logoalt Hacker News

geerlingguy • today at 12:35 PM • 0 replies • view on HN

I assume any computer connected to my LAN is also a dedicated attack vector for everything on my LAN in case of compromise.

Exposing any port directly to the Internet is a huge risk these days—at minimum I'd put a very strong firewall in front, and unless it's serving the general public, switch to a non standard port. It's not much but would prevent the dumb automated scripts that operate on standard ports.