Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 29 Jul 1997 16:00:38 -0700 (PDT)
From:      Vincent Poy <vince@mail.MCESTATE.COM>
To:        sthaug@nethelp.no
Cc:        freebsd-security@FreeBSD.ORG, "[Mario1-]" <mario1@PrimeNet.Com>, JbHunt <johnnyu@accessus.net>
Subject:   Re: securelevel (was: Re: security hole in FreeBSD)
Message-ID:  <Pine.BSF.3.95.970729155539.3844q-100000@mail.MCESTATE.COM>
In-Reply-To: <5883.870215424@verdi.nethelp.no>

next in thread | previous in thread | raw e-mail | index | archive | help
On Wed, 30 Jul 1997 sthaug@nethelp.no wrote:

=)[cc list trimmed]
=)
=)> 	I was considering installing ssh but there is only one problem.  
=)> I use Win95 from my own side at times for various reasons as well as
=)> the other remote admins.  So a ssh client does cost money.   We're
=)> volunteers and are not getting paid in any shape or form.
=)
=)The ssh client for Windows is $99. Educational sites are eligible for a
=)50% discount. Or you could run the FreeBSD version - for free.

	We're not a Educational site and are not getting paid by GaiaNet.
We voluntarily help admin the machines remotely.  I know the FreeBSD
version is free but I am not always accessing the machines from the same
physical location.

=)It sounds like you're saying that the extra hassle you and your fellow
=)system administrators (and your users) are having because of the breakin
=)is worth less that $99. Are you sure you have your priorities straight?
=)
=)(For comparison - I run ssh for practically *all* remote logins, even
=)on the same LAN. ssh won't solve all your security problems, but it can
=)be an important *part* of better security.)

	And once again, note that we volunteer for GaiaNet, none of the
money GaiaNet makes goes to us as admins.  Even phone calls to track down
hackers come out of our own pockets.  Besides, the decision for the $99
spent is out of our own hands since we down own GaiaNet.  only the owners
have the power of say of what to buy and not buy.

=)With respect to passwords, your goal should be that no password is sent
=)in the clear. Ever. This is difficult to reach, but you'll find it helps
=)you to focus on security quite a bit.

	This has nothing to do with us but the way things were designed
originally.  


Cheers,
Vince - vince@MCESTATE.COM - vince@GAIANET.NET           ________   __ ____ 
Unix Networking Operations - FreeBSD-Real Unix for Free / / / / |  / |[__  ]
GaiaNet Corporation - M & C Estate                     / / / /  | /  | __] ]  
Beverly Hills, California USA 90210                   / / / / / |/ / | __] ]
HongKong Stars/Gravis UltraSound Mailing Lists Admin /_/_/_/_/|___/|_|[____]





Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.3.95.970729155539.3844q-100000>