3 ms·
People keep mentioning fail2ban. I claim that both this new behavior in sshd, and fail2ban, are unprincipled approaches to security. Now, I know fail2ban is a c
by enasterosophes 2y ago
People keep mentioning fail2ban. I claim that both this new behavior in sshd, and fail2ban, are unprincipled approaches to security. Now, I know fail2ban is a crowd favorite, so let me explain what I mean by unprincipled.
This is the problem fail2ban (and now sshd) try to solve: I want a few people to log into my computer, so I open my computer to billions of other computers around the world and allow anyone to make a login attempt, and then I want to stop all the illegitimate attempts, after they were already able to access port 22.
It's simple Bayesian probability that any attempt to head off all those illegitimate accesses will routinely result in situations where legitimate users are blocked just due to random mistakes rather than malicious intent. Meanwhile, illegitimate attempts continue to come en masse thanks to botnets, allowing anyone with an ssh exploit the chance to try their luck against your server.
A more principled approach to security is to not roll out the welcome mat in the first place. Instead of opening up sshd to the world, allowing anyone to try, and then blocking them, instead don't open up sshd to the world in the first place.
1. If possible, only permit logins from known and (relatively) trusted networks, or at least networks where you have some recourse if someone on the same network tries to attack you.
2. If access is needed from an untrusted network, use wireguard or similar, so sshd only needs to trust the wireguard connection. Any attempt at illegitimate access needs to crack both wireguard and ssh.
With those one or two simple measures in place, have another look at your sshd auth logs and marvel at the silence of no one trying to attack you a million times per day, while also having confidence that you will never accidentally lock yourself out.
- marshray 2y ago1. Sure, there may be cases where you already know the source IP or network block. But there are many scenarios where your legitimate users may be traveling, or using a mobile provider that won't guarantee much about the source IP. If you open your firewall too wide, a sophisticated attacker can find some box they can proxy through. 2. Doesn't wireguard then have the same challenge as SSH? Isn't that just pushing the problem around? Another way to cut down on the log spam is by configuring sshd to listen on a nonstandard port.
- enasterosophes 2y agoYou must have missed the part where I said "Any attempt at illegitimate access needs to crack both wireguard and ssh." It doesn't push the problem to wireguard. It requires wireguard to be broken as a pre-requisite for trying their hand at your sshd, and then they also need to break your sshd.
- aflukasz 2y ago> Doesn't wireguard then have the same challenge as SSH? Isn't that just pushing the problem around? Yeah, it's actually weird how frequently in those discussions people say some version of "just use vpn". I guess they really mean "just make someone else responsible".