@stefano I don't doubt the #efficiency and #quality of #FreeBSD nor the #security of #OpenBSD.

@aki #LDAP is definitely the point.

  • #SelfHosting of #Mailservers make at least nominally sense.

  • Caving in to the sharade of #SSL commercialization is quite much for me as @cacert assurer.

@ytc1 @DenOfEarth @aka_pugs I know.

And espechally in #ScientificComputing a lot of researchers loved working with #SunMicrosystems and when #Oracle took over that relationship got sour'd instantly due to #Oracle #CEO #LarryEllison...

-> https://infosec.space/@kkarhan/114682503920794745

One of the big successes of #Sun was that they basically declared a unilateral "ceasefire" in terms of #IP & #Patents re: #OpenSource. Whereas Oracle didn't seem willing to honour that.

  • Without that cooperative atmosphere we saw #OpenOffice devs literally forking off into @libreoffice and projects like #illumos and @openzfs scramble to save what was OpenSource'd and also rescue that.

Obviously #Linux with it's #GPLv2only-Kernel and most of it's Userland could not get 'closed-sourced' like #OpenSolaris which instantly got stomped out by Oracle as they wanted to sqeeze #Solaris for profits and milk their clients in typical Oracle fashion...

Now granted, I do know someone who for most of their life made their money dealing with the intricacies of setting up #postfix, #sendmail and #courier #MailServers on Solaris and if I ask said person about that they give me a kilometer stare, so OFC like a #SysV - #Unix systems Solaris and #SunOS really are one of the reasons #WindowsNT won the "#WorkstationWar" and why - if anyone - #Apple won the last "#UnixWar"...

  • Still I do am sad that I declined that #sysadmin position at a leading research center I'm not at liberty to name and I do know there's OFC still some critical infrastructure running even older Solaris servers...

https://mastodon.sdf.org/@ytc1/114689337148586939

Kevin Karhan :verified: (@[email protected])

@[email protected] @[email protected] I know. Cade in point, #OpenSolaris did have avid users just below that range, and a lot of #ScientificComputing used it, as they previously used #IRIX. And #Sun being #OpenSourve-friendly was the right direction...

Infosec.Space

@topher #Antivirus is for the most part #Scareware aimed at scamming #TechIlliterates which at best only works against kniwn threats and at worst is literal #Malware in and of itself selling user data to bad actors.

As for the rest one can just scan #Fileservers regularly and do so on #Mailservers, but existing tools to enforce quick and early updates on those distros already do most of the heavy lifting re: #ITsec...

#JustSayling

Antivirus and Internet Security Solutions

Best IT security solutions for your home and business devices. Try ESET antivirus and internet security solutions for Windows, Android, Mac or Linux OS.

Over 3 Million Mail Servers without Encryption exposed to Sniffing Attacks.

As scans from the IT-security threat monitoring platform Shadowserver show, 3.3 million hosts are running POP3/IMAP services without TLS encryption enabled and expose usernames & passwords in plain text when transmitted over the Internet.

https://www.shadowserver.org/what-we-do/network-reporting/vulnerable-pop3-report/

#pop3 #imap #mailservers #exposed #sniffing #tls #it #security #privacy #engineer #media #tech #news

HIGH: Vulnerable POP3 Report | The Shadowserver Foundation

This report identifies hosts that have a POP3 service running on port 110/TCP or 995/TCP without TLS support. This means that passwords used for mail access may be intercepted by a network sniffer. Additionally, service exposure may enable password guessing attacks against the server.

@Szwendacz I think #Antivirus and #Malware protection should be the sole responsibility of the #maintainer of said #OS / #Distro!

And I'd happily pay for #support and have that in writing for more than just #compliance reasons...

That being said #Linux already dominates (#Android is just a #toybox + #musl / #Linux distro and for the vast majority of people - espechally in the global south, it is their #Desktop!) and it "solved" the malware problem just by taking away 'the means to fuck up a system' from #TechIlliterate #users - as any reasonable #sysadmin should do anyway...

  • Something that may not work at all on #macOS and espechally on #Windows due to it not having permission managment and actual security in it's design!

So yeah, 3rd party #AV may seem like #Scareware on #Linux (and #Mailservers should at least #ClamAV their inboxes) but on Windows they are absolutely pointless given than those are #BinaryBlob - #Kernelhacks (none of them got Sourcecode access for Windows!) that actually lessen #security of the System!

  • I don't trust #Microsoft and thus I don't use Windows - period!
ADMIN #80 is available now! In this issue, we look at threat management strategies and tools. Get your copy today! https://bit.ly/ADMIN-library #security #containers #MailServers #Azure #scripting #chatbot #MySQL #Kubernetes #Microsoft #Bicep #cloud #ransomware #Kubescape #RustDesk
ADMIN Print Issues | Linux New Media Shop

Linux New Media Shop
@lamp @Mastodon @MastodonEngineering @puniko I know, but the #Fediverse kinda makes #SelfHosting quite #paywalled even compared to @Websites and #Mailservers...

Hrm. When you have #dmarc setup for your #mailservers, getting reports is nice.

Then you get the idea that you could also have your tools send out #reports. Ok, sure, easy to setup, just a cronjob.

But then, umm, it seems I am missing something.
Sending dmarc reports for mails that clearly had been spam (#rspamd sorted them out correctly), seems like an idiotic idea to me?! "Heyho, I got your mail all fine, here is a report, come on, send more" seems to not be the wisest move available.

But there also doesn't appear to be an option to skip on such things. Except for setting either exclude_domains or only_domains.
For the first I would need to know which domains spammers send from. So nope, out.
For the second I limit myself to just a few domains to send to. Which would be the known big ones usually, and that's not much interesting.

Meh, so for now, no report sending.

@Annalee

Exactly!
Because whilst #OpenBSD is propably the safest Operating System that one can hook up to the Internet out-of-the-box, noone's gonna yeet all their #Linux boxes out and force themselves to migrate everything to it.

Just because I know people who earned their living doing #Mailservers on #OpenBSD doesn't mean it's something I'd recommend to anyone even if on paper that's the "most secure option"...