4 ms·
Common the web servers like Nginx, Caddy are not secure? If they found a zero day in these application whole Internet will go up in flames.
by quaintdev 2y ago
Common the web servers like Nginx, Caddy are not secure? If they found a zero day in these application whole Internet will go up in flames.
- robertlagrant 2y agoThe whole internet keeps patching those flaws as they are found. The problem with self-hosting is patching.
- wruza 2y agoThis is a non-problem since the invention of unattended updates. This whole subthread spreads uncertainty and doubt over simple things like nginx or ssh. Service providers don’t patch their software by hand either. 20 years ago, when I was still young and naive, I took these concerns way too serious, remapped ports, believed in pwn, set up fail2ban and knocking, rotated logs. Later I realized it was all just FUD, even back then. You run on 22, 80 and 443 like a chad, use pw-based auth if you’re lazy, ignore login attempts and logs in general and never visit a server until it needs reconfiguration. Just say f* it. And nothing happens. They just work for years, the only difference is you not having tremors about it. The only time a couple of my vpses were pwned in decades was a week after I gave a sudoer ssh key to some “specialist” that my company decided to offload some maintenance to. What changed from back then is that software became easier to set up and config and less likely to do something stupid. Even your dog can run a vps with a bunch of services now.
- denton-scratch 2y ago> And nothing happens. Good luck. Some people have different experiences.
- wruza 2y agoSome people install every php plugin they can find. Recently I gave my coworker an access to a gui server and next day he complained he can't install some chinese malbloatadware on it. People have different experiences due to different paradigms. My message is about not being anxious, not about being clueless. With opensource and how code works in general, we are all in the same boat with bigcorps and megacorps. And they receive the same updates at the same rate (maybe minutes faster cause they host repos). This quote, "you can't be certain the software you use is secure", is technically true but is similar to the "you can't be certain you won't die buying groceries". Perfectly useless fearoid for your daily life.
- tjoff 2y agoI get what you are saying, and if anything all the "attacks" in the logs should build you some confidence. Oh, so 98% of all attacks assume I haven't changed the root password? I must be ahead in the game then. But the way you phrase it isn't really convincing, and for singling out 443 and 80 ports. As the subthread of breaches hint towards. You might not need to be worried about nginx, but whatever you host on nginx might be a problem and being "certain the software you use is secure" is also pretty darn useless as guidance.
- wruza 2y agoHow do you run software? Or if you are using managed hosting or a platform for running software, how exactly they solve this “security strictly < 1, have to run somehow” dilemma?
- tjoff 2y agoFor systems exposed on the internet? * Try to avoid it in the first place. * Do research, minimize risk and make whatever compromises you are willing/able to make * Isolate it * Maintain, update and monitor it At no point am I certain the software is secure.
- wruza 2y agoYou seem to include some absolute security, which is obviously nonexistent in this world (p!=0 for any event according to some models), into your internet exposure formula, when "minimize risk, make whatever compromises, update" is sufficient (to me) and everything above that is just worrying too much without having control. I think that's where we fundamentally disagree.
- tjoff 2y agoI really don't. Be aware of your threat model and the risks associated.
- ricardo81 2y ago>pw-based auth better off using key only logins and forgetting IMO
- mr_mitm 2y agoEven OpenSSH almost got a fatal backdoor recently.
- tiberious726 2y agoWhat planet are you on? Nginx had a 0 day as recently as April 2022 https://www.accuknox.com/blog/nginxday-2022-nginx-ldap-zero-day-vulnerability https://www.accuknox.com/blog/nginxday-2022-nginx-ldap-zero-... This happens _all_ _the_ _time_
- account42 2y agoA very specific one that doesn't affect 99.99% of nginx servers.
- tiberious726 2y ago"If they found a zero day in these application whole Internet will go up in flames." Don't move the goalposts. I'm certainly not saying that nginx is insecure. I'm saying that if you think any piece of software written after the 80s has reached the point where it won't have 0 days anymore you just haven't been paying attention