git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: is gitosis secure?

From
Ddavid@lang.hm <david@lang.hm>
Date
Dec 15, 2008, 01:00 UTC
Message-ID
<alpine.DEB.1.10.0812141655150.17688@asgard.lang.hm>
In-Reply-To
<4944E7E1.2030907@siamect.com>
On Sun, 14 Dec 2008, martin wrote:
Show 46 quoted lines
> david@lang.hm wrote:
>> On Sun, 14 Dec 2008, martin wrote:
>> 
>>> Dear David.
>>> Why do you trust VPN more than the SSH?
>>> I ask because I have just removed the "first VPN then SSH" solution in 
>>> favor for a SSH only solution using Gitosis just to get rid of the VPN 
>>> which I believe is less secure than SSH (well until I read you comments 
>>> below).
>>> I thought I was doing something right for once but maybe I'm not?
>>> Thanks and best regards
>>> Martin
>> 
>> in part it's that a VPN is a single point of control for all remote access.
>> 
>> If you use ssh you end up exposing all the individual machines
>> 
>> 1. data leakage of just what machines exist to possibly hostile users.
>> 
>> 2. the many machines are configured seperatly, frequently by different 
>> people. this makes it far more likely that sometime some machine will get 
>> misconfigured.
>> 
>> 3. people who are focused on providing features have a strong temptation to 
>> cut corners and just test that the feature works and not test that 
>> everything that isn't supposed to work actually doesn't work. as a result, 
>> in many companies there is a deliberate seperation (and tension) between a 
>> group focused on controlling and auditing access and one that is focused on 
>> creating fucntionality and features.
>> 
>> also from a polical/social point of view everyone recognises that if you 
>> grant someone VPN access you are trusting them, but people don't seem to 
>> think the same way with ssh.
>> 
>> David Lang
>> 
>
> I opened port 22 in the firewall to just those hosts that I need to reach, 
> which is one in this case...the rest of the machines I cannot reach.
> I did a brief port scan and the thing is silent... so I don't think I reveal 
> any of the other hosts... but I should not say is it's secure with your 
> measures...
>
> Your point two I don't understand...   If you are in charge of the firewall 
> you also know what machines you let people reach. If these machines are 
> numerous then I think there is a management problem somewhere else...
two things here
1. if you are running multiple different applications that all want to be 
exposed via port 22 (like git for 'git push') then you may need to expose 
numerous machines. tools that use SSH don't tend to have the ability to 
use a gateway box before they start executing commands, they assume that 
you will SSH directly into the destination box.
2. many people take the attitude that SSH is secure, period, end of 
statement. so they think that every machine should be able to be contacted 
via SSH, and you can then use SSH to do any other functionality on any 
machine that you can dream up. a small minority of people try to minimize 
what boxes are exposed directly (you are one of them), but most don't
David Lang
Previous: martinNext: Mike Hommey
Message 24 of 41 in “is gitosis secure?”
  1. Thomas KochDec 9, 2008
  2. Sam VilainDec 9, 2008
  3. Florian WeimerJan 18, 2009
  4. Boyd Stephen Smith Jr.Jan 18, 2009
  5. Florian WeimerJan 18, 2009
  6. Boyd Stephen Smith Jr.Jan 18, 2009
  7. Tommi VirtanenFeb 3, 2009
  8. Stephen R. van den BergFeb 4, 2009
  9. Tommi VirtanenFeb 4, 2009
  10. Stephen R. van den BergFeb 5, 2009
  11. Tommi VirtanenFeb 5, 2009
  12. R. Tyler BallanceDec 9, 2008
  13. Tommi VirtanenFeb 3, 2009
  14. Sverre RabbelierDec 9, 2008
  15. NixDec 13, 2008
  16. Sverre RabbelierDec 13, 2008
  17. Sitaram ChamartyDec 14, 2008
  18. david@lang.hmDec 14, 2008
  19. martinDec 14, 2008
  20. david@lang.hmDec 14, 2008
  21. Jakub NarebskiDec 14, 2008
  22. david@lang.hmDec 15, 2008
  23. martinDec 14, 2008
  24. david@lang.hmDec 15, 2008
  25. Mike HommeyDec 15, 2008
  26. david@lang.hmDec 15, 2008
  27. Mike HommeyDec 15, 2008
  28. TaitDec 15, 2008
  29. Sitaram ChamartyDec 14, 2008
  30. david@lang.hmDec 15, 2008
  31. Jakub NarebskiDec 14, 2008
  32. david@lang.hmDec 15, 2008
  33. Rogan DawesDec 15, 2008
  34. david@lang.hmDec 15, 2008
  35. Rogan DawesDec 15, 2008
  36. Jakub NarebskiDec 14, 2008
  37. NixDec 15, 2008
  38. david@lang.hmDec 15, 2008
  39. Asheesh LaroiaDec 15, 2008
  40. david@lang.hmDec 15, 2008
  41. Garry DolleyDec 9, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.