Please read part 1 first.
Securing the beast
Now I’m getting close to wanting to move the box to a server room. That means that it’ll be directly connected to the internet, with no router and no nating. It will be attacked. A lot. If there’s any obvious hole in it’s defences, it will get owned.
I’m not a security expert, but I do know that there’s no such thing as absolut security. You just secure the box as well as possible, with the resources you are willing to use. It’s a compromise between usability, resources and security.
I see security as a triangle between, keeping the machine up to date, making sure that the installed programs are setup as secure as possible and keeping an eye on the box for strange behaviour (did somebody get through).
When you look at the security page at debian.org, all it tells you is to keep the packages up to date. I’ll start by looking at that.