3 ms·
I used digital ocean for hosting a wordpress blog. It got attacked pretty regularly. I would never host an open server from my own home network for sure. Thi
by virtue3 1y ago
I used digital ocean for hosting a wordpress blog.
It got attacked pretty regularly.
I would never host an open server from my own home network for sure.
This is the main value add I see in cloud deployments -> os patching, security, trivial stuff I don't want to have to deal with on the regular but it's super important.
- tadfisher 1y agoWordpress is just low-hanging fruit for attackers. Ideally the default behavior should be to expose /wp-admin on a completely separate network, behind a VPN, but no one does that, so you have to run fail2ban or similar to stop the flood of /wp-admin/admin.php requests in your logs, and deal with Wordpress CVEs and updates. More ideal: don't run Wordpress. A static site doesn't execute code on your server and can't be used as an attack vector. They are also perfectly cacheable via your CDN of choice (Cloudflare, whatever).
- manmal 1y agoA static site does run on a web server.
- rrix2 1y agoa static site is served by a webserver, but the software to generate it runs elsewhere.
- manmal 1y agoYes. And a web server has an attack surface, no?
- mikepurvis 1y agoI think it’s reasonable to understand that nginx/caddy serving static files (or better yet a public s3 bucket doing so) is way, way less of a risk than a dynamic application.
- moehm 1y agoYes, but the web server is just reading files from disk and not invoking an application server. So if you keep your web server up to date, you are at a much lesser risk than if you would also have to keep your application + programming environment secure.
- manmal 1y agoThat really depends on the web server, and the web app you'd otherwise be writing. If it's a shitty static web server, than a JVM or BEAM based web app might be safer actually.
- moehm 1y agoUh, yeah, I thought about Nginx or Apache and would expect them to be more secure then your average self-written application.
- codegeek 1y agoThe thing with WordPress is that it increases the attack area using shitty plugins. If I have a WP site, I change wp-config.php with this line: define( 'DISALLOW_FILE_EDIT', true ); This one config will save you lot of headaches. It will disable any theme/plugin changes from the admin dashboard and ensures that no one can write to the codebase directly unless you have access to the actual server.