3 ms·
Do you ever configure, type or have to share MAC addresses? Probably not. On the other hand, most devs / technical staff type IPs into the browser and terminal
by i_like_to_post 6y ago
Do you ever configure, type or have to share MAC addresses? Probably not.
On the other hand, most devs / technical staff type IPs into the browser and terminal daily.
- kortilla 6y ago> On the other hand, most devs / technical staff type IPs into the browser and terminal daily. No they don’t. Configure a DNS server and type these in once. Any time I see IP addresses passed around it’s a sign of broken infrastructure. (It also means you aren’t using tls or you’re training people to accept cert errors)
- i_like_to_post 6y ago> No they don’t Oh yes they do. > Any time I see IP addresses passed around it’s a sign of broken infrastructure Nope. > It also means you aren’t using tls or you’re training people to accept cert errors So, let me get this straight. You have a server that's behind CloudFlare, and you're claiming we should use DNS and TLS to SSH into it?
- Symbiote 6y agoIPs should be passed to the DNS server, yes. Every server/VM I control (~200) has a DNS entry. Every active IP has a reverse (PTR) entry. I have a monitoring task to check for missing DNS entries, as it usually suggests a problem (i.e. we've deployed or undeployed something incompletely).
- kortilla 6y agoI think you’re confused a bit, so let’s split apart the use cases to be clear why IPs are bad in both cases. You said devs and technical staff were typing IPs into their browsers. Presumably this means the address bar, which breaks TLS. SSH derives a big chunk of security from key caching. If you’re using IPs you now can’t have an IP change without triggering key warnings on the SSH clients for a new key at a minimum or (worst case) a breach.
- i_like_to_post 6y ago> You said devs and technical staff were typing IPs into their browsers. Presumably this means the address bar, which breaks TLS. Looks like you got confused. I didn't say that. You just assumed that. > SSH derives a big chunk of security from key caching. No, it does not. It is pointless to fill DNS entries for hosts that are supposed to have their IPs hidden behind DDoS mitigation services like CloudFlare. The whole purpose of the exercise is to not leak the IP addresses. You SSH into your servers via IP, the IP gets cached with the key. There is no difference compared to having a DNS entry, except for the fact that you do not leak the server IP. > If you’re using IPs you now can’t have an IP change No one wants IP changes on externally facing hosts. You keep the IP static and if something happens with the server, you just reassign the IP.