4 ms·
> And nothing happens. Good luck. Some people have different experiences.
by denton-scratch 2y ago
> And nothing happens.
Good luck. Some people have different experiences.
- wruza 2y agoSome people install every php plugin they can find. Recently I gave my coworker an access to a gui server and next day he complained he can't install some chinese malbloatadware on it. People have different experiences due to different paradigms. My message is about not being anxious, not about being clueless. With opensource and how code works in general, we are all in the same boat with bigcorps and megacorps. And they receive the same updates at the same rate (maybe minutes faster cause they host repos). This quote, "you can't be certain the software you use is secure", is technically true but is similar to the "you can't be certain you won't die buying groceries". Perfectly useless fearoid for your daily life.
- tjoff 2y agoI get what you are saying, and if anything all the "attacks" in the logs should build you some confidence. Oh, so 98% of all attacks assume I haven't changed the root password? I must be ahead in the game then. But the way you phrase it isn't really convincing, and for singling out 443 and 80 ports. As the subthread of breaches hint towards. You might not need to be worried about nginx, but whatever you host on nginx might be a problem and being "certain the software you use is secure" is also pretty darn useless as guidance.
- wruza 2y agoHow do you run software? Or if you are using managed hosting or a platform for running software, how exactly they solve this “security strictly < 1, have to run somehow” dilemma?
- tjoff 2y agoFor systems exposed on the internet? * Try to avoid it in the first place. * Do research, minimize risk and make whatever compromises you are willing/able to make * Isolate it * Maintain, update and monitor it At no point am I certain the software is secure.
- wruza 2y agoYou seem to include some absolute security, which is obviously nonexistent in this world (p!=0 for any event according to some models), into your internet exposure formula, when "minimize risk, make whatever compromises, update" is sufficient (to me) and everything above that is just worrying too much without having control. I think that's where we fundamentally disagree.
- tjoff 2y agoI really don't. Be aware of your threat model and the risks associated.