|
fail2ban is a real pet peeve of mine because anyone security conscious enough to deploy this will have likely already mitigated any actual security risks this could help with either by using a strong password or public key authentication. That leaves noise in the logs - which sure, it's nice to reduce, but using an alternative port can help here. I may sound like a spoilsport - but the fact that there have been a number of security vulnerabilities (https://www.cvedetails.com/vulnerability-list/vendor_id-5567...) in this project, make it worse than security theatre, it actually increases risk whilst not at all reducing it. |
Don't use fail2ban. (Don't use passwords, either!)
https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu...