I deem ssh called from inetd to be secure enough for most purposes as an
alternative to telnet. An attacker could close off the port by flooding it
with requests, so maybe running port-sentry at the same time would be
feasible (nb: this has further consequences). Depends on the nature of the
system. On my home machine there are a few ports publically open (ssh,
ftp, web) because that is what I want running there. Realistically I could
tighten up a lot, but I don't deem it to be necessary. If you're building
a server for www.linux.org or something else high profile then you would
want to be much more fascist. There are plenty of people around who are of
the opinion that "it's secure enough" is a bullshit security policy, so
it's really up to you as to how restrictive you want to be wrt remote
access to your machines.
At 06:59 PM 4/30/00 +1000, erich wrote:
>I have read a lot of people talking about not using telnet over the
>internet, the question is:
> How do make "secure" (read, secure as practical) remote connections
>over the internet ?
Alexander Else
http://cyberchrist.org
--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text