BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] vnc
- Subject: [Discuss] vnc
- From: markw at mohawksoft.com (markw at mohawksoft.com)
- Date: Mon, 25 Aug 2014 11:12:10 -0400
- In-reply-to: <53FB453F.8040201@gmail.com>
- References: <53F9F6B9.4060505@stephenadler.com> <20140824161132.GE14848@randomstring.org> <be314521ab6bebb6add54d706b042f01.squirrel@mail.mohawksoft.com> <53FA1C3B.70908@gmail.com> <cb98ac9a77c99dd9313c5b1503d30ee1.squirrel@mail.mohawksoft.com> <53FB453F.8040201@gmail.com>
The problem is security. If you allow SSH access to the open internet, you're more open to attack. With openvpn you can enable two-factor authentication and a lot more security. Then, sure, let a really trusted user open an SSH shell. It is inarguable that SSH and a VPN is far more secure than merely SSH or other access methods. > On 8/25/2014 8:51 AM, markw at mohawksoft.com wrote: >> SSH is a very BAD thing to open up to the free internet. BAD BAD BAD. >> Once in, you are in. Shell access is dangerous. > > Stop right there. > > We have been discussing securing VNC connections to X11 desktops running > on virtual framebuffer devices. In other words: full shell access. Thus, > none of your points are immediately relevant to the discussion at hand. > They might be relevant to a discussion about access to private services > other than shell access but that's a different discussion. > > -- > Rich P. > _______________________________________________ > Discuss mailing list > Discuss at blu.org > http://lists.blu.org/mailman/listinfo/discuss >
- Follow-Ups:
- [Discuss] vnc
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] vnc
- References:
- [Discuss] vnc
- From: adler at stephenadler.com (Stephen Adler)
- [Discuss] vnc
- From: dsr at randomstring.org (Dan Ritter)
- [Discuss] vnc
- From: markw at mohawksoft.com (markw at mohawksoft.com)
- [Discuss] vnc
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] vnc
- From: markw at mohawksoft.com (markw at mohawksoft.com)
- [Discuss] vnc
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] vnc
- Prev by Date: [Discuss] Why the dislike of X.509?
- Next by Date: [Discuss] vnc
- Previous by thread: [Discuss] vnc
- Next by thread: [Discuss] vnc
- Index(es):