• 3 Posts
  • 1.23K Comments
Joined 1 year ago
cake
Cake day: September 21st, 2024

help-circle







  • GreenKnight23@lemmy.worldtomemes@lemmy.worldLiving language
    link
    fedilink
    arrow-up
    5
    arrow-down
    5
    ·
    edit-2
    2 days ago

    that’s retarded.

    edit: if you upvote you agree the term “retarded” has changed meaning to not target the mentally deficient.

    if you downvote you agree that the meaning of words cannot change, and thus agree that the term “retarded” means to “make slow or slower; keep back, hinder, delay” according to 14th century Latin. making your reason to downvote in the first place moot.





  • I wouldn’t go onto a teen community and spout off how to make explosives even though they’re relatively safe to a trained individual.

    same reason behind not allowing a hobbyist and amateur community to think that iptables and firewalld is the best/only solution.

    it’s dangerous and someone will get hurt eventually.








  • GreenKnight23@lemmy.worldtoSelfhosted@lemmy.worldDocker security
    link
    fedilink
    English
    arrow-up
    4
    arrow-down
    1
    ·
    3 days ago
    • anyone gaining physical or remote access to the device can set rules. by protecting the entire network with a hardware firewall you mitigate attack vectors from other hardware on your network that become compromised.
    • iptables and firewalld are notorious for locking users out of the system by overzealous or green system admins. in the msp world this happens practically by the hour.
    • iptables and firewalld can be used against you in the event of a breach. one of the first things an attacker may attempt is to forward ports and lock system admins out as they take over the system.
    • make sure you save your rules properly or they’ll be gone after a reboot or botched upgrade
    • migrating your rules from one system to another when you’re changing hardware or restoring a system is a huge pain in the ass.
    • got a network change that’s going to modify the subnet your systems are on? get ready to migrate all 15 of your devices one by one for the next 8-15 hours (depending on the complexity of your rules)

    it’s far easier, and safer to have all your network config done in the network. from system migrations to securing/hardening. it’s far more efficient and effective to have a single source of truth that manages network routing and firewall rules. hell, you can even have a redundant or load balanced firewall configuration if you’re afraid of a single point of failure.

    point is, firewalld and iptables is for amateur hour and hobbyists.

    if you want to complain that “docker doesn’t respect system firewalls” then at least have the chutzpah enough to do it the right way from the beginning.