Afficher un message
Vieux 04/09/2006, 03h50   #6
responder
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: ssh dictionary attacks

(The suggestion under discussion came from "shrike@cyberspace.org"
<shrike@cyberspace.org>)

Ertugrul Soeylemez wrote:

[...]

> but in the deterministic
> e-world problems shouldn't be hidden, but rather solved.


What problems clearly did you think I wanted to be hidden, or did I not
understand your intent, please ?

> The other problem with the suggestion is: Firstly, the real bad guys
> wouldn't be found that way, and the police had too much work filtering
> out those "innocent" bad admins (i.e. PEBKAC users, who need the
> computer for their work or other things, and wouldn't care much about
> computing security). And there are probably hundrets of thousands of
> them.


But this is exactly the point: The '"innocent" bad admins' are a threat
to others if running compromised systems. "Innocence" or carelessness or
cluelessness is not a justification for running compromised, networked
systems, and should not be a guarantee of any percieved "right" to
continue doing so. The criterion is that if a connected system is
compromised it should be disconnected.
  Réponse avec citation
 
Page generated in 0,15021 seconds with 9 queries