Re: ssh dictionary attacks
(The suggestion under discussion came from "shrike@cyberspace.org"
<shrike@cyberspace.org>)
Ertugrul Soeylemez wrote:
[...]
> but in the deterministic
> e-world problems shouldn't be hidden, but rather solved.
What problems clearly did you think I wanted to be hidden, or did I not
understand your intent, please ?
> The other problem with the suggestion is: Firstly, the real bad guys
> wouldn't be found that way, and the police had too much work filtering
> out those "innocent" bad admins (i.e. PEBKAC users, who need the
> computer for their work or other things, and wouldn't care much about
> computing security). And there are probably hundrets of thousands of
> them.
But this is exactly the point: The '"innocent" bad admins' are a threat
to others if running compromised systems. "Innocence" or carelessness or
cluelessness is not a justification for running compromised, networked
systems, and should not be a guarantee of any percieved "right" to
continue doing so. The criterion is that if a connected system is
compromised it should be disconnected.
|