5 ms·
Is it? If you've got `PasswordAuthentication` disabled, only allow public key logins and keep your system up to date. Honest question. I self host my email ( d
by waingake 2y ago
Is it? If you've got `PasswordAuthentication` disabled, only allow public key logins and keep your system up to date. Honest question.
I self host my email ( docker-mailserver ) and host my personal website on an old laptop with a static IP. Have done for years now without issue.
- pkrotich 2y agoThe keyword is diligently keeping your system up to date! That said you’ll still have exposure to zero day vulnerabilities and DOS attacks.
- kristopolous 2y agohttps://wiki.debian.org/UnattendedUpgrades https://wiki.debian.org/UnattendedUpgrades Most distros have something like this.
- Beijinger 2y agoThis reminded me of: https://github.com/ajgon/self-hosted-mailserver/blob/master/docs/my-first-5-minutes-on-a-server-or-essential-security-for-linux-servers.md https://github.com/ajgon/self-hosted-mailserver/blob/master/...
- Fabricio20 2y agoBut an attacker with one of the biggest vulnerabilities on earth (hell, ssh noauth 0day) would very likely use it against big cloud providers and infrastructure (isps and others) and not burn it on your home server! Keeping it reasonably up to date with your distro's cycle is probably enough for most people doing this home server thing. So of course, as things always are with security this is a matter of risk assessment and understanding your attack surface, a server with only public key and maybe on a special port goes a very long way, add fail2ban on top and i'd say it's probably fine for quite a while. But that does make me think... what if... a wormable noauth 0day like that on ssh or some other popular system... how fast could it replicate itself to form the biggest botnet.. how long would it take, to take over all visible linux servers on the internet (so that your little home box ends up being a target)? I guess at that point you are limited by bandwidth, but since you can scale that with every compromised server... hope someone does the math on that one day!
- rcxdude 2y agoIpv4 is only 4 billion addresses. It doesn't actually take very long to just try all of them. If you're running a service exposed to the internet and it has a published exploitable vulnerability, it's just a matter of time before it gets exploited. (that said, that time does give a little buffer for patching)
- Beijinger 2y ago"I self host my email " Is this still possible? Are your emails getting delivered? Downvoted. I don't know when the downvoter tried the last time to "host their own email". Yes, DMARC, DKIM und SPF. Good luck trying to get your email deliverd to t-online or something. https://forum.hestiacp.com/t/t-online-curious-story-about-the-acceptance-of-third-party-emails/3675/7 https://forum.hestiacp.com/t/t-online-curious-story-about-th... They may even check if your domain has an "imprint". I kid you not. I use my own domains too, but I piggyback with infomaniak.com
- johnklos 2y ago> Good luck trying to get your email deliverd to t-online or something. People who say it cannot (or should not) be done should not interrupt those who are doing it. The dismissiveness is likely why you are downvoted, I'm guessing. The suggestion that because it's hard for you and therefore you're surprised others are doing it isn't a good look. Self hosting email isn't that hard, and there are many solutions for all sorts of self hosting issues. That's a topic for another discussion, though.
- Beijinger 2y ago"Self hosting email isn't that hard". Self hosting is super easy. Getting your emails delivered is hard. And I am not even talking SPAM folder here (see t-online example). Smart comment from reddit: "The problem with selfhosting email, unlike selfhosting services like Jellyfin or Nextcloud, is that you rely on other people's servers to play ball with you, but they often don't. Or they play for a while and then suddenly decide not to without telling you. It's unpredictable and we selfhosters don't have enough control over that." This describes it pretty well.
- pja 2y ago> Is this still possible? Are your emails getting delivered? Mine are. Although it probably helps to have a static IP with a 25 year long clean history. Are there very occasional glitches? Sure. But I've seen ISPs drop everything from GMail on the floor for no obvious reason. I've seen GMail drop GMail email before. Same for every other large email provider. To date I haven't seen any reason strong enough to push me to switch to a centralised email host. That day may yet come of course.
- Beijinger 2y ago"PasswordAuthentication disabled" not sure I can even do this on my shared BSD server. I have ssh access via pw and need it. Is this really dangerous?
- johnklos 2y agoIt is, if for no other reason than you never know when some other user has a guessable password. You should switch everyone to ssh keys. It's a good excuse to learn :)
- Scramblejams 2y agoYes, it's risky to accept password auth if someone sharing the box with you has a poor password. They could do things like: . Install a spam or brute force password bot, which could get the machine kicked off its internet connection (in addition to whatever havoc it causes first) . DoS the server by filling up the disk or using too much RAM (are quotas enforced?) . Exploit a local vuln to get root, if such exists on that box. (Is the kernel promptly patched and the box rebooted?) . Explore other users' directories (are permissions locked down correctly across users?) …and more thrilling possibilities! Embrace key auth. Future you will thank you.
- sneak 2y agoYes. Authenticating with passwords is obsolete and dangerous. Use keys and disable password auth.
- tpoacher 2y agoAnd if you really like passwords, you could always enable both, too!
- fragmede 2y agoHow good is your password? If it's long, with special characters, it's fine. Install fail2ban. The problem with auth keys is you can't get into the server if you don't have your laptop/phone/NFC device because you got pickpocketed/mugged?