<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Linux on tigger.dev</title><link>https://tigger.dev/tags/linux/</link><description>Recent content in Linux on tigger.dev</description><generator>Hugo</generator><language>en-gb-oed</language><copyright>© Tadhg O'Brien</copyright><lastBuildDate>Thu, 29 Jan 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://tigger.dev/tags/linux/index.xml" rel="self" type="application/rss+xml"/><item><title>Setup &amp; Harden a Linux Server in 2026</title><link>https://tigger.dev/harden-linux-server/</link><pubDate>Thu, 29 Jan 2026 00:00:00 +0000</pubDate><guid>https://tigger.dev/harden-linux-server/</guid><description>&lt;p&gt;If you spin up a fresh Linux box today, it&amp;#39;s not &amp;#34;new&amp;#34; for long. The moment it&amp;#39;s reachable, it&amp;#39;s being scanned, prodded, and occasionally hammered by automated traffic. That&amp;#39;s not paranoia, it&amp;#39;s just the background noise of the modern internet. Honeypot data has been consistent for years: a brand-new instance with a public IP will typically see its first SSH probe within minutes, and credential-stuffing attempts shortly after.&lt;/p&gt;
&lt;p&gt;
Cloud providers have made it trivially easy to create compute instances. What they haven&amp;#39;t done is make them safe by default. You still get a general-purpose system with a wide attack surface, and it&amp;#39;s on you to reduce that surface before you put anything meaningful on it.&lt;/p&gt;</description></item></channel></rss>