<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title>danielmiessler.com - Latest Comments in Security and Obscurity: Does Changing Your SSH Port Lower Your Risk?</title><link>http://drm.disqus.com/</link><description>https://danielmiessler.com/about/</description><atom:link href="https://drm.disqus.com/security_and_obscurity_does_changing_your_ssh_port_lower_your_risk/latest.rss" rel="self"></atom:link><language>en</language><lastBuildDate>Sat, 26 Oct 2013 12:07:43 -0000</lastBuildDate><item><title>Re: Security and Obscurity: Does Changing Your SSH Port Lower Your Risk?</title><link>https://danielmiessler.com/blog/security-and-obscurity-does-changing-your-ssh-port-lower-your-risk#comment-1097560155</link><description>&lt;p&gt;Daniel,&lt;/p&gt;&lt;p&gt;I've followed your stories on BBR and HackerNews for a while now, this one is very intriguing and I appreciate the effort.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">cob</dc:creator><pubDate>Sat, 26 Oct 2013 12:07:43 -0000</pubDate></item><item><title>Re: Security and Obscurity: Does Changing Your SSH Port Lower Your Risk?</title><link>https://danielmiessler.com/blog/security-and-obscurity-does-changing-your-ssh-port-lower-your-risk#comment-152590617</link><description>&lt;p&gt;I agree that only good administrators should have access and the risk of a screw-up is low, but it is a risk - and that's what this is all about. Is the risk of an admin making a mistake (and even good ones do) higher than the risk of getting hit by an ssh 0-day and saved by a different port? In most cases I don't believe it is.&lt;/p&gt;&lt;p&gt;I would note that although changing the port should be an easy change, ssh is critical and a mistake made when configuring it can lead to a high security risk or leave you unable to fix a genuine security problem elsewhere. This is always the case but is surely an argument for reducing the time spent in sshd_config unnecessarily.&lt;br&gt;&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Bob</dc:creator><pubDate>Sat, 19 Feb 2011 13:04:15 -0000</pubDate></item><item><title>Re: Security and Obscurity: Does Changing Your SSH Port Lower Your Risk?</title><link>https://danielmiessler.com/blog/security-and-obscurity-does-changing-your-ssh-port-lower-your-risk#comment-152529061</link><description>&lt;p&gt;I have to say I was of the same mentality that the port changes were a stupid change that added complexity, but the point that really hit home for me was the zero-day one. We take for granted that SSH itself is secure. And if you want to buy yourself a bit of extra time from automated attacks when a zero-day gets exposed, running on a different port will most CERTAINLY buy you some time.&lt;/p&gt;&lt;p&gt;With regards to the added complexity part... any good administrator is inside the sshd_config file for any server deployment anyway, so changing the port number is very minimal risk. If you keep it consistent across your company, then anyone who has a legitimate reason to be using SSH anyway shouldn't have a problem with it after initial training. Anybody who is comfortable enough with SSH to be given server access should be fine at changing the port number to connect with. Anybody who isn't comfortable with that has no business having shell access to your server.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Justin DeMaris</dc:creator><pubDate>Sat, 19 Feb 2011 11:44:15 -0000</pubDate></item><item><title>Re: Security and Obscurity: Does Changing Your SSH Port Lower Your Risk?</title><link>https://danielmiessler.com/blog/security-and-obscurity-does-changing-your-ssh-port-lower-your-risk#comment-152465160</link><description>&lt;p&gt;It really isn't that simple.&lt;/p&gt;&lt;p&gt;A better analogy would be to say we could install a magical camouflage on our tanks that reduced the chance of getting hit by 1% but actually made it break down 1% more as well. Should we do it? Well, we could, but in the end it doesn't make any difference.&lt;/p&gt;&lt;p&gt;So changing the ssh port reduces my exposure to automated ssh attacks. I already have adequate protection against these through other policies (which I would require anyway), they are very very low risk.&lt;/p&gt;&lt;p&gt;However, by doing this I have at least:&lt;/p&gt;&lt;p&gt;- Made an additional configuration change. In other words, added complexity, no matter how minor. And we know about complexity and security.&lt;/p&gt;&lt;p&gt;- Added to user and admin WTF factor. Oh, here's that complexity again.&lt;/p&gt;&lt;p&gt;- Admin time taken away from dealing with real threats.&lt;/p&gt;&lt;p&gt;- Changed to a less-tested code path through ssh. In this case a very very minor one, but once you start making this sort tweak they all add up.&lt;/p&gt;&lt;p&gt;These are maybe a bit of a stretch but so is the idea of a different port stopping some new ssh 0-day.&lt;br&gt;&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Bob</dc:creator><pubDate>Sat, 19 Feb 2011 08:04:44 -0000</pubDate></item><item><title>Re: Security and Obscurity: Does Changing Your SSH Port Lower Your Risk?</title><link>https://danielmiessler.com/blog/security-and-obscurity-does-changing-your-ssh-port-lower-your-risk#comment-151927892</link><description>&lt;p&gt;If your tank armor is good enough then getting owned by a bullet is&lt;br&gt;small. So why use camo?&lt;/p&gt;&lt;p&gt;More importantly: Why not?&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Daniel Miessler</dc:creator><pubDate>Fri, 18 Feb 2011 19:39:43 -0000</pubDate></item><item><title>Re: Security and Obscurity: Does Changing Your SSH Port Lower Your Risk?</title><link>https://danielmiessler.com/blog/security-and-obscurity-does-changing-your-ssh-port-lower-your-risk#comment-151919038</link><description>&lt;p&gt;I think that sometimes people spend far too much time faffing around creating novel solutions to minor risks rather than putting the effort into following good practice - which will mitigate the trivial stuff anyway - and saving their creativity for the real worries.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Bob</dc:creator><pubDate>Fri, 18 Feb 2011 19:29:30 -0000</pubDate></item><item><title>Re: Security and Obscurity: Does Changing Your SSH Port Lower Your Risk?</title><link>https://danielmiessler.com/blog/security-and-obscurity-does-changing-your-ssh-port-lower-your-risk#comment-151918639</link><description>&lt;p&gt;The problem is that you measure the risk by the number of hits on your port.&lt;/p&gt;&lt;p&gt;Perhaps the 3 hits on the non-standard port are more risky than all of the other hits combined?&lt;/p&gt;&lt;p&gt;-- Arik&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Arik</dc:creator><pubDate>Fri, 18 Feb 2011 19:29:03 -0000</pubDate></item><item><title>Re: Security and Obscurity: Does Changing Your SSH Port Lower Your Risk?</title><link>https://danielmiessler.com/blog/security-and-obscurity-does-changing-your-ssh-port-lower-your-risk#comment-151916161</link><description>&lt;p&gt;I don't think this is really the case. If you follow good security practice then your risk of getting owned by an automated attempt is near zero even if a new OpenSSH vulnerability is found and - somehow - makes its way into automated scripts quickly enough for you to be hit without warning. These automated attempts are not a security risk for most people, at least I would hope not most people reading this. Moving port does precisely nothing to mitigate the genuine risk of a determined attacker except the thin argument that it reduces noise in logs, and there are other equally valid solutions there.&lt;br&gt;&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Bob</dc:creator><pubDate>Fri, 18 Feb 2011 19:26:11 -0000</pubDate></item><item><title>Re: Security and Obscurity: Does Changing Your SSH Port Lower Your Risk?</title><link>https://danielmiessler.com/blog/security-and-obscurity-does-changing-your-ssh-port-lower-your-risk#comment-151816423</link><description>&lt;p&gt;I think you discount the idea that many Internet-daemon compromises have nothing to do with successful authentication. And, as-is the case with past SSH vulnerabilities, buffer overflows can happen early-on in the protocol exchange, possibly leading to a root shell. Yeah, it's only a stop-gap measure, but moving services like SSH to a port not normally seen/probed in a basic namp scan tends to at least keep the script kiddies away (and, as you say, keeps your logs MUCh cleaner).&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Russell VT</dc:creator><pubDate>Fri, 18 Feb 2011 17:27:05 -0000</pubDate></item><item><title>Re: Security and Obscurity: Does Changing Your SSH Port Lower Your Risk?</title><link>https://danielmiessler.com/blog/security-and-obscurity-does-changing-your-ssh-port-lower-your-risk#comment-151810065</link><description>&lt;p&gt;You need to pick a "better" non-standard port ... preferably something not already defined on the "common list of TCP ports." You've experienced more probes on 24 in a weekend than I tend to see in a year or two. Simply adding some multiples of a hundred tends to get you off the list...&lt;/p&gt;&lt;p&gt;Ref: &lt;a href="http://en.wikipedia.org/wiki/List_of_TCP_and_UDP_port_numbers" rel="nofollow noopener" target="_blank" title="http://en.wikipedia.org/wiki/List_of_TCP_and_UDP_port_numbers"&gt;http://en.wikipedia.org/wik...&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Someone submitted you to Reddit, BTW:&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.reddit.com/r/netsec/comments/fnz1h/obscurity_does_changing_your_ssh_port_lower_your/" rel="nofollow noopener" target="_blank" title="http://www.reddit.com/r/netsec/comments/fnz1h/obscurity_does_changing_your_ssh_port_lower_your/"&gt;http://www.reddit.com/r/net...&lt;/a&gt;&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Russell VT</dc:creator><pubDate>Fri, 18 Feb 2011 17:20:35 -0000</pubDate></item><item><title>Re: Security and Obscurity: Does Changing Your SSH Port Lower Your Risk?</title><link>https://danielmiessler.com/blog/security-and-obscurity-does-changing-your-ssh-port-lower-your-risk#comment-151713955</link><description>&lt;p&gt;I change my ssh port to 443, though for a completely different reason. My school blocks outbound 22 on wifi...&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Pronto185</dc:creator><pubDate>Fri, 18 Feb 2011 15:29:27 -0000</pubDate></item><item><title>Re: Security and Obscurity: Does Changing Your SSH Port Lower Your Risk?</title><link>https://danielmiessler.com/blog/security-and-obscurity-does-changing-your-ssh-port-lower-your-risk#comment-151696305</link><description>&lt;p&gt;port 22, zero attempts. Iptables for the win.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Bob Smith</dc:creator><pubDate>Fri, 18 Feb 2011 15:07:57 -0000</pubDate></item><item><title>Re: Security and Obscurity: Does Changing Your SSH Port Lower Your Risk?</title><link>https://danielmiessler.com/blog/security-and-obscurity-does-changing-your-ssh-port-lower-your-risk#comment-151445636</link><description>&lt;p&gt;I think it's much simpler in the long run to just set up (for example) fail2ban, and never have to worry about what port your ssh was on or whether some other service or app will support a custom ssh port.  That's what I do for my VPS's and I have no complaints whatsoever.  Still, it makes an interesting point that an obscurity layer *on top of already sound security* can usually only make a good thing better.&lt;/p&gt;&lt;p&gt;The only worry is that the security may fail and you may never notice because it's already obscured.  This is most likely to happen in a situation where a system is likely to switch maintainers at some point and the new maintainer may not know all the ins &amp;amp; outs.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Evan Kaufman</dc:creator><pubDate>Fri, 18 Feb 2011 12:21:50 -0000</pubDate></item><item><title>Re: Security and Obscurity: Does Changing Your SSH Port Lower Your Risk?</title><link>https://danielmiessler.com/blog/security-and-obscurity-does-changing-your-ssh-port-lower-your-risk#comment-151444278</link><description>&lt;p&gt;Not really, they could try millions of times and fail if you have root password disabled and fail2ban set up.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">JC</dc:creator><pubDate>Fri, 18 Feb 2011 12:21:11 -0000</pubDate></item><item><title>Re: Security and Obscurity: Does Changing Your SSH Port Lower Your Risk?</title><link>https://danielmiessler.com/blog/security-and-obscurity-does-changing-your-ssh-port-lower-your-risk#comment-151428471</link><description>&lt;p&gt;I run SSH on a non-standard port sometimes, but I don't have any delusions that it actually helps anything. All my SSH are key-auth only. Since every bot in the universe attempts to connect with password auth, they will never get in even if I'm on port 22. The reason I move the port is simply to make the log files cleaner, since they won't be full of failed attempts.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Scott Rubin</dc:creator><pubDate>Fri, 18 Feb 2011 12:13:23 -0000</pubDate></item><item><title>Re: Security and Obscurity: Does Changing Your SSH Port Lower Your Risk?</title><link>https://danielmiessler.com/blog/security-and-obscurity-does-changing-your-ssh-port-lower-your-risk#comment-126528842</link><description>&lt;p&gt;From my own personal experience, I have no seen a difference in switching ports. I have to connect from hotels quite frequently. Obviously someone makes their living from hacking there, because when I get home I am still seeing attack on the port I selected for that week. If you just open the port, most automated attacks will use the default. If you are scanned and have banners, they will figure it out if they want. My guess is since they saw the traffic going to the particular receiver socket, they recorded it then performed their attack. In your experiment, how many connections were you making to port 24 from the public? Besides the minor annoyance of the attacker opening connections, and I had high hopes they were not going to crack my key and password.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">WebDesignHero</dc:creator><pubDate>Sun, 09 Jan 2011 13:06:44 -0000</pubDate></item><item><title>Re: Security and Obscurity: Does Changing Your SSH Port Lower Your Risk?</title><link>https://danielmiessler.com/blog/security-and-obscurity-does-changing-your-ssh-port-lower-your-risk#comment-11182106</link><description>&lt;p&gt;This is a really, really good idea.  Security through obscurity is not a replacement for other standard industry-best security practices, but it is a very helpful part.  &lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;The bottom line is it consumes server resources to deal with bogus connections.  Even if you have an effective rejection system in place, a non-standard port reduces the amount of traffic you have to deal with.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Sol Invictus</dc:creator><pubDate>Thu, 11 Dec 2008 20:29:00 -0000</pubDate></item><item><title>Re: Security and Obscurity: Does Changing Your SSH Port Lower Your Risk?</title><link>https://danielmiessler.com/blog/security-and-obscurity-does-changing-your-ssh-port-lower-your-risk#comment-11182104</link><description>&lt;p&gt;I do this too.  A while back I got really annoyed by the number of brute force attempts on my servers.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;I have a HIDS system in place which alerts me to brute force attacks.  On port 22 I would get at least 10 messages that it had blocked a brute force attack every day.  I thought about disabling that rule, but then I realized that what I wanted to do was block out the annoying scripts, not the deliberate attacks on my systems.  So I moved the SSH port to 831 (just made the number up).  Now I don't get the attack messages unless someone scans my system to look at open ports and attack the services on them, something which indicates a much more dedicated attack which I might actually be worried about.  I think I've gotten all of one ssh brute force alert across 10 servers.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;To mitigate the inconvenience I just put the ports in my .ssh/config file along with shorthands, such as:&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;Host s1&lt;br&gt;  HostName server1&lt;br&gt;  Port 831&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;Really quite elegant.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Drew</dc:creator><pubDate>Thu, 11 Dec 2008 17:12:58 -0000</pubDate></item><item><title>Re: Security and Obscurity: Does Changing Your SSH Port Lower Your Risk?</title><link>https://danielmiessler.com/blog/security-and-obscurity-does-changing-your-ssh-port-lower-your-risk#comment-11182102</link><description>&lt;p&gt;i used to do this, but switched to using knockd instead.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;one reason i switched is that it wasn't always easy to persuade other software to use the new port.  even sftp requires quite an ugly syntax to pass the parameter down to the ssh layer.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;the other reason was that my isp started "traffic shaping".  that means that data transfer using non-standard ports had limited bandwidth.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;neither of those is a very powerful argument (and i've since changed providers - from vtr to telefonica chile - to avoid the traffic shaping) and knockd is itself a bit frustrating to use if you don't have the client handy (you can trigger it using telnet, but it's hit and miss).&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;even so, you might consider it... &lt;a href="http://www.portknocking.org/" rel="nofollow noopener" target="_blank" title="http://www.portknocking.org/"&gt;http://www.portknocking.org/&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;ps also, of course, it can protect other protocols too.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">andrew cooke</dc:creator><pubDate>Thu, 11 Dec 2008 14:44:47 -0000</pubDate></item><item><title>Re: Security and Obscurity: Does Changing Your SSH Port Lower Your Risk?</title><link>https://danielmiessler.com/blog/security-and-obscurity-does-changing-your-ssh-port-lower-your-risk#comment-11182100</link><description>&lt;p&gt;I just run SSH on a non-standard port &amp;gt;1024 to keep down the size of my log files.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Mike</dc:creator><pubDate>Thu, 11 Dec 2008 12:22:32 -0000</pubDate></item><item><title>Re: Security and Obscurity: Does Changing Your SSH Port Lower Your Risk?</title><link>https://danielmiessler.com/blog/security-and-obscurity-does-changing-your-ssh-port-lower-your-risk#comment-11182097</link><description>&lt;p&gt;What you're advocating here is not so much security improvement through obscurity, but security improvement through irregularity.  You could proclaim from the mountaintops that you serve ssh on port 24—in fact, you just did—and it would still have improved your security.  Heck, you could respond to attempts on 22 with a message redirecting them two ports higher, and it would improve your security, because it would still filter out all the wardialer-style scripts.  It wouldn't work if everyone did the same thing, but by decreasing regularity, you make it much harder for the scripts to account for your case.  None of these stop someone determined to get into your system in particular, of course, but that's why you're not &lt;em&gt;relying&lt;/em&gt; on them.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">blahedo</dc:creator><pubDate>Fri, 29 Aug 2008 13:04:30 -0000</pubDate></item><item><title>Re: Security and Obscurity: Does Changing Your SSH Port Lower Your Risk?</title><link>https://danielmiessler.com/blog/security-and-obscurity-does-changing-your-ssh-port-lower-your-risk#comment-11182095</link><description>&lt;p&gt;plz can you tell me how to change the port of the ssh on fedora 8&lt;br&gt;because i&lt;code&gt;ve 2 servers on the same router when so i can&lt;/code&gt;t login to one of them because the servers ssh have the same port &lt;br&gt;plz help me , thx&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Samir</dc:creator><pubDate>Tue, 27 May 2008 13:39:55 -0000</pubDate></item><item><title>Re: Security and Obscurity: Does Changing Your SSH Port Lower Your Risk?</title><link>https://danielmiessler.com/blog/security-and-obscurity-does-changing-your-ssh-port-lower-your-risk#comment-11182093</link><description>&lt;p&gt;The problem with changing ports that services listen on is the loss of trust. Services that listen on ports lower than 1024 are considered "trusted" because they require root privileges. So if SSH is enabled on a very high port, I'd be worried about my personal security when I connect to that system.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;Also, using service detection with tools like NMAP will quickly remove negate any extra security that is provided by running on non-standard ports. &lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;The only upside to running on non-standard ports is that automated attacks won't occur, but honestly a good firewall ruleset or a something like deny_hosts really solves the problem while retaining the "trust" factor.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Sean</dc:creator><pubDate>Sun, 16 Mar 2008 15:33:30 -0000</pubDate></item><item><title>Re: Security and Obscurity: Does Changing Your SSH Port Lower Your Risk?</title><link>https://danielmiessler.com/blog/security-and-obscurity-does-changing-your-ssh-port-lower-your-risk#comment-11182091</link><description>&lt;p&gt;I agree wholeheartedly; it's just another level of protection as part of defence in depth - although I'd use port 48351, or similar, rather than port 24!&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;This action would only be security through obscurity if you had no password or private key on the accounts - the non-standard port was your only protection.  I'm sure that that is not the case!&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;A further protection is, on your firewall, to only permit connections with a source port less than 1024, then use the 'UsePrivilegedPort yes' in your ~/.ssh/config file to tell ssh to use source ports &amp;lt; 1024.  My quick checks with nmap showed that nmap used source ports over 1024 - so even a hit on the right destination port would not result in an 'open'.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;Were you monitoring the traffic to your ssh ports, if yes, were most of the source ports &amp;lt; 1024??&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Adrian Bool</dc:creator><pubDate>Sun, 16 Mar 2008 06:57:44 -0000</pubDate></item></channel></rss>