Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I highly doubt that these recommendations are intended for administering developer's workstations.

Also, a number of the recommendations you are railing against here are prefaced with "if possible" and "unless needed". For example, advice is provided on how to configure OpenSSH if it is deemed necessary to be run: "If the system needs to act as an SSH server, then certain changes should be made to the OpenSSH daemon configuration file"

The point of guides like this is to lock down everything that isn't necessary. As a part of this, it helps to question what services and actions each of your machines really needs. It's not unthinkable that some Linux servers deployed in a network do not need OpenSSH server running.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: