A couple of things about Linux security that really hinder ppl / I don’t think are promoted enough:
- People forget to secure VIM. Even if you’ve secured everything, very easy to use the built in mini-shell in VIM to move to the actual shell.
- Look at / focus on your SSH key fingerprints. These things matter. I didn’t pay attention to these things nearly as much as I should have the first two years of my career, but it’s so easy to just intercept your request, grab your private key, and then just pass you on to your regular server without you even knowing.
- Please please secure your web servers. The default configuration can be very difficult to argue is secure, e.g. the fact that every web server reveals out of the box the exact semver of the Apache/Nginx or the lack of automatic HTTPS redirection that would be useful for 90% of modern deployments. Check out Caddy which helps with some of this.