Re: wotaskd and ssh
Pascal Robert <[email protected]>
| Newsgroups | gmane.comp.web.webobjects.wonder-disc |
|---|---|
| Message-ID | <[email protected]> |
Le 2013-02-22 à 23:58, Paul Hoadley <[email protected]> a écrit : > On 23/02/2013, at 1:19 PM, Ramsey Gurley <[email protected]> wrote: > >>>> I guess I should have been paying closer attention. I'm at a loss. How is enabled by default a security risk? >>> >>> Brute force attack for denial of service… But if someone close the wotaskd port (1085), logically they can close the port for the SSH server too… >> >> Yeah. This sounds like a configuration over convention argument. Show of hands. Anyone running wotaskd without a firewall between it and the internet? Anyone, anyone? Bueller? >> >> Who's going to have 6022 open? I thought there must be some other argument. > > I objected last time this came up (though I don't remember being the only one). I'm just against changing the _default_ behaviour of a long-standing, central piece of software like this. I guess it _is_ ideological, yes. Of course I have a firewall between wotaskd and the internet, it's just the principle—someone might have some bizarro configuration we haven't thought of, and this might bite them. If we follow that logic, that means we will never add new features into wotaskd. It's not changing the behaviour, except that it's opening a new TCP port. That built-in SSH server is the first step for easy deployment from Jenkins and from WOLips. Yeah, probably that people with existing "complex" deployment workflow won't use it. But I could settle that it's off by default, but any deployment packages (the RPMs for RedHat/CentOS, the .deb for Ubuntu and Debian) will enable it. > Of course, it's also coloured by the fact that this is a feature I don't intend to use, and I will happily be out-voted. ------------------------------------------------------------------------------ Everyone hates slow websites. So do we. Make your web apps faster with AppDynamics Download AppDynamics Lite for free today: http://p.sf.net/sfu/appdyn_d2d_feb