Re: "Debian as My home firewall/router" on the debian-user mailing list
Arnt Karlsen <[email protected]>
| Newsgroups | gmane.comp.security.ipcop.user |
|---|---|
| Organization | ..ing.Arnt.Karlsen |
| Message-ID | <[email protected]> |
On Sun, 28 Feb 2016 13:14:30 -0700, Matt wrote in message <CAAiWk=U85OPZC88ucNOZqpAYS0YFGgcbdKSJyyy7q_QMCsmmrA-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>: > I usually explain it to people like this: > > With any security device / product, there is a trade off between > usability and security. IE: The most secure devices are often also > the most difficult to use / present the most hurdles. > > So, one has to ask - what's the risk? What is your acceptable level > of risk? What do you stand to lose? > > When you think about your house - you lock your doors, right? And > probably your windows, and keep the garage shut, etc. Now, will that > keep out someone who is intent on breaking into your house out? No, > of course not. So, for some folks, having doors and windows that lock > isn't acceptable enough for their security, so they purchase an alarm > system, maybe get a dog, or buy a gun. But still, will this stop > someone who is _really_ intent on getting into your house? Still, > no. So to take it to the next level, you move 200 miles from anyone, > you put 20' concrete walls around your house, hire armed guards, and > insist on DOD level background checks before anyone can enter your > home. Now - THAT is a pain in the @$$ but also affords you > considerably less risk than simply locking the door and closing the > garage. > > Similarly, with firewalls, most people change the default password on > their wifi, lock down unused ports on their firewall, and keep > anti-virus up to date, etc. For those that want a little extra - > they use something like IPcop / pfsense / or SOHO routers (think > Sonicwall, EdgeRouter Lite, etc.) But for those who just HAVE to have > the 20' walls, they roll their own highly customized solution or > spend several hundreds of thousands of dollars (if not more) on > purpose built commercial hardware solutions (think Palo Alto, Cisco, > Juniper, etc.) ..and none of these run systemd? ;o) ..if you trust systemd, there's Debian Jessie, Red Hat etc, even http://www.linuxfromscratch.org/lfs/view/7.5-systemd/ and http://www.linuxfromscratch.org/lfs/view/systemd/ if you trust systemd people using the merits of banana republic politics rather than technological merit to push systemd onto Debian, Ubuntu etc distros. ..similarly, if you trust North Korea's Red Flag Linux, designed to protect the North Korean regime by tagging and tracking and reporting to regime servers any and all files on any USB etc device stuck into your etc Red Flag Linux box, and to not drop child porn or terror plans into your "Linux" box, then you can probably run North Korea's Red Flag Linux on your box. Etc. ..afaict, both systemd and North Korea's Red Flag Linux are capable of fetching core parts of their binaries off servers online, leaving you without any real way of tracking down new variants of old classics like http://c2.com/cgi/wiki?TheKenThompsonHack because they disappear as you yank the cord. ..at least systemd knows the difference between real and virtual machines and North Korea's Red Flag Linux knows the difference between North Korea's "internet" and anything else I've heard people try it in. ..if http://distrowatch.com/table.php?distribution=ipcop and http://www.linuxfromscratch.org/lfs/view/7.5/ can be trusted, ipcop and LFS is or can still be built with old fashion debug-able and human-readable sysv-init scripts, rather that systemd's Red Flag style binaries. ..beware that ipcop and LFS' udev comes from systemd's udev repository, so you want devuan.org's vdev or eudev or some other safe udev replacement, devuan is not ready for production, we need help and this is where I'd be eminently pleased to learn systemd is really, really, really run by people like Ed Snowdon, Glenn Greenwald, Manning, Assange, Wikileaks, PJ, Groklaw.net and Bernie... :o| > So - back to the question, what do you have to protect? and What is > your acceptable level of risk? > > For me and my lowly home network, IPcop is sufficient. For most of my > customers, IPcop is sufficient. But is it sufficient for fortune 500 > companies? Not even close. And those in between? Well, that's up for > debate. :-) > > My $0.02 > > Matt -- ..med vennlig hilsen = with Kind Regards from Arnt Karlsen ...with a number of polar bear hunters in his ancestry... Scenarios always come in sets of three: best case, worst case, and just in case. ------------------------------------------------------------------------------ Site24x7 APM Insight: Get Deep Visibility into Application Performance APM + Mobile APM + RUM: Monitor 3 App instances at just $35/Month Monitor end-to-end web transactions and take corrective actions now Troubleshoot faster and improve end-user experience. Signup Now! http://pubads.g.doubleclick.net/gampad/clk?id=272487151&iu=/4140 _______________________________________________ IPCop-user mailing list [email protected] Manage your subscription or unsubscribe https://lists.sourceforge.net/lists/listinfo/ipcop-user