git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: is gitosis secure?

From
Ddavid@lang.hm <david@lang.hm>
Date
Dec 15, 2008, 06:32 UTC
Message-ID
<alpine.DEB.1.10.0812142229010.17688@asgard.lang.hm>
In-Reply-To
<alpine.DEB.2.00.0812142121090.9552@vellum.laroia.net>
On Sun, 14 Dec 2008, Asheesh Laroia wrote:
Show 22 quoted lines
> On Mon, 15 Dec 2008, Nix wrote:
>
>> On 14 Dec 2008, Jakub Narebski spake thusly:
>>> BTW. is outgoing SSH transport (from network to outside) blocked as well?
>> 
>> *No* ports are open. All they have is a (non-transparent) buggy HTTP proxy. 
>> These guys really don't get the Internet, despite their sales literature 
>> banging on endlessly about it.
>
> If that's the only way you can access the network, you can take advantage of 
> the way HTTP proxies deal with HTTPS: they typically let it through byte for 
> byte.
>
> "connect.c is the simple relaying command to make network connection via 
> SOCKS and https proxy. It is mainly intended to be used as proxy command of 
> OpenSSH."
>
> Run sshd on port 443, use connect.c, and you're set.
>
> (Except for some really smart SSL-aware HTTP proxies that verify that it's an 
> SSL connection of some kind.  In theory, you could then sslwrap your sshd and 
> then be set.)

although, if the company is doing this as a deliberate security measure (as opposed to not knowing what they are doing), setting up a bypass like this can get you fired for deliberatly bypassing a security device.

also, examples of people going to this sort of effort to bypass security policies end up with employees being trusted less.

you are far better off going through channels and discussing what you are trying to do and why.

David Lang
Previous: Asheesh LaroiaNext: Garry Dolley
Message 40 of 41 in “is gitosis secure?”
  1. Thomas KochDec 9, 2008
  2. Sam VilainDec 9, 2008
  3. Florian WeimerJan 18, 2009
  4. Boyd Stephen Smith Jr.Jan 18, 2009
  5. Florian WeimerJan 18, 2009
  6. Boyd Stephen Smith Jr.Jan 18, 2009
  7. Tommi VirtanenFeb 3, 2009
  8. Stephen R. van den BergFeb 4, 2009
  9. Tommi VirtanenFeb 4, 2009
  10. Stephen R. van den BergFeb 5, 2009
  11. Tommi VirtanenFeb 5, 2009
  12. R. Tyler BallanceDec 9, 2008
  13. Tommi VirtanenFeb 3, 2009
  14. Sverre RabbelierDec 9, 2008
  15. NixDec 13, 2008
  16. Sverre RabbelierDec 13, 2008
  17. Sitaram ChamartyDec 14, 2008
  18. david@lang.hmDec 14, 2008
  19. martinDec 14, 2008
  20. david@lang.hmDec 14, 2008
  21. Jakub NarebskiDec 14, 2008
  22. david@lang.hmDec 15, 2008
  23. martinDec 14, 2008
  24. david@lang.hmDec 15, 2008
  25. Mike HommeyDec 15, 2008
  26. david@lang.hmDec 15, 2008
  27. Mike HommeyDec 15, 2008
  28. TaitDec 15, 2008
  29. Sitaram ChamartyDec 14, 2008
  30. david@lang.hmDec 15, 2008
  31. Jakub NarebskiDec 14, 2008
  32. david@lang.hmDec 15, 2008
  33. Rogan DawesDec 15, 2008
  34. david@lang.hmDec 15, 2008
  35. Rogan DawesDec 15, 2008
  36. Jakub NarebskiDec 14, 2008
  37. NixDec 15, 2008
  38. david@lang.hmDec 15, 2008
  39. Asheesh LaroiaDec 15, 2008
  40. david@lang.hmDec 15, 2008
  41. Garry DolleyDec 9, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.