cross-posted from: https://reddthat.com/post/39309359
I’ve been running Home Assistant for three years. It’s port forwarded on default port 8123 via a reverse proxy in a dedicated VM serving it over HTTPS and is accessible over ipv4 and ipv6. All user accounts have MFA enabled.
I see a notification every time there’s a failed login attempt, but every single one is either me or someone in my house. I’ve never seen a notification for any other attempts from the internet. Not a single one.
Is this normal? Or am I missing something? I expected it to be hammered with random failed logins.
What is it about Wordpress? I’ve never used it, but it seems that every other day there is a new Wordpress exploit, and that’s been going on for years.
I think of it like Bethesda games.
It’s passable for what you want, but the real value is the plugins that can fix what problems you have.
But all those plugins also have security vulnerabilities that need to be managed.
Just don’t look behind the curtain to see what the CEO is up to.
Incredible yet accurate analogy
Had to go look it up. What a cluster. Anyways, I don’t blog mainly because I don’t have anything to say that people would be interested in. Maybe farming. LOL I’ve just wondered down through the years why someone didn’t fix all the attack surfaces Wordpress seems to have. Plus it drives a substantial share of websites, so I guess it’s a good target to go after.
It’s a huuuugely popular CMS used on around 40% of all websites on the internet, and it has around 70,000 plugins available of varying quality. Most exploits are from badly written plugins.