01grander
Posts: 2
Joined: Wed Sep 18, 2019 7:47 pm

Security - Best Practices

Wed Sep 18, 2019 7:56 pm

Hey,

My boss is wanting to use Raspberry Pi's for a lot of different projects around our department. We currently are doing very basic tasks, opening a website, displaying a message, and printing pdf's. We are wanting to use these at an intake area, those will perform different functions but I need to start looking into best security practices since it will be "public" facing. It's not going to be for the general public but it will be for people outside our department. It will be on its own vlan behind a basic firewall but I am looking for tips for best security practices.


Any tips?


Thanks

User avatar
davidcoton
Posts: 4909
Joined: Mon Sep 01, 2014 2:37 pm
Location: Cambridge, UK
Contact: Website

Re: Security - Best Practices

Wed Sep 18, 2019 8:25 pm

Signature retired

User avatar
graysky
Posts: 98
Joined: Fri Apr 05, 2013 11:43 am
Location: /run/user/1000
Contact: Website

Re: Security - Best Practices

Wed Sep 18, 2019 9:43 pm

01grander wrote:
Wed Sep 18, 2019 7:56 pm
We are wanting to use these at an intake area, those will perform different functions but I need to start looking into best security practices since it will be "public" facing.
All bets are off if there is physical access to the machine.

W. H. Heydt
Posts: 12431
Joined: Fri Mar 09, 2012 7:36 pm
Location: Vallejo, CA (US)

Re: Security - Best Practices

Wed Sep 18, 2019 10:19 pm

graysky wrote:
Wed Sep 18, 2019 9:43 pm
01grander wrote:
Wed Sep 18, 2019 7:56 pm
We are wanting to use these at an intake area, those will perform different functions but I need to start looking into best security practices since it will be "public" facing.
All bets are off if there is physical access to the machine.
Even that can be mitigated to a degree. Besides booting over a network (where that is possible), there are cases that have an SD card slot cover and you have to physically disassemble the case (which takes removing 4 screws) to remove that cover.

Much of it depends on just how far you want to go. At what point does the cost of physical security exceed the time and materials it costs to deal with a Pi going on walkabout.

Return to “General discussion”