Skip to content

Comment on Lynis – Security auditing and hardening tool, for Unix-based systemsparent

Comments

It's closer to checkbox compliance, rather than being effective. Sure, those checks may be interesting and point out some actual issues. But if you're given a choice, then a short threat modelling session will have much higher impact. Someone else brought up CIS here - it's the same category with counterproductive changes like installing an integrity checker and tcpwrapper inside docker images.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.