So this government Covid 19 tracking app is an interesting idea – they even said that they would release the source code…. all very good, I’m thinking I may even install the thing… but then today I read this!
Hi I’m very proud to announce that my application (which I still haven’t found a name for!) is ready for beta release. It’s a very light command line app that uses log data for security hardening, so if you use Ubuntu, debian or linux (and or nginx or apache2) and are comfortable with the command line then please do get in touch. At this stage it’s a fairly simple app and in effect a security tool for those of us who can not afford thousands of dollars towards their own IDS.
This application will probably be most useful for smb running their own sites (small aws installs for example) for people who want extra security, and to stop a lot of the “noise” that hits the average web server.
If you want more information, have a look at the intro vid I made that is put up on youtube..
All I ask is that you supply the version of ubuntu / linux that you’re using and that after looking at the app take the time to fill in a short survey.
Look forward to hearing from you Regards Steve Abrahall PS if your interested email me at
steveabrahall AT gmail DOT comm
To find out what version of the os your using lsb_release -a
Did some testing this morning on the new certs and realised that things were not working in firefox and at one point I think I saw an erro in chrome! Problem was fire fox needed both www and non www versions of the site name. Re issuing the cert sorted this in no time!
This is how the process worked out…!
sudo certbot --nginx Saving debug log to /var/log/letsencrypt/letsencrypt.log Plugins selected: Authenticator nginx, Installer nginx No names were found in your configuration files. Please enter in your domain name(s) (comma and/or space separated) (Enter 'c' to cancel): www.gingercatsoftware.com gingercatsoftware.com
Don’t use a pass word! Use a pass phrase . Twelve or more letters, the odd number and lower and upper case letters, make it something you can remember but long and easy for you to remember is the most important thing.
For example I like dogs, bentley cars and pingpong I might write a sticky note that says *_* Fave animal Fave car Fave sport
and the pass phrase might look like
This is a good pass phrase But think of it like this
There are 62 possibilities for each character, and 16 characters. This translates to 62^16 (47672401706823533450263330816) trials worse case, or half of that on average. If the attacker can do a billion trials per second, that means 47672401706823533450 seconds, which is about 1511681941489 years. I think that’s pretty good protection. You could even chop off a few characters and still feel pretty safe.
Probably best not to put your exact pass phrase in this (just in case some one nasty sniffs if across the net work or the interweb) but have a play with this site it’s fun and gets the point home.
The other thing is don’t use the same pass phrase for all accounts! What you might say do I have to remember lots of pass phrases? Well the next thing to do is start using the keychain, but I’ll talk more about this in another exciting episode!