3 ms·
Does it _harm_ security?
by killaken2000 8y ago
Does it _harm_ security?
- throwawaymath 8y agoNo, but it is non-standard. Why do things you don't need to?
- xorcist 8y agoPerahaps not directly, but it does add to cognitive overhead and makes securing the system as a whole more difficult. If your environment contains multiple ssh servers running on non-standard ports you would not notice when something out of the ordinary happens. Something listening to an unexpected port should be something you must look into, not shrug at.
- romeisendcoming 8y agoSo standardize on a non-standard port, document it and when you do have ssh probes assume it's targeted rather than just another l33t child running du-jour crack(x). Moving to non-standard means more sophisticated discovery and possibly a more sophisticated attempt.