3 ms·
Example: if you restrict things to not being useful for most organizations then you can do it safer? Except, which is less likely to be owned and have no impact
by count 6y ago
Example: if you restrict things to not being useful for most organizations then you can do it safer?
Except, which is less likely to be owned and have no impact on your business, S3 or some janky home baked web server?
Are you staying up on every single dependency and security vulnerabilities present in that entire stack of gear (you aren't hooked up a web server directly into a provider backbone...so you've got routers, switches, an OS, firmware, the web server software, a building to hold it all in, etc. etc.).
Even something so absolutely simple as 'serve static web pages' has a huge cross cutting set of things keeping it functioning.
Do you have guards preventing someone from just walking out with the drive on that single machine? Is the data encrypted? Is it backed up? Is the backup offsite? Is the backup offsite encrypted? Who's got the keys? Are the keys backed up? Who's got access to the key backups?
Etc. etc. etc.
- permille42 6y agoHaving a "home baked server" in no way means it is "janky". There are some pretty clear and correct ways to setup a secure server these days. Using an OS such a RHEL gives some guarantees about auditing for vulns being done already for you. You don't have to take on the responsibility for analyzing everything yourself. CentOS historically gives some of the same benefits. What do you think Amazon uses internally for Amazon.com? They use a variant of RHEL. ( albeit a really old "jankified" version ) I'm not suggesting you run the server over home networking. ( which is against TOS by the way ) You can own your own server and place it in a good Colo facility who are already handling the power, routing, etc. I previously wrote the management software for a major company that handles configuration and setup of all their data centers. I know a thing or two about what is necessary. Redundant power and networking with monitoring of both is essential, and also common and easily available in a decent colo. You can of course use a bottom dollar colo that just throws some shit together, but you will, as you say, risk there being vulns in the stack outside your server. That said, it isn't hard either to setup your own data center from nothing. You need multi-phase power, redundancy, and a number of components that are somewhat costly for an individual, but there are reasonably affordable options these days. You can get 220 in the home if you pay for it. I'd recommend having a commercial location pre-setup with it though of course. Preferably you'd want your data center near a major internet hub and/or with connections to multiple major internet providers... And yes. I have guards from someone walking away with my equipment. I have a gun and I'm happy to shoot any intruder in the face with it. All my drives are encrypted as well and if there was a breakin they will auto-shutdown... I own enterprise level tape backup equipment and hundreds of tapes. So yes: offsite backup that is encrypted. The keys are backed up and encrypted themselves. You can go down the rabbit hole as far as you like. My setup is still more secure than Amazon and the like.