HN user

evs91

1 karma
Posts0
Comments13
View on HN
No posts found.

consumer EDR "could" detect it if everyone knew what to look for and the pricing was good. Unfortunately (or not) EDR for consumers is limited to really just the MS365 addon for Microsoft Defender for Endpoint (P2) which is $3 a month on top of your MS365 license (so looking at a good value if you already have an enterprise tenant even if solo). Downside: it's a firehose of information and is a full-time job managing for SMB. But to the other comment here: sandboxing / runtime isolation helps. It's more an onion than a strict wall. One failure shouldn't cause the city to collapse.

CoreGPT 5 months ago

yeah; no way with the data currently collected and lack of any audit certifications would I ever allow this on enterprise tenants. lmao.

You are pretty much going to experience that no matter what. Even if you update UFW to only allow Cloudflare IP ranges, you will get scans against SSH and if you turn on deny logging you will see that your IP still is being scanned. Changing the IP just moves your target somewhere else for it to be indexed again. Fail2Ban rules, like you mentioned, will reduce your attack surface and get the "background" automated attacks somewhat at bay. You can do things like only allowing SNI HTTPS requests and not direct IP connections (which is what you doing with the Cloudflare proxy). From what you are saying: you are doing a solid middle of the road start. I would focus on making sure you keep the security posture up as you implement other services. Is this just for your projects or are you providing a service to customers? If it's just you - does the effort merit the work. If its customers, there are more things you can do but "do you need to" is going to be more up to you.

TL;DR - sounds like a solid starting place; don't worry about the IP address

Free AI API Key 1 year ago

Cerebras alone for the speed of the response - it was quite jarring the first time to see a 70B model respond near instantly.