http://y5wnzw4e6i7srm2gqadlow5anhlaj5avdkzbwzbmrxwkygxdp7ffieqd.onion/blog/firehol-considered-useful.html
Thanks for reading ♥ For something like the ssh daemon, what I do is set public key login (ssh-keygen(1)) as the only login method (disabling password login) which would make it 'safe' for worldwide access because no one can possibly brute-force something that doesn't accept a password. While this is true, openssh is not perfect code! A CVE can be created and considering the ssh daemon tends to be the super user..... So I put the ssh daemon on the 'any' interface part of this config to...