Mailing List ArchiveSupport open source code!
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]Re: tlug: telnet: different question + others
- To: tlug@example.com
- Subject: Re: tlug: telnet: different question + others
- From: "Stephen J. Turnbull" <turnbull@example.com>
- Date: Mon, 29 May 2000 22:05:07 +0900 (JST)
- Content-Transfer-Encoding: 7bit
- Content-Type: text/plain; charset=us-ascii
- In-Reply-To: <20000529211108.B6592@example.com>
- References: <20000529101400.B7207@example.com><Pine.LNX.4.10.10005290525160.31060-100000@example.com><20000529132313.B277@example.com><14642.4422.675111.887914@example.com><20000529171430.A8484@example.com><14642.19581.689154.716136@example.com><20000529211108.B6592@example.com>
- Reply-To: tlug@example.com
- Sender: owner-tlug
>>>>> "Thomas" == Thomas O'Dowd <tom@example.com> writes: Thomas> All in the spirit of education... I think the post got so Thomas> many responses because it was an interesting technical Thomas> question about how to do something on a linix box. There Thomas> was nothing malicious in any of the responses apart from No, not malicious. Just unthinking. If you don't understand and describe the security implications, then you may very well be doing someone, possibly even the perpetrator, a severe disservice. And not mentioning the ethical implications at all is unethical, to my mind. Thomas> the side effect that if they were successful it might lead Thomas> to the attendance records going out of sync with reality. False. Some of the suggestions involved clear security breaches (.rhosts, ssh access without passphrase on a semi-public terminal) that could possibly be more broadly exploited. (At the very least, an intruder with the intent to break the real security on the University net could almost surely exploit that script to mask their identity. Remember, on a public access box everyone is root, there's no good way to be sure that any file on it is secure.) Certain more or less obvious extensions (eg, an ssh tunnel opened from the computer room to the student's dorm room, which I am willing to bet is not prevented by the current security arrangements, being familiar with my own University's policies) could easily be used to completely bypass the security. Until this evening I thought it would go without saying that that's obviously unethical and quite probably illegal. But I guess I'd better be careful and point it out. "Don't try this at home!" Thomas> But that is for the student to decide. Back in our day, Thomas> the lecturer handed out an attendance book now and again Thomas> and if you were lucky someone would sign your name for you Thomas> if you were otherwise engaged that particular day... Of Thomas> course your friend runs the risk of a followup headcount, Thomas> but the odds were pretty good. And just how does that open further security holes? But the computer variant probably does! The point is that computers, especially on networks, are only partly analogous to what happened "back in our day". -- University of Tsukuba Tennodai 1-1-1 Tsukuba 305-8573 JAPAN Institute of Policy and Planning Sciences Tel/fax: +81 (298) 53-5091 _________________ _________________ _________________ _________________ What are those straight lines for? "XEmacs rules." -------------------------------------------------------------------- Next Nomikai Meeting: June 16 (Fri), 19:00 Tengu TokyoEkiMae Next Technical Meeting: July 8 (Sat) 13:30 Topic: TBA -------------------------------------------------------------------- more info: http://www.tlug.gr.jp Sponsor: Global Online Japan
- Follow-Ups:
- Re: tlug: telnet: different question + others
- From: "Thomas O'Dowd" <tom@example.com>
- References:
- Re: tlug: telnet: different question + others
- From: Frank Bennett <bennett@example.com>
- Re: tlug: telnet: different question + others
- From: Philip Mak <pmak@example.com>
- Re: tlug: telnet: different question + others
- From: Chris Sekiya <sekiya@example.com>
- Re: tlug: telnet: different question + others
- From: "Stephen J. Turnbull" <turnbull@example.com>
- Re: tlug: telnet: different question + others
- From: Frank Bennett <bennett@example.com>
- Re: tlug: telnet: different question + others
- From: "Stephen J. Turnbull" <turnbull@example.com>
- Re: tlug: telnet: different question + others
- From: "Thomas O'Dowd" <tom@example.com>
Home | Main Index | Thread Index
- Prev by Date: Re: tlug: Problems with glib-1.2.new
- Next by Date: tlug: Re: telnet: different question + others
- Prev by thread: Re: tlug: telnet: different question + others
- Next by thread: Re: tlug: telnet: different question + others
- Index(es):
Home Page Mailing List Linux and Japan TLUG Members Links