3 ms·
Ky feelings on egress port blocking have been one of the big changes in cyber security over the years, and I think a lot of best practise guides will take years
by technion 2y ago
Ky feelings on egress port blocking have been one of the big changes in cyber security over the years, and I think a lot of best practise guides will take years to catch up.
At one point you could restrict egress to certain ports and be reasonably confident in what was going on on a network. These days basically everything is tunnelled over port 443, including most malware communication.
- RedShift1 2y agoAnd then you have applications like Skype that need all ports: https://support.microsoft.com/en-us/skype/which-ports-need-to-be-open-to-use-skype-on-desktop-fe63a90c-f4a8-492c-8926-f3c3b2681a14 https://support.microsoft.com/en-us/skype/which-ports-need-t...
- zokier 2y agoAnd big part why everything is going through 443 is because of overzealous netadmins blocking everything else.