Comment by eeZah7Ux
5 years ago
No, it's not. You can deploy a very minimal Linux while also keeping the services that are actually good for security, like logging, IDS/IPS, certification compliance tooling, monitoring.
Unless you are running unnecessary daemons exposed on the Internet, 99% of the attack surface is from your application and the kernel itself.
Both parts that you can't remove.
No comments yet
Contribute on Hacker News ↗