[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: CVS
At 06:53 PM 10/30/1999 -0700, you wrote:
>
>On Sat, 30 Oct 1999, Daniel E. Markle wrote:
>
>> On Sat, Oct 30, 1999 at 09:26:33AM -0400, Jason Pincin wrote:
>> > Huh? Why does cvs need to be ssh? This is going to be open source
>> > code... why the great security lengths?
>>
>
>Hmmm... let's see:
>
>"Joe Killjoy" decides to have some fun and downloads our CVS tree and
>makes some "minor" changes to things. He can even figure out our
>usernames by our posts on the linuxkb-discuss list which his archived on
>SEUL and pose as us, which would make it very difficult to figure out what
>are legit mods and what aren't.
>I don't have any problem with posting our code on a web site or letting
>the world have access to the webcgi interface or anon r/o CVS access.
>But the momement you let anyone have write access to the code you've got a
>major risk. I'd like to see it over ssh, just because I know some of us
>come from high-sniffed environments (college networks and such).
You are absolutely correct--all 3 of our linux boxes have been sniffed in
the last month. Luckily, we have people that are very aware of most of the
security holes.
>
>If we don't want to bother with shell access to run webupdate, it would be
>pretty simple to write a CGI program that does it.
Another good point--we limit the number of accounts on any of the three
boxes we run--our primary box has 31 (including root--some of which will be
removed in the near future), our development box has 6 users, and our exec
box has 4. All three boxes are accessible via ssh--and telnet will be
turned off in the near future on our primary server.
>> I've been wondering this all along, like why password protect devel?
>
>The theory was that we may have information in IRC logs or email that we
>may not want as public knowledge.
We generally password protect any development site we work on, including
development docs, so that the information does not leak to the public.
It's terrible when you haven't finished converting pages over and someone
sees your work.
>> Why password protect dev?
>
>Because we're doing a closed alpha development? Perhaps tst will be an
>open beta... This is really only a matter of preference on our part. If
>people want an unprotected site, then we should just announce to the world
>an open test.
>
>> If this is your thought on it, we should get rid of
>> these annoying and unproductive checks on these parts of the site.
>
>I guess it's pretty relative. For me, passwords are a way of life. I've
>got so many that I have to store them on my Palm Pilot to keep track. :-)
>