Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


View this topic in a long page with up to 500 replies per page Create new topic
1 | 2 
Tinkerisk
4909 posts

Uber Geek
+1 received by user: 3827


  #3219170 16-Apr-2024 16:21
Send private message

turtleattacks:

 

Given that it's only going to be used as an internal file server - would it make sense just to block internet access to the W11 machine?

 

(upgraded to W11 from W10). 

 

 

Anyone asking such questions should only switch on a server after clarification. Sorry, this is not meant personally, but in terms of security.

 

 





     

  • Qui nihil scit, omnia credere debet. - He who knows nothing must believe everything.
  • Firewalls do NOT stop dragons. Really not!
  • I avoid Big Tech. They try hard to dictate technology and „culture“ across borders.
  • In effect we have everything to hide from someone, and no idea who „someone“ is.



turtleattacks

1021 posts

Uber Geek
+1 received by user: 311

Trusted

  #3219172 16-Apr-2024 16:23
Send private message

Tinkerisk:

 

turtleattacks:

 

Given that it's only going to be used as an internal file server - would it make sense just to block internet access to the W11 machine?

 

(upgraded to W11 from W10). 

 

 

Anyone asking such questions should only switch on a server after clarification. Sorry, this is not meant personally, but in terms of security.

 

 

 

 

 

 

No offense taken mate, I'm still trying to learn as I go myself. 





Tinkerisk
4909 posts

Uber Geek
+1 received by user: 3827


  #3219175 16-Apr-2024 16:34
Send private message

turtleattacks:

 

No offense taken mate, I'm still trying to learn as I go myself. 

 

 

A server is protected for access FROM the Internet. If it is only used for internal purposes, access from the Internet is completely blocked. However, a connection TO the Internet makes sense for (automatic) security and version updates, but a firewall should prevent the server from becoming independent, e.g. only being able to establish very specific connections to the Internet. Otherwise, TO the Internet access can be completely blocked, which then results in manual updates.





     

  • Qui nihil scit, omnia credere debet. - He who knows nothing must believe everything.
  • Firewalls do NOT stop dragons. Really not!
  • I avoid Big Tech. They try hard to dictate technology and „culture“ across borders.
  • In effect we have everything to hide from someone, and no idea who „someone“ is.



MadEngineer
4644 posts

Uber Geek
+1 received by user: 2622

Trusted

  #3219310 16-Apr-2024 20:46
Send private message

Tinkerisk:

 

turtleattacks:

 

No offense taken mate, I'm still trying to learn as I go myself. 

 

 

A server is protected for access FROM the Internet. If it is only used for internal purposes, access from the Internet is completely blocked. However, a connection TO the Internet makes sense for (automatic) security and version updates, but a firewall should prevent the server from becoming independent, e.g. only being able to establish very specific connections to the Internet. Otherwise, TO the Internet access can be completely blocked, which then results in manual updates.

 

Never make the false assumption that because you've protected something from the internet that it's safe.  Lateral movement is a tab key away from within a hackers toolkit once they're in your network.





You're not on Atlantis anymore, Duncan Idaho.

Tinkerisk
4909 posts

Uber Geek
+1 received by user: 3827


  #3219313 16-Apr-2024 21:08
Send private message

MadEngineer:

 

Tinkerisk:

 

A server is protected for access FROM the Internet. If it is only used for internal purposes, access from the Internet is completely blocked. However, a connection TO the Internet makes sense for (automatic) security and version updates, but a firewall should prevent the server from becoming independent, e.g. only being able to establish very specific connections to the Internet. Otherwise, TO the Internet access can be completely blocked, which then results in manual updates.

 

Never make the false assumption that because you've protected something from the internet that it's safe.  Lateral movement is a tab key away from within a hackers toolkit once they're in your network.

 

 

Hence my reference to the firewall, which standard routers do not have or only have as a ‚light’ version. So I don't assume anything as safe, neither in front of it nor behind it. 😉





     

  • Qui nihil scit, omnia credere debet. - He who knows nothing must believe everything.
  • Firewalls do NOT stop dragons. Really not!
  • I avoid Big Tech. They try hard to dictate technology and „culture“ across borders.
  • In effect we have everything to hide from someone, and no idea who „someone“ is.

1 | 2 
View this topic in a long page with up to 500 replies per page Create new topic








Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.