Gnus development mailing list
 help / color / mirror / Atom feed
From: Alan Shutko <ats@acm.org>
Subject: Re: Reading Ding in Gnus
Date: 24 Jan 2000 15:22:59 -0500	[thread overview]
Message-ID: <m3d7qrgqxo.fsf@acm.org> (raw)
In-Reply-To: dsg@mitre.org's message of "24 Jan 2000 14:57:53 -0500"

dsg@mitre.org (David S. Goldberg) writes:

> > If you can convince your sysadmin to open outbound ssh (which is
> > about as far from a security risk as can be), you can either
> > redirect ports, or set up a PPP tunnel.
> 
> Was there a smiley missing?  That PPP tunnel is a complete subversion
> of the firewall.

No, it's not.  My PPP tunnel won't allow anything into the network,
and my machine won't packets to it.  All it does is let me contact
certain services that our firewall blocks.  If you view a firewall as
a tool to prevent use of services by people inside it, yes, I'm
undermining it.  If you view a firewall as a tool to protect against
outside intruders, I'm not "completely subverting" the firewall.

Now I hear you saying "Why would the firewall administrator block
outgoing POP if he didn't care if you used it?"  Good question, which
is why I asked him.  He didn't know, just sounded like a good idea at
the time (like blocking all ICMP).  In any case, he knows about my PPP
tunnel and has no problem with it.

Naturally, doing things this way will involve communication with the
firewall admin, so I don't see any problem with it.  If the admin
doesn't go for it, it isn't going to happen.  But personally, I don't
think that (implemented correctly) this is more of a security concern
for the company than executives forwarding all their mail to hotmail
so they can access it on the road.

-- 
Alan Shutko <ats@acm.org> - In a variety of flavors!
When nothing can possibly go wrong, it will.



      reply	other threads:[~2000-01-24 20:22 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2000-01-19 19:57 Rui-Tao Dong
2000-01-19 20:52 ` Kai Großjohann
2000-01-19 21:18   ` Rui-Tao Dong
2000-01-19 22:50     ` Alan Shutko
2000-01-24 19:57       ` David S. Goldberg
2000-01-24 20:22         ` Alan Shutko [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=m3d7qrgqxo.fsf@acm.org \
    --to=ats@acm.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).