5 ms·
“Default configurations of software and applications” The fact it’s 2023 and software still doesn’t ship with secure defaults blows my mind. OpenBSD has been
by pnpnp 3y ago
“Default configurations of software and applications”
The fact it’s 2023 and software still doesn’t ship with secure defaults blows my mind.
OpenBSD has been pushing secure defaults for a long, long time.
- j0hnyl 3y agoI think it's easier said than done in practice. What it means to have secure defaults varies based on what the production environment looks like, and the reality is that most software is feature rich and isn't usually intended to run in production out of the box, which is what makes a lot of the default configurations insecure.
- sumtechguy 3y agovery much this. one package I work with to be secure requires an LDAP server already setup correctly plus TLS packages already to go signed by a proper root certificate. Secure by default in that case would be tough.
- PhilipRoman 3y agoIIRC typing "apt install sshd" (or whatever the package name is), is enough for Ubuntu to start a systemd service with password authentication enabled, so we are definitely far away from having secure defaults even for the most basic things.
- j0hnyl 3y agoFair enough!