Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: secure installation

From: alex black <enigma(at)turingstudio.com>
Date: Mon Aug 20 2007 - 13:47:17 EDT


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

> thus defeat the purpose). A default firewall simply can't work,
> even if we
> had some way to implement it perfectly for all packages (without
> breaking
> any, which we undoubtedly would).

It all depends on context - I agree that a default firewall for "debian" is stupid, but if you look at the way an OpenBSD box looks when the default install is done, that is my ideal. I happen to prefer the way thing generally are done in debian, but on the initial install, OpenBSD whips any other OS I've seen. It has pf on by default and only allows SSH connections. Ideal.

Would that be a good idea for a workstation? No - nightmare. Is it a good idea for a server? Yes absolutely. Servers, unless they are packaged appliance distros or subdistros, should always have the bare minimum of services and allow SSH only by default.

$.000002

_a

  • -- alex black, founder the turing studio, inc.

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.3 (Darwin)

iD8DBQFGydOsAHZuLuydb2YRAuAsAJ4gdXkilHb7NNUBnC5uKpYoG6VIJACdFZTK Azi/tVYEPnuIAwLX/atPaE8=
=DJ5Y
-----END PGP SIGNATURE-----

-- 
To UNSUBSCRIBE, email to debian-security-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Received on Mon Aug 20 13:50:56 2007
Do you need help?X

This archive was generated by hypermail 2.1.8 : Sun Oct 07 2007 - 07:52:51 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library