Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #268605
| From | Michael Kjörling <2695bd53d63c@ewoof.net> |
|---|---|
| Newsgroups | linux.debian.user |
| Subject | Re: making Debian secure by default |
| Date | 2024-03-28 21:50 +0100 |
| Message-ID | <In4Rb-2mKH-1@gated-at.bofh.it> (permalink) |
| References | (1 earlier) <ImQlb-2bMw-3@gated-at.bofh.it> <In0Nz-2juy-3@gated-at.bofh.it> <In1JD-2kky-5@gated-at.bofh.it> <In3BL-2lQK-3@gated-at.bofh.it> <In3BL-2lQK-13@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On 28 Mar 2024 15:28 -0400, from greg@wooledge.org (Greg Wooledge): >> so apparently somebody else has done a threat analysis and decided >> apparmor is the appropriate mitigation strategy? > > *An* appropriate mitigation strategy. Not "the". > > There are many, many layers. Right. We've got everything from address space layout randomization (ASLR), firewalling, full-disk encryption (for example with LUKS) and automatic system updates all the way to password policies, file/directory access permissions and system call masking. There is the concept of data backups, storage-level redundancy, SMART monitoring and system log analysis. It's possible to choose between encrypted SSH and plain-text telnet or rsh for remote shell access (and these days, no one should suggest the latter, but I digress). Each of which can help mitigate _some_ threats and is utterly useless against others. Even within each of those there are differences. For example, a _lot_ of people and guides say, essentially unconditionally, "Thou Shall Disable SSH Password Authentication". That's good advice in some situations and _horrible_ advice in other situations. It's not particularly meaningful to make a threat assessment for "Debian". (It might very well be meaningful to make a threat assessment for _the Debian project_, but that's something very different.) What certainly _is_ meaningful is to make a threat assessment for your computer, your data, your network and your usage. Which will almost certainly be very different from mine, or Alice's, or Bob's; never mind between my desktop system, Carol's server and Mallory's laptop; and therefore will require a different implementation. -- Michael Kjörling 🔗 https://michael.kjorling.se “Remember when, on the Internet, nobody cared that you were a dog?”
Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
making Debian secure by default Lee <ler762@gmail.com> - 2024-03-27 22:40 +0100
Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-03-28 00:10 +0100
Re: making Debian secure by default Lee <ler762@gmail.com> - 2024-03-28 05:30 +0100
Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-03-28 14:40 +0100
Re: making Debian secure by default Greg Wooledge <greg@wooledge.org> - 2024-03-28 16:30 +0100
Re: making Debian secure by default Hans <hans.ullrich@loop.de> - 2024-03-28 16:50 +0100
Re: making Debian secure by default Lee <ler762@gmail.com> - 2024-03-28 19:20 +0100
Re: making Debian secure by default Ralph Aichinger <ra@h5.or.at> - 2024-03-29 08:50 +0100
Re: making Debian secure by default Stefan Monnier <monnier@iro.umontreal.ca> - 2024-03-29 20:10 +0100
Re: making Debian secure by default Jeffrey Walton <noloader@gmail.com> - 2024-03-29 20:40 +0100
Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-03-28 17:00 +0100
Re: making Debian secure by default Lee <ler762@gmail.com> - 2024-03-28 21:20 +0100
Re: making Debian secure by default Curt <curty@free.fr> - 2024-03-28 18:50 +0100
Re: making Debian secure by default Lee <ler762@gmail.com> - 2024-03-28 20:40 +0100
Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-03-29 18:00 +0100
Re: making Debian secure by default Joe <joe@jretrading.com> - 2024-03-29 18:30 +0100
Re: making Debian secure by default Curt <curty@free.fr> - 2024-03-29 18:50 +0100
Re: making Debian secure by default Nicholas Geovanis <nickgeovanis@gmail.com> - 2024-04-01 02:30 +0200
Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-04-01 03:50 +0200
Re: making Debian secure by default Roberto C. Sánchez <roberto@debian.org> - 2024-04-01 05:00 +0200
Re: making Debian secure by default Nate Bargmann <n0nb@n0nb.us> - 2024-04-01 10:40 +0200
Re: making Debian secure by default <tomas@tuxteam.de> - 2024-04-06 09:50 +0200
Re: making Debian secure by default Nate Bargmann <n0nb@n0nb.us> - 2024-04-06 09:50 +0200
Re: making Debian secure by default <tomas@tuxteam.de> - 2024-04-06 09:51 +0200
Re: making Debian secure by default <tomas@tuxteam.de> - 2024-04-06 09:50 +0200
Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-04-06 09:50 +0200
Re: making Debian secure by default Nate Bargmann <n0nb@n0nb.us> - 2024-04-06 09:51 +0200
Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-04-06 09:51 +0200
Re: making Debian secure by default Jeffrey Walton <noloader@gmail.com> - 2024-04-06 09:51 +0200
Re: making Debian secure by default Nate Bargmann <n0nb@n0nb.us> - 2024-04-06 09:52 +0200
Re: making Debian secure by default Charles Curley <charlescurley@charlescurley.com> - 2024-04-06 09:52 +0200
Re: making Debian secure by default Jeffrey Walton <noloader@gmail.com> - 2024-04-06 09:51 +0200
Re: making Debian secure by default John Hasler <john@sugarbit.com> - 2024-04-06 09:51 +0200
Re: making Debian secure by default Joe <joe@jretrading.com> - 2024-04-06 09:52 +0200
Re: making Debian secure by default John Hasler <john@sugarbit.com> - 2024-04-06 09:52 +0200
Re: making Debian secure by default Joe <joe@jretrading.com> - 2024-04-06 09:52 +0200
Re: making Debian secure by default Curt <curty@free.fr> - 2024-03-29 18:50 +0100
Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-03-29 21:00 +0100
Re: making Debian secure by default Curt <curty@free.fr> - 2024-03-30 17:10 +0100
Re: making Debian secure by default Lee <ler762@gmail.com> - 2024-03-28 19:10 +0100
Re: making Debian secure by default Jeffrey Walton <noloader@gmail.com> - 2024-03-28 23:20 +0100
Re: making Debian secure by default Florent Rougon <f.rougon@free.fr> - 2024-03-28 17:30 +0100
Re: making Debian secure by default Florent Rougon <f.rougon@free.fr> - 2024-03-28 18:10 +0100
Re: making Debian secure by default Greg Wooledge <greg@wooledge.org> - 2024-03-28 18:10 +0100
Re: making Debian secure by default Florent Rougon <f.rougon@free.fr> - 2024-03-28 18:10 +0100
Re: making Debian secure by default jeremy ardley <jeremy.ardley@gmail.com> - 2024-03-28 00:40 +0100
Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-03-28 00:50 +0100
Re: making Debian secure by default Lee <ler762@gmail.com> - 2024-03-28 05:50 +0100
Re: making Debian secure by default <tomas@tuxteam.de> - 2024-03-28 06:20 +0100
Re: making Debian secure by default Emanuel Berg <incal@dataswamp.org> - 2024-03-28 06:30 +0100
Re: making Debian secure by default <tomas@tuxteam.de> - 2024-03-28 08:20 +0100
Re: making Debian secure by default Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-28 12:20 +0100
Re: making Debian secure by default Emanuel Berg <incal@dataswamp.org> - 2024-03-28 12:40 +0100
Re: making Debian secure by default David Wright <deblis@lionunicorn.co.uk> - 2024-03-28 21:40 +0100
Re: making Debian secure by default Emanuel Berg <incal@dataswamp.org> - 2024-03-29 10:40 +0100
Re: making Debian secure by default David Wright <deblis@lionunicorn.co.uk> - 2024-03-30 04:00 +0100
Re: making Debian secure by default Curt <curty@free.fr> - 2024-03-28 15:50 +0100
Re: making Debian secure by default Lee <ler762@gmail.com> - 2024-03-28 17:30 +0100
Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-03-28 18:10 +0100
Re: making Debian secure by default Lee <ler762@gmail.com> - 2024-03-28 21:50 +0100
Re: making Debian secure by default tomas@tuxteam.de - 2024-03-28 18:30 +0100
Re: making Debian secure by default Lee <ler762@gmail.com> - 2024-03-28 20:30 +0100
Re: making Debian secure by default Greg Wooledge <greg@wooledge.org> - 2024-03-28 20:30 +0100
Re: making Debian secure by default Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-28 21:50 +0100
Re: making Debian secure by default tomas@tuxteam.de - 2024-03-28 21:20 +0100
Re: making Debian secure by default Curt <curty@free.fr> - 2024-03-29 17:10 +0100
Re: making Debian secure by default debian-user@howorth.org.uk - 2024-03-29 21:50 +0100
Re: making Debian secure by default debian-user@howorth.org.uk - 2024-03-28 22:50 +0100
Re: making Debian secure by default Marc SCHAEFER <schaefer@alphanet.ch> - 2024-03-28 12:10 +0100
Re: making Debian secure by default Franco Martelli <martellif67@gmail.com> - 2024-03-28 17:30 +0100
Re: making Debian secure by default Michel Verdier <mv524@free.fr> - 2024-03-28 17:30 +0100
Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-03-28 17:40 +0100
Re: making Debian secure by default Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-28 21:50 +0100
Re: making Debian secure by default Richmond <dnomhcir@gmx.com> - 2024-03-28 21:50 +0100
Re: making Debian secure by default Jeffrey Walton <noloader@gmail.com> - 2024-03-29 16:40 +0100
Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-03-31 21:10 +0200
Re: making Debian secure by default Roberto C. Sánchez <roberto@debian.org> - 2024-03-31 21:30 +0200
Re: making Debian secure by default gene heskett <gheskett@shentel.net> - 2024-03-31 22:30 +0200
Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-03-31 23:20 +0200
Re: making Debian secure by default gene heskett <gheskett@shentel.net> - 2024-04-01 01:00 +0200
csiph-web