It is now very nearly impossible to install a headless Pi

Jan 26, 2024 Last reply: 2 years ago 94 Replies

OK, so it may be slightly more possible than I was surmising. However a Raspberry Pi isn't that fast, it'll run out of puff quite rapidly! My B+ takes quite a while just to log me in with password authentication! :-)

Well, as I said, at 5 seconds per attempt a dictionary attack is hopeless.

Particularly if you don’t allow password-based logins in the first place ...

Similar experiences here too and more like 15 years. They always seem to use a list of "common usernames" and another list of "common passwords". The 'smartest' one used some names from the company e-mail acct. In short, all script kiddies - bots - no pro/State-level stuff. Sorry to burst many egos, but really is YOUR server WORTH five CPU-seconds by N.Korea ???

Well ... there's $$$ in being a doom-sayer. Articles and 'news' (and security-ware vendors) always hype it up. I get several End-Of-The-World mails from Norton every single week.

You have to THINK about YOUR place on the hack-worthy totem pole and THEN act accordingly.

For SSH I never ever use the default port - and that seems to deter 99.9% of the bots right off. Limit max tries/sessions/ connections and that'll get rid of 99.9% of the remaining. Movie-style "hacking" is just not WORTH it for home/smallbiz systems. They go for the BIG stuff - banks/M$/SolarWinds/etc.

It's OK to use more-obscure dictionary words, just break it up with a few numbers/characters. 10-12 chars total is more than bots are interested in trying to figure out. Anyway, this way YOU can remember it, THEY can't be bothered trying to work it out.

The continuing most-dangerous thing out there is not "hacking" but "human factors" - esp mail-based ransomware and to some degree "click-ware". Humans never look for the ".ru" or whether the mail "smells right" - they just click the big shiny link. Those are SO EASY to mass-distribute that if even 0.05% fall for it they've made their money.

My successor is really really good with GiantCorp package offerings but I'm afraid he's kinda thin on the skills to actually analyze/research a smelly e-mail. So long as he can say it's M$'s fault the nasty thing got through ...

"Paranoia" is actually a mutant form of EGOTISM ... where some nobody comes to think THEY are SO important that giant spectral orgs and States are gonna spend millions and CPU-years and thousands of man-hours just to mess around with them.

Then comes the tinfoil wallpaper and hats and lead- lined underwear... and then proof of conspiracy when the cell reception gets crappy ...

How much is a botnet node worth ? In CPU-seconds ? Or to invert it how cheaply can they be obtained in CPU-seconds. I prefer that my systems aren't at the low end of the list but rather far enough up it that the bulk harvesters won't bother me.

It's like bicycle locks, nothing will stop a determined thief but any thief will go for the easy ones first so fit something half decent but don't go over the top.

Your broadband is plenty fast enough to launch DDNS attacks along with thousands of other compromised systems. It's the sheer number of compromised machines on a botnet rather than their connection speeds which makes it a problem.

Most of the attempts are against root or known service names, but there are lots of username/password attempts which have probably come from other successfully compromised systems, reminding you to never reuse credentials.

Your Pi may not be very important, but else can they get to once inside your network? And do you really want it to be used to attack others?

---druck

My chief engineer went to do a security audit and install a corporate firewall, and then test it.

His security report included:

- "The widespread use of dial in modems connecting to users DDI ports to enable them to operate their windows desktop computers from home represents a far greater security risk than that offered by the internet connection....

- "The list of root passwords pinned up behind the receptionist desk as well as the directory of usernames and DDI extensions is also sub optimal...

I rest your case....

Indeed. My B is fast because it has SSD, but the Zero takes an age.

Its also like bicycles in that a thief wont spend time on a worthless kids tricycle. When there is a carbon fibre mountain bike parked next to it.

I literally have nothing of value to a thief anywhere on any system. At worst, I might lose a small amount of money in a bank account, before the bank cried 'foul'. Every single financial transaction these days uses 2FA and and SMS to my smartphone.

They would need both.

And if I lose the smartphone, there are no banking details on it whatsoever.

That's all done from a desktop.

As I said, I personally am simply not worth hacking except as a botnet member.

I am thank Clapton, supremely unimportant in the grand scheme of things.

Not a lot really.

And I would notice a botnet DDOS attack within seconds. I have a permanent traffic sensor on every desktop and a web page monitoring router traffic. the moment those show anything the browser gets switched off. There are some sites that will enrol up in peer to peer s*it.

I have found two. I assume some javascript action of some sort.

I dont use them any more.

It's nothing like bicycles, botnet hurders don't care what they are cracking, adding another node to a botnet is the goal and one is pretty much as good as another. Also they aren't putting their own effort or their own CPU cycles into cracking new machines, it's being done by a script running on other peoples machines already in the botnet.

---druck

Sounds like something you should take up with the Ubuntu packagers. I maintain a Gentoo ebuild for rpi-imager (it's in my overlay...sudo eselect repository enable salfter && sudo emaint sync -r salfter), and it works like a champ.

More recently, I've migrated my print server (an ancient RPi Model B) from Raspbia^H^H^H^H^H^H^HRPi OS to Alpine, and it's running headless. The Alpine install needed to be done on a spare Raspberry Pi, but once it was up and running with ssh access, I was able to do the rest of the setup over the network. Once I had it configured as I wanted it, I brought the MicroSD card over to another computer to image it and shipped the image home so I could blast it onto an SD card. It's a much lighter-weight system now...could put it on a 128MB SD card, if I had one that small. :) The server runs headless, with just two printers, a network cable, and a power supply plugged in.

For remote access (to a headless box or otherwise), you should be using key-based authentication anyway and should disable password authentication in sshd.

I find it useful to have a weak point, one machine with password authentication, for that time I find myself on a machine without an appropriate key.

What is the usuaL set up for a home LAN, one key to rule them all, or a key for each machine?

One key for each host that needs to connect. That way, if one of your computers gets stolen or is lost, you can revoke its access.

Doesn't hurt to run a few utils like top and htop and ps every so often. Bots use cpu, memory and bandwidth. Some might do a fair job at disguise, others won't do so well. Simply re-booting, like a cron job at midnight, may be enough to mess up their function.

"Popular" systems - Win/Android/Mac - are going to be the primary targets, bots and such optimized for them. Linux proper is there, but not super-popular by the percentages. Win in particular is a security disaster and most users are know-nothings, best to put efforts there.

"Perfect" security does not exist, not even for mega-corps or federal/defense systems. Automated defenses are always behind the curve - the attackers always have the advantage. BUT - attackers DO want a decent investment/return picture and infesting my old C-64 or even my Pi-2 is not a good investment. Low exposure is also a priority for bots, if they show up everywhere then there will be detections and automatic responses made and the useful life of the bot will be short. In short, there's an economy to it to achieve maximum bang/buck.

Philosopher is almost TOO extreme, loses a lot of utility in order to be safe. That's his call. I'd like to be THAT stealthy, THAT much of a cyberverse ghost, but can't quite go that far (yet).

I'll still say the greatest risk is not hackers, but USERS. They fall for all the tricks and install evilware themselves.

Heh, heh ... :-)

Though dial-up modems are kinda yesterdecade (did find a new one still it its wrapped box under a desk when I cleaned out my office recently though)

A very REAL prob, which persists, is that more than one person often has to know connection usernames/passwords/ ports/etc no matter the methods. Multiple users may need to access each others data when "Mr. X" goes on vacation. You also cannot have just ONE super-duper 'vault' for said docs because redundancy is safety.

Redundancy is also vulnerability - it's a trade-off. You have to keep that "list on the wall" in more than one location - and you'll NEVER be sure some functionary didn't copy it into a Word doc in their Documents folder (the first thing intruders go at) for convenience.

No malice is required, simply normal human, inevitable, laziness. Could NOT do manual log-in to use network shares or 2FA or anything else nastily inconvenient at my old job - the staff wouldn't put up with it. Had to be fairly easy, automatic. Human nature and the truth of the cyberverse are often at odds - and the whiners win.

Best I could do was to allow no "home-worker" RDT type connections. Be there or be square. No 'active directory' or any other Win single-point auto-"update"-ware either. Many who did that stuff suffered horribly ; my "primitive" approach was closer to indestructible - evilware had few paths.

The new IT people, they really go for all that M$ convenience stuff - cloud networking, systemwide updates, remote-workers, no linux/unix master boxes, 3rd-party 'security monitoring', Online 365, PROMISED secure cloud storage/backups, all that "great" stuff. Probably not a single on-site backup. I used to pre-encrypt anything sent to cloud backup. They won't - they'll trust M$ or whomever.

Given the increasingly nasty world situation, I figure six months before NK or some Romanian ransomware kiddies blast it all to oblivion. Oh well, I'm out, getting my pension ... whatever will be will be. Nobody seems to learn anything ..........

Why specifically?

One argument against using key based authentication (in my case anyway) is that my home desktop and my laptop (which are the ssh clients) are turned on and logged-into just about all the time. Thus, with the default log-in key used for authentication, all my remote systems would be accessible to someone just walking up to desktop or laptop.

I *could* generate a separate key for every remote and force it to ask for the key every time I log in but that adds extra hassle every time I add or change a remote system.

Using the default (ssh password authentication) means that I have no extra configuration required to either default or local system **and** no on can casually walk up to desktop or laptop and get a login to a remote.

Yes, a key is harder to crack than a password, but a reasonably difficult to guess password is going to take far too long (in the real world) to break.

Which is of course the default setup with ssh. You generate a key on the client and that client key will get copied to all the systems to which that client wants to connect.

I (like most ssh users I suspect) only have two ssh client machines, my desktop and my laptop. They each have thirty or forty remote systems they connect to. If either got stolen it would be quite a job to remove all the remote keys!

The public key that is, of course.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required