From owner-freebsd-questions@FreeBSD.ORG Mon May 3 16:48:20 2010 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [69.147.83.52]) by hub.freebsd.org (Postfix) with ESMTP id DD96F106566B for ; Mon, 3 May 2010 16:48:19 +0000 (UTC) (envelope-from amvandemore@gmail.com) Received: from mail-vw0-f54.google.com (mail-vw0-f54.google.com [209.85.212.54]) by mx1.freebsd.org (Postfix) with ESMTP id 8FA1A8FC19 for ; Mon, 3 May 2010 16:48:19 +0000 (UTC) Received: by vws7 with SMTP id 7so1597240vws.13 for ; Mon, 03 May 2010 09:48:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:mime-version:received:received:in-reply-to :references:date:message-id:subject:from:to:cc:content-type; bh=apnhG1D+HQO7Tv/y9VSfftPJlDvEkTfFcBo2odgqsGU=; b=kMKi1X6ChKstNY0t0kNI4MUwKsTuyy/Y6X5KIVNoLUjWnqHI1zykXf/zS1picmPW7R BvPDhSdI2phIpQ09SPEGmBcxyQF7Q7jHDcJRhqwv4FBjyIv9kh935WqxtCKlU5/o1/Vp ajyii5gHlS0BFUCBOh4KLmJxkoADbSDmjtTr0= DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; b=LE4YhRBmQvIzq4BkfWmXWrNnYtVamwEoJv6IcVWr/ogCyHmz/Kf6M0xIbz/0KWC+qF vCG6jZvoE0lWMUFy9EQJEz1fx24vP+T+wRuG9Ln3phpbIHeMWU1DzxRctrBtaTMzUGa4 0zcIqYsdewEmIGIyqRO79quMN0P4+86lbDmxE= MIME-Version: 1.0 Received: by 10.229.221.65 with SMTP id ib1mr1981766qcb.47.1272905293076; Mon, 03 May 2010 09:48:13 -0700 (PDT) Received: by 10.229.99.67 with HTTP; Mon, 3 May 2010 09:48:12 -0700 (PDT) In-Reply-To: <20100503163933.GA15599@elwood.starfire.mn.org> References: <20100503144110.GA14402@elwood.starfire.mn.org> <4BDEF9E4.9020806@infracaninophile.co.uk> <20100503163933.GA15599@elwood.starfire.mn.org> Date: Mon, 3 May 2010 11:48:12 -0500 Message-ID: From: Adam Vande More To: John Content-Type: text/plain; charset=ISO-8859-1 X-Content-Filtered-By: Mailman/MimeDel 2.1.5 Cc: freebsd-questions@freebsd.org Subject: Re: pf suggestions for paced attack X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 03 May 2010 16:48:20 -0000 On Mon, May 3, 2010 at 11:39 AM, John wrote: > Hi, Matthew. Indeed, yes, you may not recall, but my rules are > based on a set that I originally got from you, and I do, in fact, > have a white list, which I should have mentioned, but some of my > users are "road warriors" and could be coming from virtually anywhere. > You're right, though - it's time to look into alternatives to > password-based authenticaion. I think I've taken password-based > protection and rate adaptive rules to their logical limit. > > What's wrong with denyhosts? Key-based authentication has it's own set pitfalls. I'm far more likely to lose my usb stick than my password. I imagine there are other like me. -- Adam Vande More