BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] Trying to connect to internet in Debian
- Subject: [Discuss] Trying to connect to internet in Debian
- From: ron at bclug.ca (Ron)
- Date: Fri, 16 Jan 2026 16:18:44 -0800
- In-reply-to: <2251f0d2-d8f7-47ec-9797-36e6022e1311@app.fastmail.com>
- References: <20260114200605.72f09d97.Richard.Pieri@gmail.com> <13efd674-e437-4524-ba2c-f63d1a792516@app.fastmail.com> <20260115210552.50d857d3.Richard.Pieri@gmail.com> <0d375c22-412f-4cb8-a0fa-fe37c8ea6d90@app.fastmail.com> <20260116153626.0ce7346c.Richard.Pieri@gmail.com> <2251f0d2-d8f7-47ec-9797-36e6022e1311@app.fastmail.com>
Randall Rose wrote on 2026-01-16 14:07: > From my perspective, if a distro is used by naive users and it > sometimes installs things out-of-the-box that may have security > vulnerabilities which a firewall could help with I see a flaw in this logic: if an install includes, say, Apache, and there's a potential security vulnerability in Apache, a firewall won't help. If the firewall blocks traffic to Apache, it's breaking functionality. If Apache has a vulnerability, what can a firewall do to block the vulnerability? > then its installer > should offer a checkbox for installing a firewall with reasonable > settings that's already up and running on first boot. Probably because an active firewall by default would block things the admin requires. A *lot* of installs of Debian would be on servers, where the admin *needs* ssh access. Which a firewall rule might well block. A default firewall could (would) generate a lot of support questions / user problems. A sophisticated user can implement a firewall at their convenience. A naive user won't install one and won't need one since they're unlikely to be running listening services. If you trust the Debian maintainers enough to install their OS, you should trust their decision on this. I run a bunch of Ubuntu servers on VPSs that are wide open to the internet. Not a firewall on any of them. Not a problem yet. (Well, I do block a lot of IPs with iptables due to excessive attempts on email servers, but that's not really a firewall.)
- References:
- [Discuss] Looking for a PCIe USB host bus adapter
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] Trying to connect to internet in Debian
- From: rrose at pobox.com (Randall Rose)
- [Discuss] Trying to connect to internet in Debian
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] Trying to connect to internet in Debian
- From: rrose at pobox.com (Randall Rose)
- [Discuss] Trying to connect to internet in Debian
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] Trying to connect to internet in Debian
- From: rrose at pobox.com (Randall Rose)
- [Discuss] Looking for a PCIe USB host bus adapter
- Prev by Date: [Discuss] Trying to connect to internet in Debian
- Next by Date: [Discuss] Trying to connect to internet in Debian
- Previous by thread: [Discuss] Rust; was Trying to connect to internet in Debian
- Next by thread: [Discuss] Trying to connect to internet in Debian
- Index(es):
