From owner-freebsd-security Sun Oct 1 1:25:24 2000 Delivered-To: freebsd-security@freebsd.org Received: from eastwood.aldigital.algroup.co.uk (eastwood.aldigital.algroup.co.uk [194.128.162.193]) by hub.freebsd.org (Postfix) with ESMTP id 4756C37B502 for ; Sun, 1 Oct 2000 01:25:21 -0700 (PDT) Received: from algroup.co.uk (socks-fw.aldigital.co.uk [192.168.254.10]) by eastwood.aldigital.algroup.co.uk (8.8.8/8.6.12) with ESMTP id IAA02741; Sun, 1 Oct 2000 08:25:13 GMT Message-ID: <39D6F48B.EC92A921@algroup.co.uk> Date: Sun, 01 Oct 2000 09:23:39 +0100 From: Adam Laurie Organization: A.L. Group plc X-Mailer: Mozilla 4.74 [en] (X11; U; FreeBSD 3.4-STABLE i386) X-Accept-Language: en MIME-Version: 1.0 To: Michael Bryan Cc: security@FreeBSD.ORG Subject: Re: cvs commit: ports/mail/pine4 Makefile (fwd) References: <200009301404.e8UE4xU64460@cwsys.cwsent.com> <20000930152917.E25121@149.211.6.64.reflexcom.com> <39D6707D.CEAB26E2@ursine.com> Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.org Michael Bryan wrote: > > "Crist J . Clark" wrote: > > > > On Sat, Sep 30, 2000 at 11:43:20PM +0200, Roman Shterenzon wrote: > > > Still, I think the default should be "insecure" install, since most > > > machines are firewalled. > > > > [...] > > > > I guess I am one of the few that thinks we should default off for the > > good of the newbie user, rather than save the newbie 5 minutes of RTFM > > to turn on telnet and ftp. Just everyone hope no exploit like the > > recent SGI telnetd bug is ever found hiding in FreeBSD's telnetd. > > I agree, mainly for the reasons you state --- the newbies that are most > likely to install with defaults and no tweaking are often those who are > running in environments where they need the most protection. The default > install should be all services off, with an easy means to enable them > explicitly during and after an install. You can add my vote to that. cheers, Adam -- Adam Laurie Tel: +44 (20) 8742 0755 A.L. Digital Ltd. Fax: +44 (20) 8742 5995 Voysey House Barley Mow Passage http://www.aldigital.co.uk London W4 4GB mailto:adam@algroup.co.uk UNITED KINGDOM PGP key on keyservers To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message