discuss AT lists.opennicproject.org
Subject: Discuss mailing list
List archive
- From: gp AT gparent.net
- To: discuss AT lists.opennicproject.org
- Subject: Re: [opennic-discuss] .OZ admin bowing out...
- Date: Thu, 01 May 2014 19:58:42 +0000
- Openpgp: id=70154FCF
If I were to join a project where
nobody knows anything about me and I haven't ever said a word -
yes.
Because I wouldn't host a bunch of my infrastructure on a server that I share as a T1 for OpenNIC. Also, SHA1 isn't good either. Please, implement a crypt-like scheme if you're going to implement anything at all. As presumably experienced sysadmins, would you really give root access to your boxes to someone else who you only know online? Generally, root should be protected. Surely, in terms of safeguarding the OpenNIC infrastructure, everything that could be done with root access can be achieved another way without accessing the server at all. People (or their personal password store) can be compromised just as systems can and a compromised person with root access to your systems is arguably more of a risk than the risk you're trying to prevent. Simon -- -gp |
- Re: [opennic-discuss] .OZ admin bowing out..., Mario Rodriguez, 05/01/2014
- Re: [opennic-discuss] .OZ admin bowing out..., Simon, 05/01/2014
- Re: [opennic-discuss] .OZ admin bowing out..., Mario Rodriguez, 05/01/2014
- Re: [opennic-discuss] .OZ admin bowing out..., gp, 05/01/2014
- Re: [opennic-discuss] .OZ admin bowing out..., Julian DeMarchi, 05/01/2014
- Re: [opennic-discuss] .OZ admin bowing out..., Martin C, 05/01/2014
- Re: [opennic-discuss] .OZ admin bowing out..., Simon, 05/01/2014
Archive powered by MHonArc 2.6.19.