2026-09-18 14:41 UTC
@Sempf@infosec.exchange Last I saw, SFTP was the recommendation. If there's a business reason why that can't be done (which I've seen once or twice), require file-level encryption.
Replies (1)
-
@XenoPhage@infosec.exchange 2026-09-18 14:49
@nerdpr0f@infosec.exchange @Sempf@infosec.exchange My favorite part is getting dinged every time a security scan is run. “You have an open SSH server!" Yeah, no shit. It's an SFTP server. And we’ve justified this to you a billion times. Stop dinging us on it!!