Just How Effective is System Hardening?
SkiifGeek, pointing to our recent coverage of what the NSA went through to create SELINUX, wants to know just how effective system hardening is at preventing successful attack, and writes "When Jay Beale presented at DefCon 14, he quoted statistics (PDF link) that Bastille protected against every major threat targeting Red Hat 6, before the threats were known. With simple techniques available for the everyday user which can start them on the path towards system hardening, just how effective have you found system and network hardening to be? The NSA does have some excellent guides to help harden not only your OS but also your browser and network equipment."
/. is just the place to come for advice on "system hardening."
System hardening is just another layer of a "defense in depth" security posture. The more layers, the better. So, if an adversary manages to get through your site firewall, access lists, IPS, vlan segregation, virus scanner, etc, they still have to contend with a hardened local system in order to compromise data.
System hardening is also very helpful against inside jobs, or against other systems on the network compromised through brute force or social engineering.
I found encasing the system in steel reinforced concrete made the system much harder. Similar attempts to place end users in the same situation were not as successful.
Ubiquitously - A Ubiquity Developer Community
I use Ubuntu 8.04. It's hardy out of the box.
Aych tea tea pea colon slash slash slash dot dot org slash
I use security through obsolescence. Nobody's going to crack my ENIAC clone!
mcgrew's razor: Never attribute to stupidity that which can be explained by greedy self-interest
A lot more work and a lot less dead time than waiting for IT to resurrect a completely fsck'd system, maybe?
I'm not wary at all. Any access they might want into your Windows system was probably built in. I imagine they already have that kind of access to every Windows computer. Anything they can give you to help keep your Windows machine from turning into part of a North Korean botnet can only benefit both you and the government.