19 karma · joined February 17, 2019
And yes, I saw that pull request but I didn't know what HN was at that time. After I saw that comment, and before they said HN = Hacker News, I started Googling around to see if I could find where my repo was being mentioned. That is how I found this post in HN.
Thanks!
Thanks for that link -- never seen it before.
I was an SA for a Fortune 10 company for 5+ years supporting 150k+ servers but we don't need to get into comparing resumes here. I appreciate your time and don't want to waste more of it. However, if would like to continue the discussion maybe we can do it on GitHub? I don't care for HNs commenting style. Thanks!
I simplified things that would be too heavy to get into. The guide is not intended to teach everything about security -- that would be too much. The goal is to cover enough to give the reader a high level understanding. Once they have a basic understanding they can research more if they desire.
Can you tell me some of the "exotic details where defaults would be sane enough"? I can amend the guide.
Are you saying a public key can be used to decrypt data it encrypted? Or are you saying a public key could also be used to decrypt data that the private key encrypted?
You mention "server room". This guide is intended for a person running a simple server in their home. Hopefully SAs securing a large scale environment are not using information from GitHub. :/
I made some other updates to the guides that I hope address your other concerns?
Regarding your distribution agnostic comment, I do not see value in distribution specific guides on hardening. Sans a few edge distributions, most distributions are similar enough that the hardening steps are the same. It is okay to look for distribution specific documentation on how to install the distribution but it hurts the cause having distribution specific hardening guides.
Also, I want more folks to use Linux. Most distributions are so similar there is no value in having so many distribution specific guides -- all it does is create unnecessary confusion and steer potential prospective users away from Linux.
I think for home use, ufw is probably good enough. I've been using it for 3+ years and it's worked out okay for me okay.
I have not heard of ferm but I will check it out. Thanks!
If you're using public/private keys you can use the "from" option for the keys. But it's not fool proof.
Can you recommend any good network scanning tools? I've been on the hunt for a good one.
https://github.com/imthenachoman/How-To-Secure-A-Linux-Serve...
Although I wonder if its necessary if you use an app password. What is the worst a bad-actor can do with the app password?
This is my first time putting a guide like this together. I see a lot of really great feedback and I will be incorporating them into future updates.
I don't have time today but I will reply individually to all the comments that I can.
I appreciate any/all feedback/advice. If possible, could future issues be submitted to GitHub because it is easier for me to manage if everything is in one place. https://github.com/imthenachoman/How-To-Secure-A-Linux-Serve...
But right now I need to find all the other places this guide is linked to with comments so I can address them too. :)