Re: duqu

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]



On Wednesday, December 07, 2011 05:48:24 AM Adam Tauno Williams wrote:
> *DISABLE* password authentication on public-facing [and preferably all]
> servers.  Isn't that securing a server rule#1?

Interestingly enough, there are vulnerability scanning tools out there that will flag the lack of a password prompt as indicating that no password is required.... one such tool, which I can't name, is very popular in the PCI-DSS compliance industry.

In my particular case, I was able to convince the person running the scan that ssh with key-based security was better than passwords; but I could see where others would not be swayed, and would insist that having a password prompt is more secure..... (of course, that somewhat ignores how key-based auth works, but when you are just reading the scan tool's output and taking it as fact......)

_______________________________________________
CentOS mailing list
CentOS@xxxxxxxxxx
http://lists.centos.org/mailman/listinfo/centos


[Index of Archives]     [CentOS]     [CentOS Announce]     [CentOS Development]     [CentOS ARM Devel]     [CentOS Docs]     [CentOS Virtualization]     [Carrier Grade Linux]     [Linux Media]     [Asterisk]     [DCCP]     [Netdev]     [Xorg]     [Linux USB]
  Powered by Linux