atom feed200 messages in org.freebsd.freebsd-securityRe: securelevel (was: Re: security ho...
FromSent OnAttachments
103 earlier messages
Nate WilliamsJul 28, 1997 9:09 pm 
Vincent PoyJul 28, 1997 9:12 pm 
Vincent PoyJul 28, 1997 9:15 pm 
Vincent PoyJul 28, 1997 9:19 pm 
Heikki SuonsivuJul 28, 1997 9:33 pm 
Jan KoumJul 28, 1997 9:39 pm 
Vincent PoyJul 28, 1997 9:49 pm 
Jordan K. HubbardJul 28, 1997 10:05 pm 
Vincent PoyJul 28, 1997 10:14 pm 
Gary PalmerJul 28, 1997 10:27 pm 
Gary PalmerJul 28, 1997 10:28 pm 
Vincent PoyJul 28, 1997 10:35 pm 
Vincent PoyJul 28, 1997 10:37 pm 
John-David ChildsJul 28, 1997 10:38 pm 
Gary PalmerJul 28, 1997 10:40 pm 
Vincent PoyJul 28, 1997 10:44 pm 
Gary PalmerJul 28, 1997 10:50 pm 
Vincent PoyJul 28, 1997 10:55 pm 
Jordan K. HubbardJul 28, 1997 10:59 pm 
Vincent PoyJul 28, 1997 11:01 pm 
Jordan K. HubbardJul 28, 1997 11:07 pm 
Jordan K. HubbardJul 28, 1997 11:11 pm 
Jordan K. HubbardJul 28, 1997 11:16 pm 
Sergei S. LaskavyJul 29, 1997 12:13 am 
John-David ChildsJul 29, 1997 2:09 am 
NarviJul 29, 1997 2:48 am 
Stephen D. SpencerJul 29, 1997 3:43 am 
Robert WatsonJul 29, 1997 5:32 am 
Adam ShostackJul 29, 1997 5:49 am 
Robert WatsonJul 29, 1997 6:39 am 
Nate WilliamsJul 29, 1997 7:19 am 
Rodney W. GrimesJul 29, 1997 8:58 am 
Warner LoshJul 29, 1997 9:25 am 
Warner LoshJul 29, 1997 9:34 am 
Christopher PetrilliJul 29, 1997 9:52 am 
Jim ShanklandJul 29, 1997 9:57 am 
John DowdalJul 29, 1997 10:50 am 
Poul-Henning KampJul 29, 1997 12:05 pm 
Bill PechterJul 29, 1997 12:29 pm 
Matthew HuntJul 29, 1997 12:37 pm 
Christopher PetrilliJul 29, 1997 12:43 pm 
[Mario1-]Jul 29, 1997 1:07 pm 
Garrett WollmanJul 29, 1997 1:07 pm 
[Mario1-]Jul 29, 1997 1:14 pm 
sth...@nethelp.noJul 29, 1997 1:39 pm 
Jordan K. HubbardJul 29, 1997 2:23 pm 
Vincent PoyJul 29, 1997 2:45 pm 
Vincent PoyJul 29, 1997 2:57 pm 
Vincent PoyJul 29, 1997 3:02 pm 
sth...@nethelp.noJul 29, 1997 3:30 pm 
Rocco LuciaJul 29, 1997 3:33 pm 
Vincent PoyJul 29, 1997 3:44 pm 
Aaron BornsteinJul 29, 1997 3:44 pm 
Vincent PoyJul 29, 1997 3:54 pm 
Vincent PoyJul 29, 1997 4:00 pm 
Jay D. NelsonJul 29, 1997 5:29 pm 
Adam ShostackJul 29, 1997 6:06 pm 
Gary SchrockJul 29, 1997 6:10 pm 
Adam ShostackJul 29, 1997 6:11 pm 
Michael SmithJul 29, 1997 6:54 pm 
Jay D. NelsonJul 29, 1997 7:58 pm 
Jay D. NelsonJul 29, 1997 8:10 pm 
Michael SmithJul 29, 1997 8:25 pm 
Marco MolteniJul 30, 1997 5:04 am 
James SengJul 30, 1997 5:31 am 
Alex G. BulushevJul 30, 1997 5:59 am 
Vincent PoyJul 30, 1997 6:45 am 
Robert WatsonJul 30, 1997 7:03 am 
Nate WilliamsJul 30, 1997 7:48 am 
Vincent PoyJul 30, 1997 7:54 am 
Nate WilliamsJul 30, 1997 8:06 am 
Nate WilliamsJul 30, 1997 8:13 am 
Vincent PoyJul 30, 1997 8:28 am 
Vincent PoyJul 30, 1997 8:33 am 
zoonieJul 30, 1997 9:09 am 
Poul-Henning KampJul 30, 1997 9:25 am 
Poul-Henning KampJul 30, 1997 9:31 am 
John-David ChildsJul 30, 1997 10:17 am 
Ian KallenJul 30, 1997 10:37 am 
Patrick GilbertJul 30, 1997 11:43 am 
Jay D. NelsonJul 30, 1997 1:52 pm 
[Mario1-]Jul 30, 1997 2:06 pm 
Jordan K. HubbardJul 30, 1997 3:53 pm 
Jordan K. HubbardJul 30, 1997 4:04 pm 
yossmanJul 30, 1997 4:20 pm 
Jordan K. HubbardJul 30, 1997 4:24 pm 
Peter KorstenJul 30, 1997 4:43 pm 
Michael SmithJul 30, 1997 8:01 pm 
Cy SchubertJul 30, 1997 9:10 pm 
FreeBSD Technical ReaderJul 30, 1997 11:18 pm 
Marco MolteniJul 31, 1997 5:24 am 
yossmanJul 31, 1997 9:00 am 
Adam ShostackJul 31, 1997 9:19 am 
Marc SlemkoJul 31, 1997 11:23 am 
AndrewAug 1, 1997 10:00 pm 
Dmitry KohmanyukAug 1, 1997 10:32 pm 
Philippe RegnauldAug 2, 1997 1:46 pm 
Subject:Re: securelevel (was: Re: security hole in FreeBSD)
From:sth...@nethelp.no (sth@nethelp.no)
Date:Jul 29, 1997 3:30:03 pm
List:org.freebsd.freebsd-security

[cc list trimmed]

I was considering installing ssh but there is only one problem. I use Win95 from my own side at times for various reasons as well as the other remote admins. So a ssh client does cost money. We're volunteers and are not getting paid in any shape or form.

The ssh client for Windows is $99. Educational sites are eligible for a 50% discount. Or you could run the FreeBSD version - for free.

It sounds like you're saying that the extra hassle you and your fellow system administrators (and your users) are having because of the breakin is worth less that $99. Are you sure you have your priorities straight?

(For comparison - I run ssh for practically *all* remote logins, even on the same LAN. ssh won't solve all your security problems, but it can be an important *part* of better security.)

With respect to passwords, your goal should be that no password is sent in the clear. Ever. This is difficult to reach, but you'll find it helps you to focus on security quite a bit.