To me that sounds like enabling HTTPS is actually a risk here…
To me that sounds like enabling HTTPS is actually a risk here…
Even within infosec, certain types of information disclosure are considered security problems. Leaking signed up user information or even inodes on the drives can lead to PCI-DSS failures.
Why is broadcasting your records treated differently? Because people would find the information eventually if they scanned the whole internet? Even then they might not due to SNI; so this is actually giving critical information necessary for an attack to attackers.
With the public ledger or not, you will still need to implement proper security measures. So it shouldn't matter if your address is public or not, in fact making it public raises the awareness for the problem. That's the argument.
Until it gets obscure enough that we start calling it “public-key cryptography”. Guess the prime number I'm thinking of between 0 and 2↑4096 and win a fabulous prize!
The problem with using regular everyday obscurity is that it usually has a small state space and makes for terrible security, but people will treat it like it is cleverly hidden and safe from attackers
If I guess the IPv4 you're thinking of between 0 and 2↑32, ready or not, you win a free port scan
Trying every 256bit number gets into a "slightly" larger problem.
Forget about the internet, we've had almost 100 years to prove we can secure identity theft. And the best thing we can do is to keep our SSN's secret -- security through obscurity. Keeping your SSN private reduces your personal attack surface.
We've had 50 years to secure the internet, and yet, we still have zero day attacks. Nuclear submarines try their best to keep their locations a secret? Why? You cannot attack something you cannot see or hear.
Just because its a finite space that may eventually be discovered is a poor reason to announce where things are!
Besides, the time to scan the whole board is too time consuming in a battleship game, but scanning the whole internet on the other hand only take a few minutes[1]
If you can scan 1M ipv6's in a second, you can maybe scan 1 subnet in 584,942 years.
So if you're a firewall, and you notice scanning from a particular ip or network, it's easy enough to block them.
Also if you are scanning IPv4, you're not scanning addresses behind the NAT'd routers -- which is also effectively a form of obfuscation. So I would argue it's not the entire internet.
and work for identity validation,
as long as you don't farm it out to a cheap, know-nothing vendor.
If something was temporary then it’s likely that it wouldn’t have been found in a meaningful amount of time to be exploited.
As an only line of defence it’s not good, but its also not good to hand-deliver your entire personal information to fraudsters and then claim that the systems should be more robust.
But painting a target on your back is not exactly justified just because hiding yourself isn’t a good defence in of itself.
In any case, I think we agree.
Depends on the site I expect. My low value domains get NO ssh attempts on my random ports. The high value ones get a few each week.
The context of the conversation is that the address becomes publicly visible so you get hit with port scanners and script kiddies looking for vulns. Moving off standard ports does help but many of those are also going to look at ports like 2222 or 8022 and treat them as ssh.
It's not hard to just send something like `nmap -sV -p- <ADDRESS>` (or better, use like rustscan.) and you'll discover those ports and the services.
On the other hand, just install something like knocked and you don't have to do much. Knocking is not a difficult thing to set up.
And if you use it as a VPN and don't turn on the funnel feature, your service won't be exposed.
> On the other hand, just install something like knocked and you don't have to do much. Knocking is not a difficult thing to set up.
Neither is wireguard.
Presumably wireguard was already being used?