On 17/12/11 10:09, Tim wrote: > On Fri, 2011-12-16 at 14:39 +0000, Jake Shipton wrote: >> Though my system is logged like a server should be, even though it's >> just a plain and simple desktop on ethernet behind a router & firewall >> not moving anywhere.. but I do like to know what my system does. I >> probably would detect a break in attempt before they got in :-) > > Well, if you are being security minded, logs on the same machine can't > be trusted. Because someone who can break in, can do something to > change the logging. ;-) > This is true, which is why most of my logs are mailed locally to a separate user account which is solely used for mailing, and then checked by my mail client, which will then move them via IMAP to my Gmail inbox :-). Whilst logs could be intercepted prior to being mailed to that separate user account and fetched by my mail client, I would receive a nearly instant mail on an actual break in attempt (Lets say for sake of argument, an SSH Brute Force) Which will give me a nice whois, ip address and nmap scan of said person who attempted to brute-force me, in my gmail inbox :-). Of course, they could also attack my gmail inbox.. but even if they get the password for that, I enabled their "two-step authentication" thing, where it needs a code to login which is unique per login, which will be sent to my mobile phone as an SMS.. so they would need to hack my mobile phone aswell.. And to be quite honest, I don't think any cracker would bother doing all that just to try to get into an every day users computer, or hide them selves. Server maybe, Desktop? Unlikely (imo). All of that, mixed with safe web browsing (I don't just click random links, or download random stuff..) and tripwire, rkhunter etc.. I think the chances of a break into my system are fairly low. But still, could be possible if a person is determined enough. After-all, nothing is impossible... -- Jake -- users mailing list users@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe or change subscription options: https://admin.fedoraproject.org/mailman/listinfo/users Guidelines: http://fedoraproject.org/wiki/Mailing_list_guidelines Have a question? Ask away: http://ask.fedoraproject.org