1 |
On Sun, 11 Dec 2011 16:53:02 +0200 |
2 |
Alex Efros <powerman@××××××××.name> wrote: |
3 |
|
4 |
> Hi! |
5 |
> |
6 |
> On Sun, Dec 11, 2011 at 02:25:19PM +0000, Sven Vermeulen wrote: |
7 |
> > > 1) How can |
8 |
> > > 4.2.4.1. Root Logon Through SSH Is Not Allowed |
9 |
> > > increase security, if we're already using |
10 |
> > > 4.2.4.2. Public Key Authentication Only |
11 |
> > > Disabling root may have sense with password auth, but with |
12 |
> > > keys it is just useless inconvenience. |
13 |
> > |
14 |
> > I read somewhere that security is about making things more |
15 |
> > inconvenient for malicious people than for authorized ones. |
16 |
> > |
17 |
> > For me, immediately logging in as root is not done. I want to limit |
18 |
> > root access through the regular accounts on the system (with |
19 |
> > su(do)). I never had the need to log on as root immediately myself. |
20 |
> |
21 |
> Understood. But I still don't see how this can increase security. |
22 |
> |
23 |
> > hardening measures, glsa-check, cvechecker and the like to mitigate |
24 |
> > risks of |
25 |
> |
26 |
> Been there, done that, it doesn't work: in average, after 1-1.5 years |
27 |
> of security-only updates we end with next one security update which |
28 |
> depends on few other packages which in turn pull in 80% of other |
29 |
> @world updates. So we've to emerge world anyway every ~1.5 years, but |
30 |
> such delayed updates wasn't tested by anyone and usually gives a lot |
31 |
> of troubles resulting in server offline for several days. Daily world |
32 |
> updates are much ease to manage, even with needs to check these |
33 |
> updates on test servers first, before updating production servers. |
34 |
> (And daily updates usually easy to rollback and debug in case of |
35 |
> unexpected troubles.) Because of this I don't think Gentoo is capable |
36 |
> to act as LTS-release with security-only updates like some other |
37 |
> distributives. |
38 |
> |
39 |
|
40 |
Well, you don't wait years, just months between updates. I have |
41 |
glsa-check running daily on my systems and update when it tells me to. |
42 |
On top of that I update at least monthly, usually weekly (though I |
43 |
could probably go every six months and be fine). |
44 |
|
45 |
-- |
46 |
Matthew Thode (prometheanfire) |