Tools like fail2ban and sshguard do not add any security. They just reduce log noise, at the expense of having to parse log files with all the security problems it entails.

Follow

@juliank
They are nice thing to have but I think everyone should go through their sshd_config files for understanding of what can be done to increase security

@nikolal I don't think they're a nice thing to have. Rate limiting in the firewall has the same effect, without opening up an entirely new attack vector.

Sign in to participate in the conversation
Mastodon 🔐 privacytools.io

Fast, secure and up-to-date instance. PrivacyTools provides knowledge and tools to protect your privacy against global mass surveillance.

Website: privacytools.io
Matrix Chat: chat.privacytools.io
Support us on OpenCollective, many contributions are tax deductible!