3 ms·
"My logs and firewall are less cluttered" is not at all the correct metric to measure the security of your box. IP address spoofing is a thing. Blocking CIDR r
by awsthro00945 5y ago
"My logs and firewall are less cluttered" is not at all the correct metric to measure the security of your box.
IP address spoofing is a thing. Blocking CIDR ranges might protect you from low-effort, drive-by botnets that constantly scan the entire internet (which all should be completely mitigated by using certificate based auth anyway), but blocking based on IP address is absolutely not an effective control against a determined hacker.
You must consider your threat model. For your personal instance that you host hobby things on, you probably won't be targeted via IP spoofing. For any type of company, you should not be relying on CIDR blocking as part of your security layers. CIDR blocking is only effective at reducing the clutter of your logs, which is a convenience, not a security control. The real security control is using proper auth methods, which are so easy to do at this point that it's ridiculous for even a hobbyist to not do them.
- nyolfen 5y agomy understanding is that spoofing only works for sessionless protocols or situations -- eg a single udp packet or a series of packets that do not rely on any kind of response, since the response (like a tcp ack, or a dh handshake) is routed to the spoofed address. this would not apply to ssh. what contexts are you thinking of?
- ianhawes 5y agoYeah, the parent comment is not accurate. IP spoofing is only possible if you control the entire L4 stack.
- DarylZero 5y agoThere's network-level "IP spoofing" and then there's just routing traffic through an IP-diverse botnet.
- awsthro00945 5y agoWhy are you assuming that a determined attacker doesn't control your L4 stack? MITMs are a threat, your network could be compromised, routers (especially consumer routers) are rife with vulnerabilities. This is the entire reason "zero trust" is pushed.
- nyolfen 5y agopeople who control the l4 stack probably aren't brute forcing my ssh server
- awsthro00945 5y ago"the attacker probably won't do that" is not a security control.
- tremon 5y ago"the attacker probably won't do that" is very much part of threat modeling, the #1 step in any serious security design.
- awsthro00945 5y agoIn any serious security design, "the attacker probably won't do that" would and should be shot down immediately. If your security strategy is hoping that an attacker will be kind enough to not exploit your open vulnerability, you've already failed at threat modeling and at security. If an attacker can do it, you must assume they will do it. Because they will. That should be the starting point for any threat model.
- smegsicle 5y ago"the attacker probably won't intercept the mail and install rootkits on brand new hardware" "the attacker probably won't read my password through the wall from the radiation off my keyboard" if your starting point is APT-level adversary then you might as well give up
- lamontcg 5y agoWhat brand of locks do you have on your doors at home and does the lockpicking lawyer have a video of going through them in a few seconds?
- nyolfen 5y ago