Live data from Hacker News

How SSH Port Became 22

ssh.com

71–80 of 89 posts

Re: How SSH Port Became 22

#71
post #64
post #58

Funnily enough, changing the ssh port to a random unprivileged one is now possibly the easiest and most effective step to harden a box... I guess it shows how the internet has changed.

In the last two months, I've been getting lots of bruteforce scan attempts on all my boxes that run ssh on high ports, so it seems this is no longer as effective as it was :-/

You are not alone in this. This week I actually changed ports for ssh because of the sheer number of brute force attempts. We'll see how long that holds out.

Re: How SSH Port Became 22

#72
post #54

Earlier quoted context omitted.

Not really. He asked IANA, which was literally 2 guys in a room back in the 90's. Literally anyone could get a port assigned in those days, just like anyone could get a /24 address block.

>just like anyone could get a /24 address block. FWIW pretty much anyone who can afford the relatively low fees can still get a /24 today, but sure, the process is slightly slower.

Back then, /24's were free, and all it took was an email. No justification required. I still have one (legacy registration) and have never paid anything.

Re: How SSH Port Became 22

#73
SSH is a service, the port is a standard, but the service doesn't have to be on port 22, it's just the standards base port. I never run it on port 22 exposed to the internet (because of the flagrant criminals on the internet trying to hack into systems).

Re: How SSH Port Became 22

#74
post #64

Earlier quoted context omitted.

In the last two months, I've been getting lots of bruteforce scan attempts on all my boxes that run ssh on high ports, so it seems this is no longer as effective as it was :-/

You are not alone in this. This week I actually changed ports for ssh because of the sheer number of brute force attempts. We'll see how long that holds out.

Why not just restrict access to specific IP blocks? Even if you left it open to Verizon's entire IP space so you can hit it with your cell, you would still dramatically lower your incident rate.

Re: How SSH Port Became 22

#75
Look how easy was the whole procedure. You just sent an email and boom next day your application's port was registered by IANA. Nowdays you must have a team of academics backed up by Google to apply for that.

Re: How SSH Port Became 22

#76
post #39

Earlier quoted context omitted.

Paul did not invent/created BIND, in fact BIND was created 8 years before he took over its maintenance. BIND was created in Berkeley by grad students (probably that's why originally was so buggy) and the name stands for Berkeley Internet Name Domain. Paul of course made major contributions to DNS and of course BIND.

Berkeley Internet Name Daemon

It's actually "Domain", not "Daemon". There's a couple of good episodes of "The Network Collective" podcast that discuss the early history of DNS and BIND:

- https://thenetworkcollective.com/2018/01/hon-dns-origins/

- https://thenetworkcollective.com/2018/01/dns-adoption/

Re: How SSH Port Became 22

#77
post #39
post #31

So the crux of the story is “I had to email an internet icon and she mailed me back right away having done what I asked”. I can sympathize. When I worked at Sendmail I was tasked with running DNS for the company, which included Sendmail.org. The first thing I had to do was find a secondary DNS. Our founder said to “email his friend Paul”. It turned out his friend was Paul Vixie, the inventor of BIND, who responded in…

Paul did not invent/created BIND, in fact BIND was created 8 years before he took over its maintenance. BIND was created in Berkeley by grad students (probably that's why originally was so buggy) and the name stands for Berkeley Internet Name Domain. Paul of course made major contributions to DNS and of course BIND.

He co-founded ISC, and was in charge of BIND 8 IIRC.

* https://en.wikipedia.org/wiki/Paul_Vixie

See also Vixie cron.

Re: How SSH Port Became 22

#78

Look how easy was the whole procedure. You just sent an email and boom next day your application's port was registered by IANA. Nowdays you must have a team of academics backed up by Google to apply for that.

The internet was a sort of toy used by 10000 people.

Nowadays you should need 2 teams of academics backed up by 4 companies and 2 governments to change anything.

I'm not kidding. The internet of today should be like democracy: really hard and slow to change because sudden change is very disruptive.

Re: How SSH Port Became 22

#79

Look how easy was the whole procedure. You just sent an email and boom next day your application's port was registered by IANA. Nowdays you must have a team of academics backed up by Google to apply for that.

I remember applying for a Class C block of IP addresses back in 1993 was as simple as sending in a preformatted email template to InterNIC and getting your address space about twenty minutes later in a reply.

I've still got that Class C registered, but it hasn't been used in years, and I'm not entirely sure what to do with it.

Re: How SSH Port Became 22

#80
post #78

Look how easy was the whole procedure. You just sent an email and boom next day your application's port was registered by IANA. Nowdays you must have a team of academics backed up by Google to apply for that.

The internet was a sort of toy used by 10000 people. Nowadays you should need 2 teams of academics backed up by 4 companies and 2 governments to change anything. I'm not kidding. The internet of today should be like democracy: really hard and slow to change because sudden change is very disruptive.

Yeah, that's my point. It was like a playground of technologists and hackers. I wish I was born earlier to experience this magic place.
Post reply on HN