Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ohboyacomment
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
ohboyacomment
14y ago
Well, since you outright said I was wrong ... > It's almost always a good idea to change ssh to a high-port [citation needed] > QoS is irrelevant to most You sure? QoS is even in consumer routers these days. I'm speaking from exper
2.
▲
by
ohboyacomment
14y ago
Well, that's omitting the rules required to get an SSH packet to that chain. I also hope you've already ACCEPTed ESTABLISHED,RELATED so we're only considering these rules on new connections, otherwise you've entirely locked out SSH after th
3.
▲
by
ohboyacomment
14y ago
And then pound your desk in frustration when Postgres goes down on the box and your clever little firewall locks you out on your third connection attempt. Leaving your entire site down for the 60 minutes your firewall takes to release the l
4.
▲
by
ohboyacomment
14y ago
Locking yourself out of the machine lies that way. Strongly, strongly advise against. But, yes. There's an iptables module called ipt_recent[1] that will do what you're after. It's been built-in for ages and you don't need to install it. Yo
5.
▲
by
ohboyacomment
14y ago
For anybody considering fail2ban here, install keys and disable passwords via SSH ( don't remove the password from root as most naïve administrators suggest, since most hosting shops will give you tty1 access; just set PermitRootLogin with
6.
▲
by
ohboyacomment
14y ago
Oh, your comment is specific to this DigitalOcean scenario now? Because when you left it, it was phrased as a generality for systems administration, where you "FTFY"'d (God, I hate that) the person you are replying to in order to mock him f
7.
▲
by
ohboyacomment
14y ago
If you do your own sysadmin/devops, you are certainly guaranteed to be dealing with imperfect systems. (It's very likely worse to do your own unless you have the resources to do it right. Hosting companies have scale. Not defending Digita
8.
▲
by
ohboyacomment
14y ago
What is it, exactly, that you expect to be running and 'default open vulnerable' on a fresh Ubuntu install? On my fresh Ubuntu deploys at Linode, the only network service listening is SSH. (Lest we forget that an open port is not a security