Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #227285 > unrolled thread

crc not installed but rsync using it? ...

Started byAlbretch Mueller <lbrtchx@gmail.com>
First post2020-09-24 15:10 +0200
Last post2020-09-25 16:50 +0200
Articles 20 on this page of 51 — 17 participants

Back to article view | Back to linux.debian.user


Contents

  crc not installed but rsync using it? ... Albretch Mueller <lbrtchx@gmail.com> - 2020-09-24 15:10 +0200
    Re: crc not installed but rsync using it? ... Greg Wooledge <wooledg@eeg.ccf.org> - 2020-09-24 15:30 +0200
    Re: crc not installed but rsync using it? ... Thomas Pircher <thp+debian@p5r.uk> - 2020-09-24 15:40 +0200
      Re: crc not installed but rsync using it? ... Greg Wooledge <wooledg@eeg.ccf.org> - 2020-09-24 18:00 +0200
      Re: crc not installed but rsync using it? ... Albretch Mueller <lbrtchx@gmail.com> - 2020-09-24 18:00 +0200
        Re: crc not installed but rsync using it? ... Thomas Pircher <thp+debian@p5r.uk> - 2020-09-24 18:30 +0200
        Re: crc not installed but rsync using it? ... Reco <recoverym4n@enotuniq.net> - 2020-09-24 19:10 +0200
          Re: crc not installed but rsync using it? ... Albretch Mueller <lbrtchx@gmail.com> - 2020-09-29 16:00 +0200
            Re: crc not installed but rsync using it? ... Dan Ritter <dsr@randomstring.org> - 2020-09-29 16:50 +0200
            Re: crc not installed but rsync using it? ... Reco <recoverym4n@enotuniq.net> - 2020-09-29 16:50 +0200
        Re: crc not installed but rsync using it? ... Sven Hartge <sven@svenhartge.de> - 2020-09-24 20:30 +0200
          Re: crc not installed but rsync using it? ... David Wright <deblis@lionunicorn.co.uk> - 2020-09-25 01:00 +0200
            Re: crc not installed but rsync using it? ... Jonathan Dowland <jon+debian-user@dow.land> - 2020-09-25 11:40 +0200
              Re: crc not installed but rsync using it? ... David Wright <deblis@lionunicorn.co.uk> - 2020-09-26 04:50 +0200
              Re: crc not installed but rsync using it? ... Albretch Mueller <lbrtchx@gmail.com> - 2020-09-29 16:00 +0200
                Re: crc not installed but rsync using it? ... Albretch Mueller <lbrtchx@gmail.com> - 2020-09-29 16:30 +0200
                  Re: crc not installed but rsync using it? ... Andrei POPESCU <andreimpopescu@gmail.com> - 2020-10-01 09:00 +0200
            Re: crc not installed but rsync using it? ... Greg Wooledge <wooledg@eeg.ccf.org> - 2020-09-25 13:50 +0200
              Re: crc not installed but rsync using it? ... Albretch Mueller <lbrtchx@gmail.com> - 2020-09-25 14:00 +0200
                Re: crc not installed but rsync using it? ... Gene Heskett <gheskett@shentel.net> - 2020-09-25 15:10 +0200
                  Re: crc not installed but rsync using it? ... John Hasler <jhasler@newsguy.com> - 2020-09-25 15:30 +0200
                    Re: crc not installed but rsync using it? ... Gene Heskett <gheskett@shentel.net> - 2020-09-25 16:00 +0200
                      Re: crc not installed but rsync using it? ... John Hasler <jhasler@newsguy.com> - 2020-09-25 18:10 +0200
                        Re: crc not installed but rsync using it? ... Stefan Monnier <monnier@iro.umontreal.ca> - 2020-09-25 18:20 +0200
                          Re: crc not installed but rsync using it? ... John Hasler <jhasler@newsguy.com> - 2020-09-25 19:40 +0200
                            Re: crc not installed but rsync using it? ... Stefan Monnier <monnier@iro.umontreal.ca> - 2020-09-25 20:20 +0200
                            Re: crc not installed but rsync using it? ... Stefan Monnier <monnier@iro.umontreal.ca> - 2020-09-26 00:10 +0200
                              Re: crc not installed but rsync using it? ... John Hasler <jhasler@newsguy.com> - 2020-09-26 00:30 +0200
                                Re: crc not installed but rsync using it? ... Stefan Monnier <monnier@iro.umontreal.ca> - 2020-09-26 00:50 +0200
                        Re: crc not installed but rsync using it? ... Gene Heskett <gheskett@shentel.net> - 2020-09-25 19:00 +0200
                          Re: crc not installed but rsync using it? ... Stefan Monnier <monnier@iro.umontreal.ca> - 2020-09-26 00:20 +0200
                            Re: crc not installed but rsync using it? ... Gene Heskett <gheskett@shentel.net> - 2020-09-26 00:50 +0200
                              Re: crc not installed but rsync using it? ... Stefan Monnier <monnier@iro.umontreal.ca> - 2020-09-26 01:00 +0200
                              Re: crc not installed but rsync using it? ... mick crane <mick.crane@gmail.com> - 2020-09-26 02:00 +0200
                                Re: crc not installed but rsync using it? ... Dan Ritter <dsr@randomstring.org> - 2020-09-26 16:50 +0200
                  Re: crc not installed but rsync using it? ... Michael Stone <mstone@debian.org> - 2020-09-25 16:30 +0200
                    Re: crc not installed but rsync using it? ... Gene Heskett <gheskett@shentel.net> - 2020-09-25 17:00 +0200
                      Re: crc not installed but rsync using it? ... Michael Stone <mstone@debian.org> - 2020-09-25 17:30 +0200
                        Re: crc not installed but rsync using it? ... Stefan Monnier <monnier@iro.umontreal.ca> - 2020-09-25 17:40 +0200
                    Re: crc not installed but rsync using it? ... Andrei POPESCU <andreimpopescu@gmail.com> - 2020-09-25 17:10 +0200
                      Re: crc not installed but rsync using it? ... Tixy <tixy@yxit.co.uk> - 2020-09-25 18:30 +0200
                        Re: crc not installed but rsync using it? ... Brian <ad44@cityscape.co.uk> - 2020-09-25 20:00 +0200
          Re: crc not installed but rsync using it? ... Albretch Mueller <lbrtchx@gmail.com> - 2020-09-25 13:50 +0200
            Re: crc not installed but rsync using it? ... Dan Ritter <dsr@randomstring.org> - 2020-09-25 15:00 +0200
            Re: crc not installed but rsync using it? ... Michael Stone <mstone@debian.org> - 2020-09-25 15:50 +0200
              Re: crc not installed but rsync using it? ... Albretch Mueller <lbrtchx@gmail.com> - 2020-09-26 14:20 +0200
                Re: crc not installed but rsync using it? ... Michael Stone <mstone@debian.org> - 2020-09-26 22:20 +0200
                  Re: crc not installed but rsync using it? ... Albretch Mueller <lbrtchx@gmail.com> - 2020-09-29 15:50 +0200
                    Re: crc not installed but rsync using it? ... David Wright <deblis@lionunicorn.co.uk> - 2020-09-29 16:50 +0200
                      Re: crc not installed but rsync using it? ... Fabrice BAUZAC-STEHLY <noon@mykolab.com> - 2020-10-01 13:30 +0200
            Re: crc not installed but rsync using it? ... Andrei POPESCU <andreimpopescu@gmail.com> - 2020-09-25 16:50 +0200

Page 2 of 3 — ← Prev page 1 [2] 3  Next page →


#227342

FromJohn Hasler <jhasler@newsguy.com>
Date2020-09-25 15:30 +0200
Message-ID<ASVXr-sc-3@gated-at.bofh.it>
In reply to#227339
Gene writes:
> No you are not the only one, but you are a minority that does not
> always want to understand how to use the internet and be safe at the
> same time.  It can be done, I'm doing it.  And I've been doing it
> since the later 90's.

Same here, though I use a pc running Debian as a router.

-- 
John Hasler 
jhasler@newsguy.com
Elmwood, WI USA

[toc] | [prev] | [next] | [standalone]


#227346

FromGene Heskett <gheskett@shentel.net>
Date2020-09-25 16:00 +0200
Message-ID<ASWqu-BR-3@gated-at.bofh.it>
In reply to#227342
On Friday 25 September 2020 09:25:20 John Hasler wrote:

> Gene writes:
> > No you are not the only one, but you are a minority that does not
> > always want to understand how to use the internet and be safe at the
> > same time.  It can be done, I'm doing it.  And I've been doing it
> > since the later 90's.
>
> Same here, though I use a pc running Debian as a router.

I did too, John H., until that PC upchucked something over a decade back, 
and I found I didn't have to register the router, much much easier to 
maintain. The CF boot media for the PC was a PITA. Lasted 6 months at 
best with the ext3 filesystem abusing it. And used around 200 watts. The 
Buffalo Netfinity router might use 10 watts.  With the radio turned off, 
even less.

Stay safe and well, John.

Cheers, Gene Heskett
-- 
"There are four boxes to be used in defense of liberty:
 soap, ballot, jury, and ammo. Please use in that order."
-Ed Howdershelt (Author)
If we desire respect for the law, we must first make the law respectable.
 - Louis D. Brandeis
Genes Web page <http://geneslinuxbox.net:6309/gene>

[toc] | [prev] | [next] | [standalone]


#227355

FromJohn Hasler <jhasler@newsguy.com>
Date2020-09-25 18:10 +0200
Message-ID<ASYsi-22O-3@gated-at.bofh.it>
In reply to#227346
I wrote:
> Same here, though I use a pc running Debian as a router.

Gene writes:
> ...I found I didn't have to register the router...

Don't know what you mean by that.  My DSL modem is in bridge mode, of
course, and pppoe on the pc just works.  The old Dell I use has been
running for about ten years now.  Will be replaced as soon as I find an
affordable ARM board with two NICs.
-- 
John Hasler 
jhasler@newsguy.com
Elmwood, WI USA

[toc] | [prev] | [next] | [standalone]


#227356

FromStefan Monnier <monnier@iro.umontreal.ca>
Date2020-09-25 18:20 +0200
Message-ID<ASYBY-25Y-3@gated-at.bofh.it>
In reply to#227355
> Will be replaced as soon as I find an affordable ARM board with
> two NICs.

Ah, yes, that.  I assume you mean tho ethernet NICs (many boards have
two NICs in the form of ethernet + wifi).

I know of the BPI-R1 and BPI-R2 and the espressobin, but hopefully
there's more.

FWIW, I use a Banana Pi where the mini-USB OTG port is used as the
second NICs (via the gether gadget).  The upside is that it frees up the
ethernet port of the computer which is connected to it, so I "daisy chained"
the second computer which I would have ideally connected to the BPI.


        Stefan

[toc] | [prev] | [next] | [standalone]


#227361

FromJohn Hasler <jhasler@newsguy.com>
Date2020-09-25 19:40 +0200
Message-ID<ASZRp-2Kh-9@gated-at.bofh.it>
In reply to#227356
Stefan writes:
> I assume you mean tho ethernet NICs (many boards have two NICs in the
> form of ethernet + wifi).

Yes, of course.  I don't want WiFi on a router and I want real NICs, not
ones faked via USB.

> I know of the BPI-R1 and BPI-R2 and the espressobin, but hopefully
> there's more.

I have an Espressobin.  It isn't stable due to some sort of power supply
problem (and the available schematics are incorrect). I tried three
different units: it's a design problem.  I may go back to messing with
it and try clocking is down, but I don't trust it now.  Too bad, because
the specs make it ideal.  It not only has three real NICs, but it also
has a real 1 Gbit switch.

I'll look at the BPI-R1 and BPI-R2.
-- 
John Hasler 
jhasler@newsguy.com
Elmwood, WI USA

[toc] | [prev] | [next] | [standalone]


#227365

FromStefan Monnier <monnier@iro.umontreal.ca>
Date2020-09-25 20:20 +0200
Message-ID<AT0u6-3d4-13@gated-at.bofh.it>
In reply to#227361
> I have an Espressobin.  It isn't stable due to some sort of power supply
> problem (and the available schematics are incorrect).  I tried three
> different units: it's a design problem.  I may go back to messing with
> it and try clocking is down, but I don't trust it now.  Too bad, because
> the specs make it ideal.  It not only has three real NICs, but it also
> has a real 1 Gbit switch.
>
> I'll look at the BPI-R1 and BPI-R2.

I don't know anything about the BPI-R2, but the stories I've heard about
the BPI-R1 aren't much more encouraging than yours about the espressobin
(which is why so far I'm sticking to my BananaPi-based hack).

I also found the Orange Pi R1, but with 256MB it's rather underpowered
for my taste (and it's only 100Mb/s ethernets).  [ And I've had
stability problems (apparently linked to power) with my Orange Pi mini,
so I look at "orange pi" with suspicion.  ]


        Stefan

[toc] | [prev] | [next] | [standalone]


#227368

FromStefan Monnier <monnier@iro.umontreal.ca>
Date2020-09-26 00:10 +0200
Message-ID<AT44G-5na-13@gated-at.bofh.it>
In reply to#227361
> I have an Espressobin.  It isn't stable due to some sort of power supply
> problem (and the available schematics are incorrect). I tried three
> different units: it's a design problem.  I may go back to messing with
> it and try clocking is down, but I don't trust it now.  Too bad, because
> the specs make it ideal.  It not only has three real NICs, but it also
> has a real 1 Gbit switch.
>
> I'll look at the BPI-R1 and BPI-R2.

BTW, depending on what you expect from an "ARM board" and what you
consider "affordable", you could go for an actual router (many of which
are based on ARM nowadays).  E.g.

    https://www.gl-inet.com/products/gl-mv1000/


-- Stefan

[toc] | [prev] | [next] | [standalone]


#227370

FromJohn Hasler <jhasler@newsguy.com>
Date2020-09-26 00:30 +0200
Message-ID<AT4o1-5tr-7@gated-at.bofh.it>
In reply to#227368
Stefan writes:
> BTW, depending on what you expect from an "ARM board" and what you
> consider "affordable", you could go for an actual router (many of
> which are based on ARM nowadays).

It has to run Debian or a Debian derivative.
-- 
John Hasler 
jhasler@newsguy.com
Elmwood, WI USA

[toc] | [prev] | [next] | [standalone]


#227372

FromStefan Monnier <monnier@iro.umontreal.ca>
Date2020-09-26 00:50 +0200
Message-ID<AT4Hn-5zB-5@gated-at.bofh.it>
In reply to#227370
>> BTW, depending on what you expect from an "ARM board" and what you
>> consider "affordable", you could go for an actual router (many of
>> which are based on ARM nowadays).
> It has to run Debian or a Debian derivative.

I can't see any reason why you couldn't install Debian on a "Brume".
The manufacturer put a logo of Ubuntu on the product's web pages, so
they may have some Ubuntu image available.  I don't see a DTS file for
it in the vanilla Linux kernel, tho, so it might be difficult to get
up-to-date kernels in the future.


        Stefan

[toc] | [prev] | [next] | [standalone]


#227359

FromGene Heskett <gheskett@shentel.net>
Date2020-09-25 19:00 +0200
Message-ID<ASZeG-2iK-5@gated-at.bofh.it>
In reply to#227355
On Friday 25 September 2020 12:06:07 John Hasler wrote:

> I wrote:
> > Same here, though I use a pc running Debian as a router.
>
> Gene writes:
> > ...I found I didn't have to register the router...
>
> Don't know what you mean by that. 

He may have changed it, but at the time I first started using it on 
a "pc" it had to be registered before it would access the 2nd port.  The 
router reflashes didn't need that. That was obviously more than a decade 
back up the log.

> My DSL modem is in bridge mode, of 
> course, and pppoe on the pc just works.  The old Dell I use has been
> running for about ten years now.  Will be replaced as soon as I find
> an affordable ARM board with two NICs.

Very niche market John, doubtfull now that the r-pi has been sold. We may 
find that by carefull inspection of the routers available though. But it 
won't be sold as anything but a router. We'll likely have to look thru 
the camo cloaking of its router propaganda to find it. High likelyhood 
we already have it and we've not looked in the proper place.

Cheers, Gene Heskett
-- 
"There are four boxes to be used in defense of liberty:
 soap, ballot, jury, and ammo. Please use in that order."
-Ed Howdershelt (Author)
If we desire respect for the law, we must first make the law respectable.
 - Louis D. Brandeis
Genes Web page <http://geneslinuxbox.net:6309/gene>

[toc] | [prev] | [next] | [standalone]


#227369

FromStefan Monnier <monnier@iro.umontreal.ca>
Date2020-09-26 00:20 +0200
Message-ID<AT4el-5qp-5@gated-at.bofh.it>
In reply to#227359
> He may have changed it, but at the time I first started using it on 
> a "pc" it had to be registered before it would access the 2nd port.

I don't understand what you're referring to:
- What is the "it" that had to be registered?
- With whom/what did it have to be registered?
- What 2nd port of what?


        Stefan

[toc] | [prev] | [next] | [standalone]


#227371

FromGene Heskett <gheskett@shentel.net>
Date2020-09-26 00:50 +0200
Message-ID<AT4Hn-5zB-1@gated-at.bofh.it>
In reply to#227369
On Friday 25 September 2020 18:10:42 Stefan Monnier wrote:

> > He may have changed it, but at the time I first started using it on
> > a "pc" it had to be registered before it would access the 2nd port.
>
> I don't understand what you're referring to:
> - What is the "it" that had to be registered?

That edition of dd-wrt.  You had to get a keyfile from brainslayer.  You 
didn't have to get one to go with a router version.  And it sometimes 
took most of a week for him to service your key request.

> - With whom/what did it have to be registered?
> - What 2nd port of what?

The second ethernet port of the pc you built to run it.
>
>
>         Stefan


Cheers, Gene Heskett
-- 
"There are four boxes to be used in defense of liberty:
 soap, ballot, jury, and ammo. Please use in that order."
-Ed Howdershelt (Author)
If we desire respect for the law, we must first make the law respectable.
 - Louis D. Brandeis
Genes Web page <http://geneslinuxbox.net:6309/gene>

[toc] | [prev] | [next] | [standalone]


#227373

FromStefan Monnier <monnier@iro.umontreal.ca>
Date2020-09-26 01:00 +0200
Message-ID<AT4R3-5CW-5@gated-at.bofh.it>
In reply to#227371
>> I don't understand what you're referring to:
>> - What is the "it" that had to be registered?
> That edition of dd-wrt.

Oooohhhh!  You were running DD-wrt on a pc??

Indeed, OpenWRT also supports running on a PC, but it would never have
occurred to me to do that.  I'd just use Debian instead: much easier to
upgrade, for example.  Indeed, I used to run Debian on my WL-700gE just
because it was much more comfortable than OpenWRT (tho the 64MB of RAM
made `apt-get` pretty damn slow).

> You had to get a keyfile from brainslayer.

Doesn't sound like Free Software, so I would have stayed far away from it.


        Stefan

[toc] | [prev] | [next] | [standalone]


#227374

Frommick crane <mick.crane@gmail.com>
Date2020-09-26 02:00 +0200
Message-ID<AT5N7-6bK-1@gated-at.bofh.it>
In reply to#227371
On 2020-09-25 23:42, Gene Heskett wrote:
> On Friday 25 September 2020 18:10:42 Stefan Monnier wrote:
> 
>> > He may have changed it, but at the time I first started using it on
>> > a "pc" it had to be registered before it would access the 2nd port.
>> 
>> I don't understand what you're referring to:
>> - What is the "it" that had to be registered?
> 
> That edition of dd-wrt.  You had to get a keyfile from brainslayer.  
> You
> didn't have to get one to go with a router version.  And it sometimes
> took most of a week for him to service your key request.
> 
>> - With whom/what did it have to be registered?
>> - What 2nd port of what?
> 
> The second ethernet port of the pc you built to run it.

When all this internet kicked off I thought anybody could have a go but 
apparently you need to be with a provider.

mick

-- 
Key ID    4BFEBB31

[toc] | [prev] | [next] | [standalone]


#227398

FromDan Ritter <dsr@randomstring.org>
Date2020-09-26 16:50 +0200
Message-ID<ATjGq-69y-7@gated-at.bofh.it>
In reply to#227374
mick crane wrote: 
> 
> When all this internet kicked off I thought anybody could have a go but
> apparently you need to be with a provider.

If you have enough money, skill, and time you can be your own
ISP.

The nature of "ISP" is in the first word, "Internet". It
requires you to be connected to one or more other networks. At
normal household scales, it is most cost-effective to buy that
connectivity from an entity that has infrastructure in your
area.

In the early 1990s a single T1 (1.54Mb/s bidirectional) to a larger
provide, a router, a server and a set of modems connected to phone lines
was all you needed to set up shop as a local ISP. The T1 might be 3 or 4
thousand dollars a month, so you needed a few hundred customers to break
even. If your average customer connected at 9600 baud and was online for
four hours a day, and a day is really only 12 hours long to account for
peak usage patterns, a modem and phone line could support 3 customers
and you could hang 160 modems off of that T1, so you would max out at
about 600 customers before you started getting enough complaints about
speed that they looked for someone else.

For the USA, I have great connectivity: there are three ISPs
willing to deliver consumer-class gigabit links to my house, so
I pay about 5x what I paid in 2000 for a connection 34000x
faster. And all the other services that an ISP would offer me, I
handle myself with Debian machines.

-dsr-

[toc] | [prev] | [next] | [standalone]


#227347

FromMichael Stone <mstone@debian.org>
Date2020-09-25 16:30 +0200
Message-ID<ASWTv-11y-5@gated-at.bofh.it>
In reply to#227339
On Fri, Sep 25, 2020 at 09:01:26AM -0400, Gene Heskett wrote:
>Your paranoia is excessive. I have 5 machines online ATM, but they are
>all on a local network in the 1902.168.xx.xx block, which is NOT
>routable from the internet but are NAT'd to my net address by having
>such a setup in a router running dd-wrt. In nearly 2 decades, no one has
>come into my systems from the internet that I didn't give the
>credentials to do so.

You post this all the time, but it's irrelevant at best and misleading 
at worst. On a default debian system these days an external firewall is 
basically a noop because there are no services listening. The attack 
vector in modern environments is much more likely to be client exploits 
(e.g., web browser) and a perimeter firewall adds zero protection from 
that threat. 

And, honestly, most people who are compromised have no clue that they 
are unless someone tells them.

Telling people that all they need to do is install a perimeter firewall 
and then they're secure is simply wrong.

[toc] | [prev] | [next] | [standalone]


#227350

FromGene Heskett <gheskett@shentel.net>
Date2020-09-25 17:00 +0200
Message-ID<ASXmy-1b6-1@gated-at.bofh.it>
In reply to#227347
On Friday 25 September 2020 10:23:43 Michael Stone wrote:

> On Fri, Sep 25, 2020 at 09:01:26AM -0400, Gene Heskett wrote:
> >Your paranoia is excessive. I have 5 machines online ATM, but they
> > are all on a local network in the 1902.168.xx.xx block, which is NOT
> > routable from the internet but are NAT'd to my net address by having
> > such a setup in a router running dd-wrt. In nearly 2 decades, no one
> > has come into my systems from the internet that I didn't give the
> > credentials to do so.
>
> You post this all the time, but it's irrelevant at best and misleading
> at worst. On a default debian system these days an external firewall
> is basically a noop because there are no services listening. The
> attack vector in modern environments is much more likely to be client
> exploits (e.g., web browser) and a perimeter firewall adds zero
> protection from that threat.
>
> And, honestly, most people who are compromised have no clue that they
> are unless someone tells them.
>
> Telling people that all they need to do is install a perimeter
> firewall and then they're secure is simply wrong.

I usually give the OP credit for not clicking on the links he runs across 
that aren't on the up and up. I dunno, but the odor about them seems to 
be warning enough for me.  If OTOH, the OP succumbs, then he/she is 
going to get bit eventually and there is little you or I can do to stop 
it.

It all boils down to a believeing in TANSTAAFL. We both obviously have 
experiences going back decades, and thats my experience. I find 
TANSTAAFL to be a law that you can't break if you tried. Like a western 
actor whose real name was Marion Morrison once said, stupid should hurt. 
What he didn't say was that it also should teach. And I don't believe we 
can argue about that.

Stay safe and well Michael.

Cheers, Gene Heskett
-- 
"There are four boxes to be used in defense of liberty:
 soap, ballot, jury, and ammo. Please use in that order."
-Ed Howdershelt (Author)
If we desire respect for the law, we must first make the law respectable.
 - Louis D. Brandeis
Genes Web page <http://geneslinuxbox.net:6309/gene>

[toc] | [prev] | [next] | [standalone]


#227353

FromMichael Stone <mstone@debian.org>
Date2020-09-25 17:30 +0200
Message-ID<ASXPz-1A9-3@gated-at.bofh.it>
In reply to#227350
On Fri, Sep 25, 2020 at 10:56:56AM -0400, Gene Heskett wrote:
>I usually give the OP credit for not clicking on the links he runs across
>that aren't on the up and up. I dunno, but the odor about them seems to
>be warning enough for me.

That's simply not true. Compromised web sites are a thing, among other 
issues.

[toc] | [prev] | [next] | [standalone]


#227354

FromStefan Monnier <monnier@iro.umontreal.ca>
Date2020-09-25 17:40 +0200
Message-ID<ASXZf-1DD-1@gated-at.bofh.it>
In reply to#227353
>>I usually give the OP credit for not clicking on the links he runs across
>>that aren't on the up and up. I dunno, but the odor about them seems to
>>be warning enough for me.
> That's simply not true.  Compromised web sites are a thing, among
> other issues.

Yup.  The widespread existence of "bad links" that smell very strongly
does not mean that there aren't odorless "bad links".
Often, the more self-confident you are, the more vulnerable you are.


        Stefan "self-confidently aware that he's quite self-confident"

[toc] | [prev] | [next] | [standalone]


#227351

FromAndrei POPESCU <andreimpopescu@gmail.com>
Date2020-09-25 17:10 +0200
Message-ID<ASXwd-1tW-1@gated-at.bofh.it>
In reply to#227347

[Multipart message — attachments visible in raw view] — view raw

On Vi, 25 sep 20, 10:23:43, Michael Stone wrote:
> On Fri, Sep 25, 2020 at 09:01:26AM -0400, Gene Heskett wrote:
> > Your paranoia is excessive. I have 5 machines online ATM, but they are
> > all on a local network in the 1902.168.xx.xx block, which is NOT
> > routable from the internet but are NAT'd to my net address by having

NAT is just a nuisance, in *both* directions.

> > such a setup in a router running dd-wrt. In nearly 2 decades, no one has
> > come into my systems from the internet that I didn't give the
> > credentials to do so.
> 
> You post this all the time, but it's irrelevant at best and misleading at
> worst. On a default debian system these days an external firewall is
> basically a noop because there are no services listening.

Well, besides exim (still installed by default as far as I know), CUPS 
(probably pulled by most DEs) and SSH server (quite common for many 
users), plenty of other softwares are listening on some port, e.g. mpd, 
syncthing (web interface), qbittorrent-nox (web interface), barrier, 
just to name a few.

Most of these have some sort of password protection available, which may 
or may not be enabled by default, assuming it's even reasonably secure.

A firewall does provide and additional layer of protection for them.

> The attack vector
> in modern environments is much more likely to be client exploits (e.g., web
> browser) and a perimeter firewall adds zero protection from that threat.

Agreed.

> And, honestly, most people who are compromised have no clue that they are
> unless someone tells them.

Agreed as well.

> Telling people that all they need to do is install a perimeter firewall and
> then they're secure is simply wrong.

Yep.

Kind regards,
Andrei
-- 
http://wiki.debian.org/FAQsFromDebianUser

[toc] | [prev] | [next] | [standalone]


Page 2 of 3 — ← Prev page 1 [2] 3  Next page →

Back to top | Article view | linux.debian.user


csiph-web