Charlie Li on 29 Aug 2018 11:48:18 -0700
|
[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]
Re: [PLUG] Linux tip: Log IP addresses, not hostnames, for use by fail2ban...
|
- From: Charlie Li <ml+PLUG@vishwin.info>
- To: plug@lists.phillylinux.org
- Subject: Re: [PLUG] Linux tip: Log IP addresses, not hostnames, for use by fail2ban...
- Date: Wed, 29 Aug 2018 14:47:50 -0400
- Autocrypt: addr=ml+PLUG@vishwin.info; prefer-encrypt=mutual; keydata= xsFNBFt7iHUBEADCorTixbMGuHd9WYSKCELlv/TFcRtvpHUw/n9LtXzKixUUwl7iuMFMYTz3 QXePX0Twq4jCQYySfcxWbPkLsSYlPOkaGQ+XytfmIHoqG5ba4i1fp+F41is0oCtLt1+oL84j NKUd13em/JWd+PJeQbSTVnHbT2yaAi7vqWw5WKVaMExjfPGU5TArV46wSRU6Zuy1ZX66q0q5 dPzeBdeKYWJE8aGtyi3pYUpKUOX4gxiNetf6leDFZ4OsexWaRdU0n8fId5d1qwjAE3lOwV5z 0Ilt8t4iXtX3JL3DAQyLZIeXHIg9O3rrpPMXQWSp2/5g39PohNk7farbhcpIKxuDN+L5N6U9 OxNHBSCv9FGDO4R/mw3YwJCovDzsF7RSyXQDIY36yjdh2uTLZ0uD5Ci/DPmJUySFLRvpqWnQ M7V5cYhdqDfcElGpRbi8JZQVYRJjvI5Jj0byG98KeaD0YFxKqmmm+Oh+xWXE7xt/DsBoZeZJ BFP84LvFbwQqprvI+sg+1z2+JIgNbYwl8VaYzfyGnqTEXTOsQYEKTdKA9MODSAsN31MlQICe CIHZV+OwOqH1KQ/mZp59AnpXAmj4T94bnahE9yJtVW/qglX/nTeFNUdu5MyEgkeB0x7mx+t0 3hE20yp/NbyvG1T/o53NHwHiURC/8Fxd1NWPZ6n4X8npQn6iyQARAQABzSFDaGFybGllIExp IDx2aXNod2luQHZpc2h3aW4uaW5mbz7CwZEEEwEIADsCGyMFCwkIBwIGFQoJCAsCBBYCAwEC HgECF4AWIQT/f8Kqvlr7jU9sRv6OcHje8gOrbAUCW3uI+wIZAQAKCRCOcHje8gOrbNX8EACT HGo3AsShFj+AaUgD9V6wTMaR2w7ubIqbkn2ZqZZ1xWj3gM6VYRKHflj9LiYqFRO4wBteAq30 Snz6F93IG+u5B1uwlC58HDwCQaROaU5cHQ8UvGPSEv0XXCcYTaC3d5NMoIh/LdutVZz56LTx hWs5NHUCaG6FfGV9QplECRteQr2rMxHZxZ3ppSY9oev/wY3U3VRUGnhM2ZwGrpmjksC1HTBH Fw2XbYdVNCOYjQrTIulaYb3y0ssgsOhvSk9bPHSTsWSCQGJk0uFNXTvIq68GhkhOwAet6//w R2y1whg47r554pBManttODaQnmWmIWBM0bZMJrlNT8T/oXlG9nA0jrjA8LvTThrCAvMSMB0F 2FhStd/I2/Fs7T6Uk1BUpgCvFiDtE8Jt1W2yq2GLtPysGrJXyDaat8IuVUthnNVhoyZb9tZu sI/FFhfh9MkPmZDwCoTUJN2yU8QhxS1iJXfMZ1f06r1TYY9rwb8E/WCBJFbMzJs3VLj/TnHL N09J2zNZgTs7gewLn/2lEV1kOL/FxIDgN7ailcf3kcNdVUxr/pLbx3NZcDkXniPO0dzQpuRw q841wBT3uqdPFJwIl4pf1EYhLj89r2vOGnM2RChl1/t+wSqHhBji3R3uylzE0qbr8O/cgx/5 wlvZJiUhyu0hJ/JoJkF8WEFkesJrTZORGc7BTQRbe4h1ARAA12Xtgcbwk7IdsRi/7sTFKs73 qoFFq+DUWwMbSuIOaWw5J9nZ+ovr9gkXlax+xf335hJ0iItB8LhA7D9wD4wjrmmBjhwK7jYv tghb8BH6MHWEWD5D9xt47CO4o8Vi1m/F4OlKxoDqIhH6n63gNeSNaXzqDpZoUsL62KX+sKKU Udj/X/oz3XwXWCb/rEIgAMMW7QFcuQBJzkHgu69oUSIki4j1mhAMiBbGexfS1dcTfpLAr9eu jDNHOw5r7aI4cA8q7us8YfDLby87hPlSrtTKcxkbawrdFNs6KNrEvggkXhYxGqm4Z0FInixa avloimBf1q7kvVM0AAgsmkdeeS/6Tzbn71WBuEW0VgEcSSBS1dv7DfgmeQeiSmv0Dvx2lZv5 P6M4Q/plSAz7hVXL6EIKltwJUjY8Re7zDbPf7jJlbEgWbLxRhlGh5MwrNXbMt6KygDRcDyOP njxg0+ICXbQyPKiq7jZY2/Q/x8P08xNx8sUKPY+XE6G5QVohQfe3LT9s15KM+1Ur4v3Hhbft HtTW1iT60HkyU9qRCJJC11OgH7wrfiucG3/eQKgBgvsfKDD36rJmsQpkO0/kkp6R+CzLby3X PrrFYJTCr08e5QWKKPdyNvAhuyQj27Lb7EhNxe3hmpV+llx0aaN9t1M+QZ88famMOgIlp7Nh 1uFr/c5WGZUAEQEAAcLBdgQYAQgAIBYhBP9/wqq+WvuNT2xG/o5weN7yA6tsBQJbe4h1AhsM AAoJEI5weN7yA6tsTGcP/2rBIvgeKismZQQn7kJOHwgmqXg/N5ArwPH3eCJmzmNZWUIlOZyl A2KtYhkzZ5G3rsL/BMmMuYRUbPJJUukaJSqFep1E6AWYPC8Seakhu1ZbK8ayBI4KZmP+3PQY S0tKyMlxX+Qt9+S/tcQqS31mMgmcVhVhKi8MrWjY+g7pF+LkBYccHuNiGNIcm8mMPHTIKU72 ARiG3DtHrRg4sf5wqgOi72277jBHdDBGw0Y7rCvMsaGm3G4GsMwj4e47H6PAFOWK7O69muvL o50oMN2rkPi+9AKPi8WcrinstleEGyEIyguRagDQjZP5gX9Xk5vkS6+xMgKt7+k7+D3jWKlW R6G9U0CyKmVJoeNqwHUdLoFD3lywjwT9vo+cqb4gQKnZsA1ss/WOvEp4EaNSR7JHFOY5X8AN QgiPxLhrbI7FPGXKw3Y7nCpcIlzFph6UL9jhNRwvoQ3GfZ0sF0JgpASdrS4N3Fmnt9L6lc3q rIrxDPpDjYwcDEUBl0sp/prjh3gdC3qs9xZ0RNWWdUqcmvRv2SDkrVDw3iQ9WhMZWuQYBmGa MViypa6WrjjlVTjqZftZyqytnHwuo1PA/qLcF/vUUn0QHFPIDx8/yTSqiw/xTwPuOFxznHjJ VbxEEG0H5rmreh1Z0WeMwsSbjC3EEf+ZI39QpFwVIG8pDwXFOClfhjFz
- Dkim-signature: v=1; a=rsa-sha256; c=relaxed; d=vishwin.info; h=subject :to:references:from:message-id:date:mime-version:in-reply-to :content-type; s=fuccboi12; bh=GYAuBaO1PKCWZm8HKbvZJqPfu/+xL+IO7 tkXKQL52X0=; b=ZVf9DEzjIuOFLYHIrtKHiJic8IwrvAm3gPYBRKw1GMLuZBY/c D8GaWXco7nqKMZXsxpsnHP2hDD6prjl9h7M8+7jREAymaW4KGSJMDYXDyw5Yh8mZ OOUFgdTGD7i0ItjDolZDXaZfoH6SWhdZCpQ3cspU6KUY0dz266hhLTzD0xiECvl2 cWpEklM3JmK4i+vX+UG88qrer5CghEbOo6prJKdEvVMQOuEnyeVqxO24JFSjDM4b AtA/9Sw614siqjBOMFyo2f9618K1JU0H6he7IYke9t3LPNAQBr55IxX3CzZZ6OnS jaLXmmvp5lM9B25xBkuLoUMjXbIzXbF6HKvsg==
- Openpgp: preference=signencrypt
- Organization: PLUG mailing list
- Reply-to: Philadelphia Linux User's Group Discussion List <plug@lists.phillylinux.org>
- Sender: "plug" <plug-bounces@lists.phillylinux.org>
- User-agent: Mozilla/5.0 (X11; FreeBSD amd64; rv:60.0) Gecko/20100101 Thunderbird/60.0
On 29/08/2018 14:03, Rich Kulawiec wrote:
> On Wed, Aug 29, 2018 at 08:24:12AM -0400, Rich Freeman wrote:
>> The problem is that the outcome of not allowing it is bad for the internet.
>
> Allowing it is worse. MUCH worse.
>
>> If we're giving up on securing things at the protocol level and
>> allowing any host to connect to any other host, what is the whole
>> point of doing this Internet thing anyway, other than VPNs being
>> cheaper than dedicated lines?
>
> Those days went away a couple of decades ago, thanks to a combination of
> incompetence, negligence, bad actors, and their enablers. Since security
> is asymmetric, you can either spend continuously-increasing amounts
> of money and effort attempting to defend your operation from people
> who have *already put proof on the table* that they're your enemy...
> or you can solve your problem in a much more permanent way by removing
> them from your view of the Internet. And while a security breach of
> your operation is obviously bad for you, it's also bad for all of us,
> since compromise of your operation will (variously) expose our data, or
> provide attackers with another platform from which to attack us, or worse.
>
I'll add: a guy from New Jersey who, among other things in past lives,
worked at the NSA and built up their internet arsenal, then went and
built Estonia's property ownership blockchain (way before blockchain
became a buzzword), put the internet this way:
"The internet is the most dangerous thing we use on a daily basis."
> As I said before, I don't like this. But it's reality. Don't blame me:
> I worked for a very long time to stop this from happening (and I wasn't
> alone in that) but it didn't work out. Too many people explicitly
> or implicitly supported the incompetent, the negligent, the bad actors,
> and their enablers, thus making them finanically successful...and
> ensuring that they would keep doing exactly what they were doing.
> Now we're faced with the consequences of that.
>
In a recent (as in earlier this month) talk this guy gave that George
and myself had the *privilege* of absorbing, he states that this pattern
of poor, incompetent operations stands to show that what the public (get
made to) think are vulnerabilities, are actually business models!
--
Charlie "café bum" Li
(This email address is for mailing list use only; replace local-part
with vishwin for off-list communication)
Attachment:
signature.asc
Description: OpenPGP digital signature
___________________________________________________________________________
Philadelphia Linux Users Group -- http://www.phillylinux.org
Announcements - http://lists.phillylinux.org/mailman/listinfo/plug-announce
General Discussion -- http://lists.phillylinux.org/mailman/listinfo/plug
- References:
- Re: [PLUG] Linux tip: Log IP addresses, not hostnames, for use by fail2ban...
- From: Rich Kulawiec <rsk@gsp.org>
- Re: [PLUG] Linux tip: Log IP addresses, not hostnames, for use by fail2ban...
- From: Fred Stluka <fred@bristle.com>
- Re: [PLUG] Linux tip: Log IP addresses, not hostnames, for use by fail2ban...
- From: Rich Kulawiec <rsk@gsp.org>
- Re: [PLUG] Linux tip: Log IP addresses, not hostnames, for use by fail2ban...
- From: Fred Stluka <fred@bristle.com>
- Re: [PLUG] Linux tip: Log IP addresses, not hostnames, for use by fail2ban...
- From: Rich Kulawiec <rsk@gsp.org>
- Re: [PLUG] Linux tip: Log IP addresses, not hostnames, for use by fail2ban...
- From: "Keith C. Perry" <kperry@daotechnologies.com>
- Re: [PLUG] Linux tip: Log IP addresses, not hostnames, for use by fail2ban...
- From: Ronald Guilmet <ronpguilmet@gmail.com>
- Re: [PLUG] Linux tip: Log IP addresses, not hostnames, for use by fail2ban...
- From: Rich Freeman <r-plug@thefreemanclan.net>
- Re: [PLUG] Linux tip: Log IP addresses, not hostnames, for use by fail2ban...
- From: Rich Kulawiec <rsk@gsp.org>
- Re: [PLUG] Linux tip: Log IP addresses, not hostnames, for use by fail2ban...
- From: Rich Freeman <r-plug@thefreemanclan.net>
- Re: [PLUG] Linux tip: Log IP addresses, not hostnames, for use by fail2ban...
- From: Rich Kulawiec <rsk@gsp.org>