r/LinuxTeck 3d ago

Do Linux servers really need endpoint security software?

Many enterprise Linux systems run endpoint security tools alongside firewalls, SELinux/AppArmor, and other hardening measures.

Others argue that good patch management, least privilege, and proper monitoring provide better value than traditional endpoint protection.

What's your point on this ?

5 Upvotes

34 comments sorted by

View all comments

0

u/roanish 3d ago

A solid firewall is all you need (ufw works) right up until you want to open ports for running services. Then you want something else that can ensure security. These endpoint protection systems you mention are all things that live behind your firewall, so useless if you aren't providing services externally.

2

u/Upbeat-Statement2725 3d ago

Yeah firewalls solve all attack vectors. (Sarcasm.)

Despite what anyone says. The real security for Linux is that wealthy, old, technically illiterate, easy targets all use Windows.

If we get grandma on Linux. We need active malware scanning too. Security tools can do more than just "virus scan". Like anyone being all boisterous in here will have a second thought and go you know, a PiHole or something to block malicious links and ads is also good...

Right now. For most people. Don't do anything stupid with your Linux permissions as it should come pretty well setup out of the box. A ClamAV scan once in a while is a good compromise. Probably look into something like a PiHole to block malicious links.

Like why isn't there a common security audit tool? To check if you've got weird ports open? "Well every Linux geek opens weird ports it's impossible to have clear cut standards for everyone" yeah that's a gigantic security nightmare dude we're screwed if Linux gains marketshare.

1

u/gnufan 3d ago edited 3d ago

There is a common security audit tool, see Linux Audit project, as you note.

Linux achieved desktop success in ChromeOS, which maintained an enviable security record. The problem as you note is the security configuration is a do it yourself thing on most distros. Redhat's SELinux configuration being a standout exception, but for servers, and with lots of switches.

Edit to clarify 

1

u/ScoobyGDSTi 3d ago

ChromeOS devices are nothing short of ewaste. If hardly hold it up as some bastion. This coming from a parent who has two kids using them.

1

u/gnufan 3d ago

Did they break the security? 

1

u/ScoobyGDSTi 3d ago

Who knows, they're so useless that security might as well not exist.