Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I appreciate the effort but this advice is not especially good.

For example fail2ban is fine but it's almost always better to just use ssh key pairs.

His firewall configuration doesn't do anything basically, just gives access to the network services that are already running, and logging firewall errors is only good if they are actionable (they rarely are) otherwise they are just filling up disk space.

The sysctl entries, I haven't checked one by one by the look like the defaults in a modern distro.



Both are used, and password logins are disabled. As I linked to in the article, those sysctl tweaks are recommended by the NSA handbook.


You are right, keys are used in the OP, not sure then why you'd use fail2ban for ssh but OK.

Regarding the sysctl entries, I reviewed them down to execshield (after that there are tweaking entries) in a Amazon EC2 vanilla Ubuntu distro and all the entries are the same except log_martian (debatable, again, are you going to look at the logs, if then what are you going to do with them) and accept_redirects. Execshield is a RedHat thing, it's not used in Ubuntu.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: