3 ms·
>Not that there is anything particularly wrong with this, but I find it silly that one should make such customization on their box just to prevent _one_ potenti
by voidlogic 11y ago
>Not that there is anything particularly wrong with this, but I find it silly that one should make such customization on their box just to prevent _one_ potential malware hazard.
I generally drop all inbound and outbound by default and open the ports in the direction (out vs in) I need on the box. Why not take it one step farther and tie each opening rule to the process/user that actually needs it? That seems like an awesome idea.
- crypt1d 11y agoIf this is the only box that you will ever maintain, then sure, knock yourself out. The problem shows up once you start maintaining hundreds of boxes, because you have an overly complex security setup that does not bring any substantial benefit to the table. It becomes just another thing you have to think about every time you redesign your environment, install new tools, etc. You are essentially sacrificing simplicity for a false sense of security.