4 ms·
It's really not weird, that's not how security works. What the application is doing is relevant to application security, but the whole point of securing the OS
by linuxdude314 3y ago
It's really not weird, that's not how security works.
What the application is doing is relevant to application security, but the whole point of securing the OS is to eliminate the necessity for "trusting" the application.
When you are securing an operating system, you must assume the application that is exposed to the operating environment (be that the internet, local LAN, even simply user logged into the workstation in the case of a GUI or CLI app) is compromised.
The primary goal of most security measures is preventing and detecting privilege escalation and lateral movement within the OS or network.
There are a lot of best practices that apply in general to securing an operating system. If you want to dig deeper, one of the best resources for this information is provided by CIS (Center for Internet Security).
CIS has hardening standards for most OS's yes even including Ubuntu.
https://www.cisecurity.org/benchmark/ubuntu_linux https://www.cisecurity.org/benchmark/ubuntu_linux
These are standards that many security conscious organizations apply to their servers. The US government takes it a step further with DISA's STIGs.
DISA STIG's are similar to CIS's benchmarks, but result in an even more locked down environment and place extreme restrictions on which crypto libraries are allowed to be used.
In short, securing the OS is a standard best practice that all organizations should be doing. Unfortunately most startups lack engineers with the expertise in building custom linux images so a lot of folks are quite unfamiliar with hardening procedures.
You should absolutely NOT use a non-standard OS because you think it will be more secure. It's a much better idea to use known industry standard security benchmarks on supported Linux distributions than trying to bake your own standard some non Debian/RHEL based bistro.
- doublepg23 3y agoIME the checklists and guides can be a useful resource but are mostly “cover your a$$” documentation, often time falling into cargo cult suggestions just to add more check-boxes.
- linuxdude314 3y agoYou must be using the wrong 'checklists' (they aren't checklists, they are implementation guidelines). CIS benchmarks and DISA STIGs provide concrete actions that lead to a more secure system. Sure some of them might not apply specifically to your environment, but in general they are an excellent starting point. Some of the line items can be a bit arcane or not as relevant in cloud environments, etc... but that's a far cry from calling them CYA. Nothing cargo cult about enabling SE Linux, restricting access with IP tables, configuring AuditD and AIDE.
- walth 3y agoI'm still not sure on how disabling the crypto algorithms that the NSA prefers to not break helps us stay more secure...
- linuxdude314 3y agoIf a single line item that seems irrelevant to you makes you think the whole process of security hardening is useless, you are a fool. Frankly you sound like the tired BOFH trope, if you don't see the benefits of security hardening I hope you are never responsible for anything important infrastructure wise in your organization.
- generalizations 3y ago> Nothing cargo cult about enabling SE Linux, restricting access with IP tables, configuring AuditD and AIDE. These are great ways to massively overcomplicate your system. Generally speaking, having encountered these tools, do not use them unless you're willing to dedicate about 2x the time you would otherwise spend administering the system.
- jdhendrickson 3y agoJust because you had difficulty does not mean you should give such advice to others. There is nothing difficult about configuring any of these systems if you know what you are doing.
- generalizations 3y agoTime consuming & tedious & error-prone != difficult.