If there happens to be some mental TLS handshake RCE that comes up, chances are they are all using the same underlying TLS library so all will be susceptible…
Among common reverse proxies, I know of at least two underlying TLS stacks being used:
- Nginx uses OpenSSL.
- This is probably the one you thought everyone was using, as it’s essentially considered to be the “default” TLS stack.
- Caddy uses
crypto/tls
from the Go standard library (which has its own implementation, it’s not just a wrapper around OpenSSL).- This is in all likelihood also the case for Traefik (and any other Go-based reverse proxies), though I did not check.
No idea about the Lemmy hosting bit, but I highly doubt that .com you got will renew at $1 going forward. Judging by this list it’ll most likely be $9+ after the first year.
At $1/year, the registrar you used is taking a loss because they pay more than that to the registry for it. They might be fine with that for the first year to get you in the door, but they’d presumably prefer to be profitable in the long term.