Mailing List Archive
tlug.jp Mailing List tlug archive tlug Mailing List Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]Re: [tlug] For all you vi heathen ;-)
- Date: Sat, 18 Jul 2020 00:39:48 +0900
- From: Benjamin Kowarsch <trijezdci@example.com>
- Subject: Re: [tlug] For all you vi heathen ;-)
- References: <20200716231225.GD62955@nuskie.local> <CADR0rneFcGb+RFSsPTpr78iK+R-b70mGzMY8ZhKMHc78zov_Hw@mail.gmail.com> <20200717145503.jm5h5bdbed2luxmu@iambic.cynic.net>
On Fri, 17 Jul 2020 at 23:59, Curt J. Sampson <cjs@example.com> wrote:
> I would not allow any extranet remote users at all unless I am running
> OpenVMS or OpenBSD.
That is a very foolish approach to security.While I cannot be sure about OpenBSD, ...Running VMS is about the smartest approach to security on this planet.The vim issue is no surprise; probably the most important part of the "fix"
was the addition of these two lines to the documentation:
Note that the user may still find a loophole to execute a
shell command, it has only been made difficult.
"'Restricted' version of a very general, complex tool" is almost invariably
a security fail; we've known this for decades. (Remember when `rsh` meant
"restricted shell"?)Well, on VMS a "restricted shell" is called a captive accountand it actually performs to specification, not best effort.The deathrow VMS cluster was running for many years with captive accountsbeing handed out to anybody who would email in and ask for one. Nobody hasever managed to break out. Some naive script kiddies tried once in a while,immediately triggering alarms that logged them out and disabled theiraccounts. The system administrators always posted such attempts on thedeathrow website for the amusement of the user community.VMS is truly Orwellian. What you are not authorised to do, you cannot do,and that is done at the kernel level, not in a shell command interpreter.And everything you are authorised to do can be monitored and alarmscan be put on it. Users can be automatically logged off and theiraccounts disabled if they do things that look like probing the system.Sometimes, the deathrow system admins had a bit of fun watchingscript kiddies in action, letting them play to see what they would be doing.The transcripts of this foolishness were then postedon the website and gave us all many good laughs.Serious crackers, like state actors or state sponsored hacking outletswouldn't even waste their time probing. They know it'd be futile.There is a difference between system design with security designed infrom the start, and system "design" with "security" bolted on afterwards.There's a reasonable argument to be made that things of this nature, should
not be made available. Not only are they an almost certain source of
security holes if used naīvely, but almost any use, even by someone who
(normally) knows what he's doing, is naīve. But they do have their (very)
occasional uses.Well, since I sold my last VAX and Alpha workstations about 20 years agoand the x86 port of VMS is not quite available yet, I appreciated the free captiveaccount I got on the deathrow cluster for porting some of my open source stuffover to VMS.Providing such a service on just about any other system would be indeed asecurity nightmare, but not with VMS. Unfortunately, the guys shut it downa few years ago due to the aging hardware (several VAX cluster nodes)making it difficult to get spare parts, high electricity consumption and use ofspace.Fortunately, VSI who acquired the rights from HP have been working hardon the x86 port and they shipped the first OS on a trial basis to a customera month ago, release for general public is scheduled for the end of the year.
- Follow-Ups:
- Re: [tlug] For all you vi heathen ;-)
- From: Curt J. Sampson
- References:
- Re: [tlug] For all you vi heathen ;-)
- From: Chris
- Re: [tlug] For all you vi heathen ;-)
- From: Benjamin Kowarsch
- Re: [tlug] For all you vi heathen ;-)
- From: Curt J. Sampson
Home | Main Index | Thread Index
- Prev by Date: Re: [tlug] For all you vi heathen ;-)
- Next by Date: Re: [tlug] Introduction to (Tech) Worker Cooperatives, 09:00AM on Sunday, July 12th JST
- Previous by thread: Re: [tlug] For all you vi heathen ;-)
- Next by thread: Re: [tlug] For all you vi heathen ;-)
- Index(es):