6 ms·
Thank you. The whole read indeed feels like not understanding IPv6. Just like people advertising not broadcasting SSID, or changing the SSH port, this is just
by scarfaceneo 2y ago
Thank you. The whole read indeed feels like not understanding IPv6.
Just like people advertising not broadcasting SSID, or changing the SSH port, this is just a false sense of security.
- wolrah 2y agoTo be fair, changing the SSH port does MASSIVELY cut down on the amount of log spam from low-effort scans. Obscurity isn't security, but hiding still makes you harder to find. In other words the lock is just as good or bad as it always was but a lot less people are going to jiggle the handle. Changing default service ports is a good thing and is one of the reasons everyone should be in favor of software supporting SRV/SVCB records so services can be hosted on arbitrary ports while still being accessible with a plain DNS name everyone's used to using. That shouldn't be lumped in with pure idiocy like disabling SSID broadcast or believing that IPv6 inherently exposes your network to the world. Ironically disabling SSID beaconing on wireless APs actually results in clients configured to use those networks broadcasting looking for them wherever they go, for those who want to hide a network it's the literal opposite of their desired result.
- sfink 2y agoYeah, I changed my SSH port for the same reason. I don't feel any more secure as a result, but now I can just watch the raw logs to see the incoming probes. They trickle in slowly, rather than being a constant flood, so I can watch the raw log for other purposes without it being inundated with noise that I have to filter out in order to be able to pay attention to anything else. That, and the logs use less space on disk.
- k_roy 2y agoI don’t agree. Because the minute you change the port, you just become of more interest. As you said, only the low effort bots scan the standard ports. But venture anywhere off the beaten path, and a place like shodan is the most benevolent of those kind of places, and it still takes about an hour for your IP and newly opened SSH port to be indexed.
- Dylan16807 2y agoMore interest to who? This comes across like you're telling a spooky story at a campfire. Being 2% more interesting than the average server is not going to get you hacked by some elite crew.
- k_roy 2y agoYou want to talk about spooky campfire stories? Let’s have another OpenSSL/ssl zero day. The point is it takes a script kiddy about 5 minutes to scan the whole 4 billion IPs for your port 22 server. It takes about 90 seconds for the fact that you opened up a random high numbered port that is an SSH service to show up on the list of people that are probably exponentially more intelligent than the normal script kiddy scanning the internet This does not make you more or less likely to be hacked just for having SSH open. But hey,go go gadget whatever.
- Dylan16807 2y ago> This does not make you more or less likely to be hacked just for having SSH open. A) The comment you responded to didn't claim you're less likely to be hacked, they said it cuts down on log spam. B) When you talked about just becoming of more interest to non-benevolent places, was that not a suggestion you're more likely to be hacked? Then I think you phrased that pretty badly.
- k_roy 2y ago> “ More interest to who?” And > elite hacking crew It was your comment. Not to mention the blog post to which I originally responded to said “ you might not want to put your servers on low numbered IPs “ Step 1, know the difference between UDP and TCP and even a few of the implications Yep. Party on
- Dylan16807 2y agoI did say those words. And I said them after the comment I'm asking about. They are irrelevant to my question, because I'm asking what the comment I originally replied to meant. You said "the minute you change the port, you just become of more interest" and then talked about places that are less "benevolent" than shodan. Is being of "more interest" to less "benevolent" places supposed to imply an increased risk of being hacked, or not?
- throw0101c 2y ago> Thank you. The whole read indeed feels like not understanding IPv6. He's posting his learning and realizations as he goes. He often has posts of style "I thought X, but then I noticed certain things (in the logs), and after more digging it's actually Y." Or "Last time I checked things were A, but at some point things changed and now they're B, and going into the release notes it appears to be about at about C."
- Tractor8626 2y agoAnyone who ever had public facing ssh - knows that changing SSH port massively increases security. Now your logs will show only deliberate attacks on you, not the mass probing spam.