4 ms·
Not that there is anything particularly wrong with this, but I find it silly that one should make such customization on their box just to prevent _one_ potentia
by crypt1d 11y ago
Not that there is anything particularly wrong with this, but I find it silly that one should make such customization on their box just to prevent _one_ potential malware hazard. There are hundred other ways that an infected machine can be abused, so IMHO prevention should be done based on attack vectors - that is stopping the machine from getting infected in the first place.
- voidlogic 11y ago>Not that there is anything particularly wrong with this, but I find it silly that one should make such customization on their box just to prevent _one_ potential malware hazard. I generally drop all inbound and outbound by default and open the ports in the direction (out vs in) I need on the box. Why not take it one step farther and tie each opening rule to the process/user that actually needs it? That seems like an awesome idea.
- crypt1d 11y agoIf this is the only box that you will ever maintain, then sure, knock yourself out. The problem shows up once you start maintaining hundreds of boxes, because you have an overly complex security setup that does not bring any substantial benefit to the table. It becomes just another thing you have to think about every time you redesign your environment, install new tools, etc. You are essentially sacrificing simplicity for a false sense of security.
- rwmj 11y agoIt's a another example of enumerating badness: http://www.ranum.com/security/computer_security/editorials/dumb/ http://www.ranum.com/security/computer_security/editorials/d... which is prevented by only permitting traffic that is supposed to be on your network / going through your NIC.
- ars 11y agoIt's not to prevent just one malware. Virtually all malware (on servers) these days has just one goal: send spam. Plus outbound spam has a very visible and detrimental impact on your reputation so warrants extra defense.
- verroq 11y agoSpam AND DDOS.
- colinbartlett 11y agoIs mining Bitcoin on owned boxes not a thing anymore? I guess because the difficulty has risen too high for ordinary CPUs?