3 ms·
Some commenters here seem to suggest that the advice on that blog post is somewhat outdated or suboptimal. I'm curious, is there something like a commonly agree
by _stephan 14y ago
Some commenters here seem to suggest that the advice on that blog post is somewhat outdated or suboptimal. I'm curious, is there something like a commonly agreed on best practice for securing/hardening a modern Ubuntu production web server? Would maybe anyone care to provide a bullet point list of the most important steps?
- csense 14y agoThe most important steps are: 1) Making sure SSH only accepts public keys. This removes the possibility of a hacker guessing a password. 2) Use fail2ban. This rate-limits SSH attempts. 3) Keep your packages up-to-date, especially Web applications. 4) Use a default-deny firewall configuration, and make sure your services bind to the localhost interface. Letting the outside world directly talk to your database, Redis and memcache lets someone see your application data without any security checks, and this should only be possible for the application itself.
- _stephan 14y agoThanks!