3 ms·
What threat model does fail2ban prevent, that couldn’t just be solved by using secure credentials?
by ahepp 3y ago
What threat model does fail2ban prevent, that couldn’t just be solved by using secure credentials?
- dreamcompiler 3y agoLet's say you lock your house's front door with a secure pass phrase while you're still inside. Once per second some stranger walks up to your door and knocks. You now get up from your chair, go to the door and say "Pass phrase please?" The knocker says "password123" and you say "Wrong, go away." But one second later they come back and knock and you have to get up and go to the door again. And again. And again. The bad guys never get in because they only try stupid passwords, but the constant getting up and going to the door gets pretty tiresome. So you get a dog, you put it outside your door and you train it to keep away for one minute any stranger who knocks but fails to get in. Now you have a lot more peace because you're not getting out of your chair every second to ask the pass phrase from some rando. Fail2ban is the dog.
- ahepp 3y agoI have seen a lot of failed connection attempts in my logs, but never noticed substantial resource usage. Is SSH DoS a serious concern? I get the impression people are suggesting it to protect authentication, which makes basically zero sense to me.
- dreamcompiler 3y agoF2B shrinks the attack surface. There's almost no chance of somebody getting in if you secure your server properly, but "almost no" is not zero, and making it even closer to zero seems like a good idea. My main concern is that some future update to SSHd will contain a zero-day vulnerability and F2B would at least slow the bad guys down. My second concern is that I might spin up a server and forget to disable SSH passwords and leave one enabled that happens to show up in a password database. Oof.