SSH?
Posted Aug 12, 2004 5:15 UTC (Thu) by
Duncan (guest, #6647)
Parent article:
Sarge is coming
Why should SSH be installed by default? How many users are there out
there that have an internet connection, but no desire to connect to their
home computer from another location, or to some other location from home
in "shell" mode? I'd venture there's a lot. If that functionality is
unneeded, why include SSH by default, since every unnecessary inclusion is
one more possible security vuln, and it's JUST this type of person that's
least likely to keep their system updated in terms of security fixes and
the like.
How many folks on the Gentoo lists ask how to connect to their home system
via SSH, saying it "just worked" on <whatever>? We tell them that Gentoo
(which does come with SSH in the system install, tho I don't agree with
that), doesn't turn on such things by default, and they must configure it
to allow X via TCP and remote forwarding. That's a Good Thing (r)! How I
did battle to try and turn off those ports on Mandrake, that /shouldn't/
have been listening AT ALL, as I didn't need nor want remote access
functionality!
Sure, have it /available/ by default, but not /installed/ by default,
unless someone chooses a "remote desktop functionality" package or some
such. Again, it's /just/ the folks who don't need it that are most likely
to fail to update their systems regularly and properly, and therefore the
most likely to get cracked in part due to something they never needed or
asked that it be installed! All it does is waste disk space, increase
complexity, and provide yet another unneeded bit of functionality that
must be kept up to date to keep the system secure.
Duncan
(
Log in to post comments)