_SystemsOS becomes the private Bitcoin and digital infrastructure behind them. > **Local access:** the Hub is available at -> `http://sovransystemsos.local` to devices connected to the same local -> network. It is protected by authentication and is not automatically exposed -> to the public internet. +> `http://sovransystemsos.local:8937` to devices connected to the same local +> network (not on Desktop, which publishes nothing). It is protected by +> authentication, answers only your local network, and is not automatically +> exposed to the public internet. --- @@ -536,18 +537,20 @@ Open the Hub directly from the Sovran_SystemsOS desktop, or from any other device on the same local network at: ```text -http://sovransystemsos.local +http://sovransystemsos.local:8937 ``` -Sign in with your Sovran_SystemsOS credentials. +Sign in with your Sovran_SystemsOS credentials. Desktop does not publish the Hub +on the network, so in that mode open it from the desktop.
-If sovransystemsos.local does not open +If sovransystemsos.local:8937 does not open 1. Make sure the Sovran_SystemsOS machine is powered on, and allow it a few minutes to finish starting. 2. Make sure both devices are connected to the same local network, and that - you entered the full address `http://sovransystemsos.local`. + you entered the full address `http://sovransystemsos.local:8937`, + including the `:8937`. 3. Avoid guest Wi-Fi networks, which may prevent devices from seeing one another. 4. Temporarily disconnect any VPN that may interfere with local-network diff --git a/SECURITY.md b/SECURITY.md index fd8f8aa..8b3b340 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -35,21 +35,40 @@ external networks and are outside a “fully offline” model. The local Hub currently uses HTTP. Authentication does not encrypt local network traffic, so use a trusted LAN and avoid public or guest Wi-Fi. -Caddy serves the Hub (`sovransystemsos.local`), Ride The Lightning (port 3051), -and Mempool (port 60847) only to this computer and to clients on your local -network (private, link-local, and VPN addresses), even when ports 80 and 443 are -forwarded to this computer for public services. Other IPv4 clients get the -connection closed. IPv6 global addresses are not filtered. +The Hub is served on port 8937, on its own: Caddy does not front it. Server + +Desktop and Bitcoin Node Only open that port in the firewall, so other devices +on your local network reach the Hub at `http://sovransystemsos.local:8937`. +Forwarding ports 80 and 443 for public services does not put the Hub in front of +the internet, because the only thing Caddy answers on those ports is the public +sites. + +On Desktop Only the Hub is not published at all. It is reachable only from the +machine itself, through the desktop application window on localhost. Desktop +Only is the role most likely to be used away from home, and a root-capable admin +UI has no business listening on a coffee-shop network. +`sovran_systemsOS.hub.directPort = true` in `custom.nix` opens port 8937 if you +do want to reach a Desktop Only Hub from another device. The Hub also checks every client itself, before it shows a login page. It runs as root, so it answers only this computer and the local network (loopback, private, VPN and link-local addresses) and turns everyone else away, however -they reached it. Global IPv6 addresses are turned away too: a laptop on your -network and a stranger on the internet look the same by address alone. If your -devices use addresses outside the local ranges, list their networks in -`sovran_systemsOS.hub.extraLanNetworks` in `custom.nix`; +they reached it. The Hub listens on IPv4 only, so IPv6 clients do not reach it +at all; if that ever changes, global IPv6 addresses would be turned away, +because a laptop on your network and a stranger on the internet look the same +by address alone. If your devices use addresses outside the local ranges, list +their networks in `sovran_systemsOS.hub.extraLanNetworks` in `custom.nix`; `sovran_systemsOS.hub.lanOnly = false` turns the check off. +The check goes by the address a connection comes from. A router that rewrites +that address when it forwards a port makes an outsider look local, so the check +is a second lock and not a reason to forward port 8937: don't. + +Caddy serves Ride The Lightning (port 3051) and Mempool (port 60847) only to +this computer and to clients on your local network (private, link-local, and VPN +addresses), even when ports 80 and 443 are forwarded to this computer for public +services. Other IPv4 clients get the connection closed. IPv6 global addresses +are not filtered. + ### Public services and your home IP address Server + Desktop publishes services under your own domain. The Dynamic DNS diff --git a/app/sovran_systemsos_web/templates/index.html b/app/sovran_systemsos_web/templates/index.html index 45468d5..4bd9a01 100644 --- a/app/sovran_systemsos_web/templates/index.html +++ b/app/sovran_systemsos_web/templates/index.html @@ -264,7 +264,7 @@

Network

LAN…
WAN…
-
sovransystemsos.local
+
sovransystemsos.local:8937
@@ -520,7 +520,7 @@
 

✍️ Write this down now.
- You will need it to log in to your computer
and the Sovran Hub at sovransystemsos.local. + You will need it to log in to your computer
and the Sovran Hub at sovransystemsos.local:8937.