Berkeley CSUA MOTD:Entry 16040
Berkeley CSUA MOTD
 
WIKI | FAQ | Tech FAQ
http://csua.com/feed/
2025/05/24 [General] UID:1000 Activity:popular
5/24    

1999/6/30-7/1 [Computer/SW/Security] UID:16040 Activity:moderate
6/30    I asked another host machine to install a ssh client so that I could
        telnet there and then ssh to soda.  Thing is, I can't connect
        because soda doesn't support ssh protocol v2.  Does anyone know
        about plans to change this?
        \_ there's a slightly easier way to do this and it doesn't involve
           asking someone else to install something for you.
        \_ when data fellows makes their ssh2 implementation less stupid
           about their license.
        \_ ssh2 is still in testing and not free for use.  Have them install
           ssh1 as well.
        \_ Ride BIKE!
        \_ Compile your own.
        \_ Interestingly (to me anyway), this only puts the security breach
           one step back.  Instead of a cracker sniffing your soda account,
           \_ the point is that soda's subnet is filled with lemurs.
           they can sniff your other telnet account, and then ssh from there
           to soda and wreak all sorts of terrible havok!
           \_ Telneting somewhere just to be able ssh to soda is a really
              stupid idea.  It not only defeats the security that the soda
              admins are trying to establish, but also compromises the other
              account as well.  Get off your ass and install ssh on your owm
              machine or explore the possibility of using s/key.
              \_ The soda admins are trying to protect against sniffers on this
                subnet.  Telnet->ssh is no dumber than purely telnet,
                and given the number of lemurs probably a bunch safer.
2025/05/24 [General] UID:1000 Activity:popular
5/24    

You may also be interested in these entries...
2012/8/26-11/7 [Computer/SW/Security] UID:54465 Activity:nil
8/26    Poll: how many of you pub/priv key users: 1) use private keys that
        are not password protected 2) password protect your private keys
        but don't use ssh-agent 3) use ssh-agent:
        1) .
        2) ..
        3) ...
	...
2012/8/7-10/17 [Computer/SW/Security] UID:54455 Activity:nil
8/6     Amazon and Apple have lame security policies:
        http://www.wired.com/gadgetlab/2012/08/apple-amazon-mat-honan-hacking/all
        "First you call Amazon and tell them you are the account holder, and
         want to add a credit card number to the account. All you need is the
         name on the account, an associated e-mail address, and the billing
         address. "
	...
2012/7/18-8/19 [Health/Men, Computer/SW/Security] UID:54438 Activity:nil
7/18    "Largest penis record holder arouses security suspicions at airport"
        http://www.csua.org/u/x2f (in.news.yahoo.com)
        \_ I often have that same problem.
        \_ I think the headline writer had some fun with that one.
           \_ One time when I glanced over a Yahoo News headline "U.S. busts
              largest-ever identity theft ring" all I saw was "U.S. busts
	...
2012/4/23-6/1 [Computer/SW/WWW/Browsers] UID:54360 Activity:nil
4/19    My Firefox 3.6.28 pops up a Software Update box that reads "Your
        version of Firefox will soon be vulnerable to online attacks."  Are
        they planning to turn off some security feature in my version of
        Firefox?
        \_ Not as such, no, but they're no longer developing this version,
           so if a 3.6.x-targeted hack shows up, you're not going to get
	...
2011/11/8-30 [Computer/SW/Security, Computer/SW/OS/Windows] UID:54218 Activity:nil
11/8    ObM$Sucks
        http://technet.microsoft.com/en-us/security/bulletin/ms11-083
        \_ How is this different from the hundreds of other M$ security
           vulnerabilities that people have been finding?
           \_ "The vulnerability could allow remote code execution if an
               attacker sends a continuous flow of specially crafted UDP
	...
2011/11/11-30 [Computer/SW/Security] UID:54224 Activity:nil
11/11   MacOSX's Sandbox security hole:
        http://preview.tinyurl.com/7ph2wtg [arstechnica]
	...
2011/2/10-19 [Computer/SW/Security] UID:54034 Activity:nil
2/9     http://www.net-security.org/secworld.php?id=10570
        Summary: iPhone passwd storage is unsafe after all
	...