5 ms·
What sane person exposes SSH externally? - OpenVPN takes only minutes to set up - There are easy to use GUI clients for all major desktops (Windows, Mac OS X,
by pbsdp 13y ago
What sane person exposes SSH externally?
- OpenVPN takes only minutes to set up
- There are easy to use GUI clients for all major desktops (Windows, Mac OS X, Linux) and phones (Android, iOS)
- It supports running with zero privileges (chroot+setuid) since it only needs to forward packets to /dev/(tun|tap), which does not require privileges after the device has been opened.
- It limits your compromise exposure to only one edge gateway (you can put any number of machines behind a single dedicated gateway). If the gateway is pwned, you still have the defense-in-depth of internal SSH, internal encrypted comms, etc.
- Supports HMAC validation of incoming data to avoid any complex processing (and thus exposure of bugs) of packets from users that don't have the shared HMAC key. This means that only the HMAC code is exposed to untrusted users.
- Supports public key +/ password authentication.
There's no reason to expose SSH to the public internet when you can run a gateway that handles only VPN traffic and greatly limits your attack surface. Defense in depth!
- sucuri2 13y agoYou would be surprised. But to say the truth, I trust the OpenSSH code a lot more than any VPN software that you can install to prevent direct access to it.
- achillean 13y agoIt's fairly common actually, at least around 12,860,698 devices have their SSH open to the public (http://www.shodanhq.com/?q=port:22 http://www.shodanhq.com/?q=port:22).
- pbsdp 13y agoThe difference is that exposing OpenVPN code allows you to separate remote access from your production services, both reducing the total attack surface and providing defense-in-depth. On top of which, OpenVPN has actually had fewer security vulnerabilities released than OpenSSH, and HMAC validation enormously restricts the surface area of exposed code as compared to OpenSSH.
- mikegioia 13y agoI don't understand how OpenVPN/PKI is any better than running SSH externally on a different port and strictly using key based auth.
- pbsdp 13y agoOpenVPN: - Exposes less code to attack - Can be run on a single machine, distinct from your production systems, where compromise will only result in a compromise of VPN communications, not of an actual production machine on which your production data/processes exist.
- stock_toaster 13y agoA few people use spiped[1] in similar fashion. [1]: http://www.daemonology.net/blog/2012-08-30-protecting-sshd-using-spiped.html http://www.daemonology.net/blog/2012-08-30-protecting-sshd-u...
- lutorm 13y agoCan't you just run an ssh gateway and accomplish the last goal, though?
- tcoppi 13y agoOne thing you should keep in mind when doing this is all traffic will be routed through the gateway, so if you say had a home desktop connected with a VPS running as the OpenVPN server, connections routed to the home desktop will go through the VPS first. This can be a significant bandwidth/latency addition, depending on your needs. Obviously much less significant if everything will be physically colocated.
- DavidHogue 13y agoOpenVPN can be set to route only certain IP blocks to the tunnel. I sometimes do prefer to route everything over the vpn though, especially at coffee shops that filter specific ports.
- rogerbinns 13y agoYou can (and probably should) setup ssh on one edge gateway and then ssh from that machine to further internal machines. ssh config files make it easy to make multiple steps transparent. I expose ssh externally on the edge gateway (but can't provide evidence for sanity). The major attractions over a vpn is a limit in what traffic gets sent on the ssh connection - by default just the shell, and whatever port forwards are needed. vpns end up forwarding DNS traffic and a bunch of other gunk. They can also expose the client machines to unintended traffic from the remote end.
- JoachimSchipper 13y agoI have considerably less faith in OpenVPN than you do. The "bastion host" concept is fine, but you can do this with SSH, near-transparently even (using ProxyCommand).
- pbsdp 13y agoCan you expand on why? OpenVPN has long been an example of solid development (and crypto) practices. As far as the bastion host, you need an actual VPN to do more than forward SSH connections. For instance, connectivity to your LDAP server, internal web services, etc. Port forwarding gets you part of the way there, but it's inconvenient to use with SSL, requires using weird local port numbers when connecting to services, etc. SSH does have VPN support via tun/tap, but it's not nearly as functionally complete as OpenVPN, and you still have the entire SSH authentication path exposed to the world.
- JoachimSchipper 13y agoOpenSSH has long been an example of solid development (and crypto) practices too, and has had a few less issues. Search for "Use constant time memcmp when comparing HMACs in openvpn_decrypt." (the fix is my colleague's, but the bug was mine.) That said, both are very good, and if you do want a full VPN there's a lot to recommend OpenVPN.
- gwu78 13y agoIs OpenVPN, both the clients and the server, fully open source? Can we look at each and every line of code?