git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: is gitosis secure?

From
Ddavid@lang.hm <david@lang.hm>
Date
Dec 15, 2008, 01:29 UTC
Message-ID
<alpine.DEB.1.10.0812141720510.17688@asgard.lang.hm>
In-Reply-To
<87prju5m6s.fsf@hades.wkstn.nix>
On Mon, 15 Dec 2008, Nix wrote:
Show 9 quoted lines
> On 14 Dec 2008, Jakub Narebski spake thusly:
>> BTW. is outgoing SSH transport (from network to outside) blocked as
>> well?
>
> *No* ports are open. All they have is a (non-transparent) buggy HTTP
> proxy. These guys really don't get the Internet, despite their sales
> literature banging on endlessly about it.
>
> Looks like a lot of git-bundling is in my future.

no ports being open and a non-transparent HTTP proxy doesn't tell me that they don't get the Internet. They could get the Internet just fine and be suitably paranoid about it. Controlling outbound traffic is actually a good thing in the current era of botnets (it prevents any of the machines in that company from participating in a botnet if they can't reach the command system)

the fact that the proxy is buggy could be an issue (I'm curious about what types of bugs you are running into, what you see as a bug may not be)

if there is a business reason for the developers on that network to be accessing resources on the Internet there should be a way to request that the appropriate ports get opened. if the answer from the security folks is 'no' you should ask them why not and what could be done to get the job done.

it may be that they don't want to provide access out from a bunch of desktops. If that is the case it may be appropriate to build a box to put into the DMZ that pulls from the upstream and then the inside desktops pull from this gateway system.

the saying goes "don't attribute to malice what can be explained by incompetence", but along the same lines in the security field, don't attribute to incompetence what can be explained by people doing their jobs that are ignorant of the requirements. they may also be operating under constraints that you don't know about.

David Lang
Previous: NixNext: Asheesh Laroia
Message 38 of 41 in “is gitosis secure?”
  1. Thomas KochDec 9, 2008
  2. Sam VilainDec 9, 2008
  3. Florian WeimerJan 18, 2009
  4. Boyd Stephen Smith Jr.Jan 18, 2009
  5. Florian WeimerJan 18, 2009
  6. Boyd Stephen Smith Jr.Jan 18, 2009
  7. Tommi VirtanenFeb 3, 2009
  8. Stephen R. van den BergFeb 4, 2009
  9. Tommi VirtanenFeb 4, 2009
  10. Stephen R. van den BergFeb 5, 2009
  11. Tommi VirtanenFeb 5, 2009
  12. R. Tyler BallanceDec 9, 2008
  13. Tommi VirtanenFeb 3, 2009
  14. Sverre RabbelierDec 9, 2008
  15. NixDec 13, 2008
  16. Sverre RabbelierDec 13, 2008
  17. Sitaram ChamartyDec 14, 2008
  18. david@lang.hmDec 14, 2008
  19. martinDec 14, 2008
  20. david@lang.hmDec 14, 2008
  21. Jakub NarebskiDec 14, 2008
  22. david@lang.hmDec 15, 2008
  23. martinDec 14, 2008
  24. david@lang.hmDec 15, 2008
  25. Mike HommeyDec 15, 2008
  26. david@lang.hmDec 15, 2008
  27. Mike HommeyDec 15, 2008
  28. TaitDec 15, 2008
  29. Sitaram ChamartyDec 14, 2008
  30. david@lang.hmDec 15, 2008
  31. Jakub NarebskiDec 14, 2008
  32. david@lang.hmDec 15, 2008
  33. Rogan DawesDec 15, 2008
  34. david@lang.hmDec 15, 2008
  35. Rogan DawesDec 15, 2008
  36. Jakub NarebskiDec 14, 2008
  37. NixDec 15, 2008
  38. david@lang.hmDec 15, 2008
  39. Asheesh LaroiaDec 15, 2008
  40. david@lang.hmDec 15, 2008
  41. Garry DolleyDec 9, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.