Re: is gitosis secure?
- From
Jakub Narebski <jnareb@gmail.com>
- Date
- Dec 14, 2008, 10:40 UTC
- Message-ID
- <m34p17f3bh.fsf@localhost.localdomain>
- In-Reply-To
- <alpine.DEB.1.10.0812132126470.17688@asgard.lang.hm>
david@lang.hm writes:
Show 10 quoted lines
> this is really a reply to an earlier message that I deleted. > > the question was asked 'what would the security people like instead of > SSH' > > as a security person who doesn't like how ssh is used for everything, > let me list a couple of concerns. > > ssh is default allow (it lets you run any commands), you can lock it > down with effort.
How is VPN better than that?
Show 5 quoted lines
> ssh defaults to establishing a tunnel between machines that other > network traffic can use to bypass your system. yes I know that with > enough effort and control of both systems you can tunnel over > anything, the point is that ssh is eager to do this for you (overly > eager IMHO)
How is VPN better than that?
> ssh depends primarily on certificates that reside on untrusted > machines. it can be made to work with tokens or such, but it takes a > fair bit of effort.
There probably VPN differs...
> sshd runs as root on just about every system
And VPN doesn't?
[...]
The idea with using SSH was, I think, that it is easier and better to use existing solution for authentication and authorization than roll your own (see the case of CVS pserver, and Subversion svnserve).
-- Jakub Narebski Poland ShadeHawk on #git