Live data from Hacker News

Professionals: How do you make sure your computer hasn't been hacked?

news.ycombinator.com

21–30 of 32 posts

Re: Professionals: How do you make sure your computer hasn't been hacked?

#21

Earlier quoted context omitted.

>If the answer is no, then you've very little to worry about as long as you practice good security habits. This is very hard to define. I have all my servers on cloud locked down and can only ssh with keys (No passwords) and everytime I look at the access log, it just makes me sweat seeing all the "drive by" ssh access attempts using standard usernames (which I don't use) and even unstandard user names (like "mother"…

Have you tried/are you interested in setting a different port number on the server? Setting a different port number and using ssh_config on your clients (so you don't have to keep specifying the different port) helps a ton. I've done this with a Google 2FA solution[1] and honestly haven't seen a single rogue attempt. ----- [1] https://www.digitalocean.com/community/tutorials/how-to-set-...

While most guides/books on initial setting up sshd explain the usual stuff - e.g.: allow only key auth, no root ...etc.

Changing ssh port from standard (I literally forgot, is it 22?) to something else is one of those things you pick up in the field.

Usually only once you actually had to maintain production servers. And hopefully before some of the fancy things (e.g.: port-knockers) failed and locked you out :)

Changing port is super simple to configure and yet it cuts out 99.9% of noise (if not 100%) from brute-force attempts that otherwise might make you ignore alarms ...

Re: Professionals: How do you make sure your computer hasn't been hacked?

#22
Somewhat related, does anyone use Moxie's knocknock [0] or a similar procedure to secure ports?

Since I learned about it I thought it was a very interesting idea. Even tried it out a couple of times but not sure if anyone else is using it. It doesn't seem maintained and I'm not aware of more recent implementations of this.

Does anyone else use it for their setups? is it worth/not worth it?

[0]https://moxie.org/software/knockknock/

Re: Professionals: How do you make sure your computer hasn't been hacked?

#23

I just assume my system is hacked at all times and act accordingly. That is the only truly secure practice.

I wouldn't turn on a hacked system, except from an Ubuntu install DVD, or some other recovery disk.

Therefore the only secure practice (doing a combined approach) is to only boot from an install DVD.

Or alternatively: just never turn the computer on.

Re: Professionals: How do you make sure your computer hasn't been hacked?

#24

Earlier quoted context omitted.

You're being downvoted - maybe because it sounds like a snarky answer? I've thought about your response and after some thinking, I feel that it's a legitimate answer. I reflected for a moment and have decided that I am starting to do the same - using the computer with the expectation that I am not the only user. It's paranoid, but it also helps me sleep at night. Maybe working at a large insurance company, where ever…

I was being serious even if it came off flippant. There is no way to be 100% certain of your security with a system as complex as a computer so if you need 100% certainty then you have to assume you are compromised, even if that is a very low probability.

Now that I think about it, that's the same reasoning Batman used to justify attacking Superman in the movie.

Re: Professionals: How do you make sure your computer hasn't been hacked?

#27

Earlier quoted context omitted.

>If the answer is no, then you've very little to worry about as long as you practice good security habits. This is very hard to define. I have all my servers on cloud locked down and can only ssh with keys (No passwords) and everytime I look at the access log, it just makes me sweat seeing all the "drive by" ssh access attempts using standard usernames (which I don't use) and even unstandard user names (like "mother"…

Have you tried/are you interested in setting a different port number on the server? Setting a different port number and using ssh_config on your clients (so you don't have to keep specifying the different port) helps a ton. I've done this with a Google 2FA solution[1] and honestly haven't seen a single rogue attempt. ----- [1] https://www.digitalocean.com/community/tutorials/how-to-set-...

I will have to do this. Running a startup means some tasks are forever in the "todo" area

Re: Professionals: How do you make sure your computer hasn't been hacked?

#29
post #24

Earlier quoted context omitted.

I was being serious even if it came off flippant. There is no way to be 100% certain of your security with a system as complex as a computer so if you need 100% certainty then you have to assume you are compromised, even if that is a very low probability.

Now that I think about it, that's the same reasoning Batman used to justify attacking Superman in the movie.

"preemptive self-defense" ftw

Re: Professionals: How do you make sure your computer hasn't been hacked?

#30
Hey everyone ,i have just concluded a deal with a real hacker and i mean real hacker after searching for a while , i am so exicted thats why i am posting this to inform you guys , i hired him to help me hack my boy friends facebook and he gave prove before i paid him , he made a complete video of him login into the facebook account as prove ,he said he can also hack emails , twitter , whatsapp accounts , and phones , i am going to hire him again to hack an email dont hire any of this fake hackers here just visit http://www.cyphersecurityteam.ga or email him cypher_hacking_services@hotmail.com
Post reply on HN