Email or username:

Password:

Forgot your password?
dee 🏳️‍⚧️

fail2ban has one core maintainer github.com/fail2ban/fail2ban and he has only 3 Github sponsors github.com/sebres

WTF

I can't even comprehend how many servers are protected by fail2ban, how many compromises are avoided, how many people who run hobby things all the way up to major sites that get to sleep soundly every night... because of this single project.

#oss

35 comments
Chuck Darwin

@dee

Fail2Ban:
ban hosts that cause multiple authentication errors

Fail2Ban scans log files like /var/log/auth.log and bans IP addresses conducting too many failed login attempts.

It does this by updating system firewall rules to reject new connections from those IP addresses, for a configurable amount of time.

Fail2Ban comes out-of-the-box ready to read many standard log files, such as those for sshd and Apache,
and is easily configured to read any log file of your choosing, for any error you wish.

Though Fail2Ban is able to reduce the rate of incorrect authentication attempts,
it cannot eliminate the risk presented by weak authentication.

Set up services to use only two factor, or public/private authentication mechanisms if you really want to protect services.

@dee

Fail2Ban:
ban hosts that cause multiple authentication errors

Fail2Ban scans log files like /var/log/auth.log and bans IP addresses conducting too many failed login attempts.

It does this by updating system firewall rules to reject new connections from those IP addresses, for a configurable amount of time.

Tim Lavoie

@cdarwin - I'm curious about the point of your post.
Pretty sure @dee knows full well what fail2ban is, and does.

CIMB4

@tim_lavoie @cdarwin @dee guess what, i didn't anf found the comment very enligtening :3

Melroy van den Berg

@dee here is the direct link to the sponsor page, in case somebody want to sponsor him: github.com/sponsors/sebres

Kera Vortiwife

@dee that one xkcd comic continues to be painfully correct

kajer

@dee

Wait... so if you dos his account...

mirabilos

@dee you know the xkcd for that, do you?

Signed /system/bin/sh on Android

Deus
Sometimes it's not always about the funds or $$. Have met a lot of developers who enjoy the freedom and the recognition without the money. Freedom = You feel obligated to sponsors so most want to avoid that 'shackle' and do things the way they like.

https://coracle.social/nevent1qqs26rmlukaspg3zf69m5qsqcwcaynxxae7wg9hzexla90v8vqw4mcsprpmhxue69uhhyetvv9ujumt0d4hhxarj9ecxjmntqld5am

Reed Mideke

@dee Well the good news for the maintainer is they can retire comfortably at any time by selling the project to an APT /s

ThomasCraig

@dee This presents a #security risk to any organisation that depends on #failtoban but is not supporting it.

Has anybody successfully championed for their org to make recurring donations to the open source software projects they rely on? How did you do it? Any challenges you confronted?

poleguy

@ThomasCraig @dee I tried to get my company to support #freecad. But I was able only to get a one time small hundred dollar donation. It had to be done by me and reimbursed because the company (#shure) did not want it to look like an endorsement for some odd reason. It was also hard to donate because only individuals were accepting donations at the time. Maybe there is an organization now? But it was a lot of work and nobody really seemed to care: Hit the schedule. Buy expensive Microsoft stuff.

Sarvo

@dee@grafana.social never needed to use it but yeah that's insane, hope you donated tho.

:neocat_scream: kitty!

@dee should I complain about this problem being immanent to the system that privatises profits and socialises losses?

13reak

@dee

Unfortunately, I strongly believe this is not the only project that looks like this. Companies only use open source and hardly support it. But when there's a vuln, the outcry to the maintainer is big.

Kevin Karhan :verified:

@dee Yeah...

It's beyond me that #fail2ban is so critically underfunded.

The Doctor

@kkarhan @dee Too many folks went all-in on Tailscale and just don't care about it. It's a frustrating thing to watch.

Ari [APz] Sovijärvi

@dee I've been in a position where I could ask for my higher ups some funds to put into open source projects to which the company depended on. Guess how often the bosses saw the light.

They rather spent the money on something that's more "clear" to them what you get for the money, like licenses on stuff we really don't need.

Irenes (many)

@dee oh wow GOOD catch

you remember that whole thing we wrote after the xz incident, about how isolated maintainers need support from the community as a defense against abuse? https://cohost.org/ireneista/post/5349137-xz-and-community

FC (Fay) 🏳️‍🌈

@ireneista @dee this is really good (and reflects my own views). thanks!

(I'm lucky to be part of a supportive community now, but I'm still worried about being the sole maintainer of several projects essential for Android Reproducible Builds)

Adrian Cochrane

(Footnote) quote from linked page:

"I’ve come to really distrust the term “open-source”, as its original intention was – and remains – to make work exploitable by large companies, rather than to protect users or developers"

@LGUG2Z @dee

Adrian Cochrane

@LGUG2Z @dee I love the title "The Problem With Free Software…
…Is Capitalism"!

Michael Vilain

@dee it could be worse. It could be ntp source still running on the desktop in the single developers basement instead of in a GitHub repo thanks to Susan Sons.

Mina

@dee does your project have a cool logo and sexy marketing, or is it just core infrastructure?

LisPi
@dee @indigoparadox While I definitely do agree with the "support your Free Software dev" message, I'm somewhat skeptical of the security aspect implied.

With botnets being as popular as they are, fail2ban always struck me more as a mitigation measure for unnecessary system load, rather than a security measure.
Philip

@dee @miclgael I bumped into this fact recently when I reached out about some translation issues. I had no idea. It’s the defacto software to use that *every* article on server security recommends. 🤯

Angle

@dee Thinking about this, and like - whose job is it, precisely, to ensure this kind of thing doesn't happen? That core infra like this has more support? Do we expect the government to do it? Corporations? Or if neither of them, (Not keen on either, personally), then who? Is someone going to go "This is my job, I will systematically review all open source projects and make note of the ones that need more support"?

Angle

@dee Is this a job for some non-profit foundation, maybe? Or just a whole gaggle of different people, all with their own crowdfunding or whatever? :/

Angle

@dee Personally, I wouldn't mind taking a step back and funding an organization whose job it is to find problems like this and assemble solutions for them - find people to review all the core infra software and make sure it's supported, or assemble resources for the programmers of such, or a million other things. That's no small ask though - even just deciding what, exactly, falls within that area is quite a task. :/

Angle

@dee I've been thinking about doing something like that for my game, once I get it going - aiming to have, not just modders and map makers and streamers and the like, but a whole ecosystem of people to provide support for them as well. No an easy thing to do though, so we'll see if I can manage it. XD

Ölbaum

(It’s a joke: it should have been the XKCD comic, but this is also a picture that is often posted without comment in a reply.)

Go Up