4 ms·
Thinking about it, fail2ban is almost entirely a placebo given that your password should be basically impossible to brute force anyways if you have the knowledg
by boringuser2 3y ago
Thinking about it, fail2ban is almost entirely a placebo given that your password should be basically impossible to brute force anyways if you have the knowledge to implement fail2ban.
- alexchamberlain 3y agoBetter: just ban password logins, and use cryptographic keys instead.
- quickthrower2 3y agoUse Role Based Access Control
- awestroke 3y agoIt can conserve server resources to just stop responding to brute force attacks
- veave 3y agoIf your server is a Gameboy, maybe.
- boringuser2 3y agoA Gameboy would probably have the computing resources to do a thousand such calculations a millisecond.
- blueflow 3y agoAlso disk space - i don't want to keep 500 MB of failed login attempts just to have a week of syslog available.
- boringuser2 3y agoRotate your logs bud. Also, suppressing these logs is the same as rapidly rotating new logs.
- quickthrower2 3y agoIt is not. Deleting my spam folder is not the same as deleting yesterdays email.
- blueflow 3y agoRotating only splits the data up into N files, not make it consume less space for a week of logs.
- veave 3y agologrotate compresses logs.
- seized 3y agoFail2ban can work on more than just sshd.