• 20 Posts
  • 915 Comments
Joined 2 years ago
cake
Cake day: November 21st, 2023

help-circle


  • Windows security baselines. They suck. Not because they are bad, but because they aren’t enforced defaults. Turning them on breaks something and you have to dig through decades of policy and app configuration to figure out why.

    I wish once a year MS would have just made a security defaults update month and made a few changes so we could anticipate them and fix them collectively over time.





  • Port forwarding is a function of NAT. It’s only needed because there aren’t enough ipv4 addresses for every device, so in most networks a lot of devices share a single ip and specific ports are forwarded to specific internal hosts

    IPv6 has a large enough address space that this isn’t needed. You can still do it if you want. But mostly you just need a firewall without any NAT.

    There’s more to it than this but you should get the idea.