4 ms·
Whilst I agree philosophically with you, if you see a reduction on in your logs of this unwanted traffic, then it serves a purpose. And that's the point here. T
by dachryn 4y ago
Whilst I agree philosophically with you, if you see a reduction on in your logs of this unwanted traffic, then it serves a purpose. And that's the point here. There is no claim that this is a good safety precaution, but the claim is that it is underrated, and at least that its worthwile to reduce some of the junk.
Its not because something isn't perfect, that it's not worth doing
- throwawaaarrgh 4y agoTurn off logging. It will have the same effect (you won't see brute force attacks on common ports) with the same security. You could also add 2 IPTables rules which would temporarily block all connection requests after hitting a threshold. But I guess actually stopping a brute force attack is less "cool" than changing a port number.
- heinternets 4y agoOn what planet is being blind to attempts the same effect as a massive reduction in hits or logon attempts?
- bakugo 4y agoWhen those attempts are guaranteed to always fail because your server is properly secured, there's no reason to even care that they're happening.
- boopboopbadoop 4y ago… so not this planet
- dan_mctree 4y ago>properly secured Saying those words and imagining it is so does not make it so. Nothing is fully safe and seeing that attitude makes it even less likely it is
- throwawaaarrgh 4y agoI agree. That said, it's clear that a culture of "obscurity is fine" is not helpful either. From first principles, what is security through obscurity? It's literally security though something being vague, old, out of date, little known. That can work. If your physical network is so old that nobody has a network card to plug into it, then they can't hack it. And maybe it works great most of the time. Until somebody finds an old token ring card and laptop. The problem is, it's only as "secure" as the old school knowledge of the hacker. With an old enough blackhat, all security via obscurity becomes shallow. So as a practice, it's always defeatable. Real security countermeasures resist all known attacks. Otherwise anything that fools a script kiddie would be valid security.