2026-10-07
ECH (Encrypted Client Hello) — a TLS 1.3 extension that encrypts the first handshake message, ClientHello. The main thing it hides is the site name in the SNI field. Without ECH any node between you and the server can …
Read more2026-10-05
Under the phrase “TLS type” people usually mean different things: protocol version (1.2 or 1.3), cipher suite, certificate type (DV, OV, EV) or a scheme where the client also presents a certificate (mTLS). In this part — …
Read more2026-09-30
HTTP has three versions in active use: HTTP/1.1, HTTP/2, and HTTP/3. Methods, headers, and status codes are the same across them, so an application usually doesn’t care which version a request arrived with. The …
Read more2026-09-22
How deployment and admin panels are organized: phpMyAdmin and RabbitMQ behind nginx The choice between phpMyAdmin and Adminer for managing the database via browser is discussed in the article “phpMyAdmin, Adminer or …
Read more2026-09-22
Vaultwarden — an unofficial implementation of the Bitwarden server in Rust (AGPL-3.0 license; as of September 2026 the current version is 1.37.3). It requires significantly fewer resources than the official server, works …
Read more2026-09-22
WordOps — an open-source (MIT) command-line tool for deploying and maintaining WordPress sites on your own VPS. It installs and configures the web stack, creates sites with the desired caching option, and issues …
Read more2026-09-22
LAMP and LEMP are two classic stacks for PHP sites: Linux, a web server, a database, and PHP. They differ by the web server: LAMP uses Apache, LEMP uses Nginx. In practice the more important difference is how the web …
Read more2026-09-22
Chats, notifications, market quotes, collaborative editing, and neural network responses that appear as words — all of this requires the server to push data to the client immediately, without repeated requests. HTTP is …
Read more2026-09-22
Caddy, Traefik, HAProxy, Nginx and Apache solve overlapping problems — they accept HTTP requests, terminate TLS and forward traffic to applications — but they are built differently and are good in different places. Below …
Read more2026-09-22
Fail2ban protects each server individually: it only sees its own logs and doesn’t know that the same addresses attacked thousands of other machines a minute ago. CrowdSec solves the same problem — detect attacks …
Read more