Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #200358 > unrolled thread
| Started by | Subhadip Ghosh <subhadip.sky@gmail.com> |
|---|---|
| First post | 2018-09-21 05:10 +0200 |
| Last post | 2018-09-24 20:50 +0200 |
| Articles | 20 on this page of 85 — 22 participants |
Back to article view | Back to linux.debian.user
Why does Debian allow all incoming traffic by default Subhadip Ghosh <subhadip.sky@gmail.com> - 2018-09-21 05:10 +0200
Re: Why does Debian allow all incoming traffic by default Roberto C. Sánchez <roberto@debian.org> - 2018-09-21 05:30 +0200
Re: Why does Debian allow all incoming traffic by default Subhadip Ghosh <subhadip.sky@gmail.com> - 2018-09-21 05:40 +0200
Re: Why does Debian allow all incoming traffic by default Roberto C. Sánchez <roberto@debian.org> - 2018-09-21 05:50 +0200
Re: Why does Debian allow all incoming traffic by default deloptes <deloptes@gmail.com> - 2018-09-21 07:10 +0200
Re: Why does Debian allow all incoming traffic by default Subhadip Ghosh <subhadip.sky@gmail.com> - 2018-09-21 19:40 +0200
Re: Why does Debian allow all incoming traffic by default Dan Ritter <dsr@randomstring.org> - 2018-09-21 19:10 +0200
Re: Why does Debian allow all incoming traffic by default Subhadip Ghosh <subhadip.sky@gmail.com> - 2018-09-21 19:40 +0200
Re: Why does Debian allow all incoming traffic by default deloptes <deloptes@gmail.com> - 2018-09-21 20:00 +0200
Re: Why does Debian allow all incoming traffic by default Subhadip Ghosh <subhadip.sky@gmail.com> - 2018-09-21 20:10 +0200
Re: Why does Debian allow all incoming traffic by default Brian <ad44@cityscape.co.uk> - 2018-09-21 21:40 +0200
Re: Why does Debian allow all incoming traffic by default David Wright <deblis@lionunicorn.co.uk> - 2018-09-21 21:50 +0200
Re: Why does Debian allow all incoming traffic by default mick crane <mick.crane@gmail.com> - 2018-09-23 01:10 +0200
Re: Why does Debian allow all incoming traffic by default Brian <ad44@cityscape.co.uk> - 2018-09-23 20:00 +0200
Re: Why does Debian allow all incoming traffic by default Joe <joe@jretrading.com> - 2018-09-23 23:00 +0200
Re: Why does Debian allow all incoming traffic by default Brian <ad44@cityscape.co.uk> - 2018-09-24 00:00 +0200
Re: Why does Debian allow all incoming traffic by default Pascal Hambourg <pascal@plouf.fr.eu.org> - 2018-09-22 09:40 +0200
Re: Why does Debian allow all incoming traffic by default Gene Heskett <gheskett@shentel.net> - 2018-09-22 11:20 +0200
Re: Why does Debian allow all incoming traffic by default Pascal Hambourg <pascal@plouf.fr.eu.org> - 2018-09-22 13:00 +0200
Re: Why does Debian allow all incoming traffic by default Dan Ritter <dsr@randomstring.org> - 2018-09-22 13:40 +0200
Re: Why does Debian allow all incoming traffic by default Pascal Hambourg <pascal@plouf.fr.eu.org> - 2018-09-22 17:00 +0200
Re: Why does Debian allow all incoming traffic by default Gene Heskett <gheskett@shentel.net> - 2018-09-22 20:20 +0200
Re: Why does Debian allow all incoming traffic by default Richard Hector <richard@walnut.gen.nz> - 2018-09-24 05:20 +0200
Re: Why does Debian allow all incoming traffic by default Gene Heskett <gheskett@shentel.net> - 2018-09-24 05:30 +0200
Re: Why does Debian allow all incoming traffic by default <tomas@tuxteam.de> - 2018-09-24 09:10 +0200
Re: Why does Debian allow all incoming traffic by default Gene Heskett <gheskett@shentel.net> - 2018-09-24 11:00 +0200
Re: Why does Debian allow all incoming traffic by default <tomas@tuxteam.de> - 2018-09-24 11:40 +0200
Re: Why does Debian allow all incoming traffic by default Gene Heskett <gheskett@shentel.net> - 2018-09-24 14:20 +0200
Re: Why does Debian allow all incoming traffic by default Dan Ritter <dsr@randomstring.org> - 2018-09-22 20:30 +0200
Re: Why does Debian allow all incoming traffic by default Gene Heskett <gheskett@shentel.net> - 2018-09-22 22:20 +0200
Re: Why does Debian allow all incoming traffic by default <tomas@tuxteam.de> - 2018-09-22 22:40 +0200
Re: Why does Debian allow all incoming traffic by default Gene Heskett <gheskett@shentel.net> - 2018-09-22 23:20 +0200
Re: Why does Debian allow all incoming traffic by default Simon Kengelbacher <simon.kengelbacher@mail.ch> - 2018-09-22 23:50 +0200
Re: Why does Debian allow all incoming traffic by default Pascal Hambourg <pascal@plouf.fr.eu.org> - 2018-09-23 00:00 +0200
Re: Why does Debian allow all incoming traffic by default Simon Kengelbacher <simon.kengelbacher@mail.ch> - 2018-09-23 00:20 +0200
SSH X forwarding going awry (Was: Why does Debian allow all incoming traffic by default) Étienne Mollier <etienne.mollier@mailoo.org> - 2018-09-23 11:40 +0200
Re: SSH X forwarding going awry FIXED (Was: Why does Debian allow all incoming traffic by default) Gene Heskett <gheskett@shentel.net> - 2018-09-23 16:10 +0200
Re: SSH X forwarding going awry FIXED (Was: Why does Debian allow all incoming traffic by default) Joe <joe@jretrading.com> - 2018-09-23 23:00 +0200
Re: SSH X forwarding going awry FIXED (Was: Why does Debian allow all incoming traffic by default) Gene Heskett <gheskett@shentel.net> - 2018-09-24 04:50 +0200
Re: Why does Debian allow all incoming traffic by default Jonathan Dowland <jmtd@debian.org> - 2018-09-24 21:00 +0200
Re: Why does Debian allow all incoming traffic by default Pascal Hambourg <pascal@plouf.fr.eu.org> - 2018-09-23 00:00 +0200
Re: Why does Debian allow all incoming traffic by default Jonathan Dowland <jmtd@debian.org> - 2018-09-24 21:00 +0200
Re: Why does Debian allow all incoming traffic by default Joe <joe@jretrading.com> - 2018-09-24 21:30 +0200
Re: Why does Debian allow all incoming traffic by default Jonathan Dowland <jmtd@debian.org> - 2018-09-26 15:50 +0200
Re: Why does Debian allow all incoming traffic by default Joe <joe@jretrading.com> - 2018-09-26 17:10 +0200
Re: Why does Debian allow all incoming traffic by default Jonathan Dowland <jmtd@debian.org> - 2018-09-26 19:30 +0200
Re: Why does Debian allow all incoming traffic by default Dan Purgert <dan@djph.net> - 2018-09-22 15:50 +0200
Re: Why does Debian allow all incoming traffic by default Pascal Hambourg <pascal@plouf.fr.eu.org> - 2018-09-22 16:50 +0200
Re: Why does Debian allow all incoming traffic by default Jonathan Dowland <jmtd@debian.org> - 2018-09-24 20:50 +0200
Re: Why does Debian allow all incoming traffic by default Henning Follmann <hfollmann@itcfollmann.com> - 2018-09-21 15:00 +0200
Re: Why does Debian allow all incoming traffic by default Reco <recoverym4n@gmail.com> - 2018-09-21 18:30 +0200
Re: Why does Debian allow all incoming traffic by default Brian <ad44@cityscape.co.uk> - 2018-09-21 20:20 +0200
Re: Why does Debian allow all incoming traffic by default Reco <recoverym4n@gmail.com> - 2018-09-21 20:40 +0200
Re: Why does Debian allow all incoming traffic by default Brian <ad44@cityscape.co.uk> - 2018-09-21 21:10 +0200
Re: Why does Debian allow all incoming traffic by default deloptes <deloptes@gmail.com> - 2018-09-21 23:20 +0200
Re: Why does Debian allow all incoming traffic by default Reco <recoverym4n@gmail.com> - 2018-09-21 23:40 +0200
Re: Why does Debian allow all incoming traffic by default Dan Purgert <dan@djph.net> - 2018-09-22 00:10 +0200
Re: Why does Debian allow all incoming traffic by default Reco <recoverym4n@gmail.com> - 2018-09-22 09:10 +0200
Re: Why does Debian allow all incoming traffic by default Dan Purgert <dan@djph.net> - 2018-09-22 15:50 +0200
Re: Why does Debian allow all incoming traffic by default Pascal Hambourg <pascal@plouf.fr.eu.org> - 2018-09-22 09:50 +0200
Re: Why does Debian allow all incoming traffic by default Reco <recoverym4n@gmail.com> - 2018-09-22 12:00 +0200
Re: Why does Debian allow all incoming traffic by default Pascal Hambourg <pascal@plouf.fr.eu.org> - 2018-09-22 13:00 +0200
Re: Why does Debian allow all incoming traffic by default Reco <recoverym4n@gmail.com> - 2018-09-22 13:30 +0200
Re: Why does Debian allow all incoming traffic by default <tomas@tuxteam.de> - 2018-09-22 22:00 +0200
Re: Why does Debian allow all incoming traffic by default Stefan Monnier <monnier@iro.umontreal.ca> - 2018-09-22 22:20 +0200
Re: Why does Debian allow all incoming traffic by default Pascal Hambourg <pascal@plouf.fr.eu.org> - 2018-09-22 23:40 +0200
Re: Why does Debian allow all incoming traffic by default Henning Follmann <hfollmann@itcfollmann.com> - 2018-09-22 12:10 +0200
Re: Why does Debian allow all incoming traffic by default Reco <recoverym4n@gmail.com> - 2018-09-22 12:40 +0200
Re: Why does Debian allow all incoming traffic by default Pascal Hambourg <pascal@plouf.fr.eu.org> - 2018-09-22 13:10 +0200
netstat (was: Re: Why does Debian allow all incoming traffic by default) rhkramer@gmail.com - 2018-09-21 20:00 +0200
Re: netstat Reco <recoverym4n@gmail.com> - 2018-09-21 20:20 +0200
Re: netstat rhkramer@gmail.com - 2018-09-22 20:50 +0200
Re: Why does Debian allow all incoming traffic by default Jonathan Dowland <jmtd@debian.org> - 2018-09-24 20:50 +0200
Re: Why does Debian allow all incoming traffic by default Henning Follmann <hfollmann@itcfollmann.com> - 2018-09-24 21:30 +0200
Re: Why does Debian allow all incoming traffic by default Jonathan Dowland <jmtd@debian.org> - 2018-09-26 15:50 +0200
Re: Why does Debian allow all incoming traffic by default Pablo Álvarez Córdoba <pabloalvarezcordoba@protonmail.ch> - 2018-09-21 18:30 +0200
Re: Why does Debian allow all incoming traffic by default Subhadip Ghosh <subhadip.sky@gmail.com> - 2018-09-21 19:30 +0200
Re: Why does Debian allow all incoming traffic by default songbird <songbird@anthive.com> - 2018-09-22 00:10 +0200
Re: Why does Debian allow all incoming traffic by default Joe <joe@jretrading.com> - 2018-09-22 09:40 +0200
Re: Why does Debian allow all incoming traffic by default Pascal Hambourg <pascal@plouf.fr.eu.org> - 2018-09-22 10:40 +0200
Re: Why does Debian allow all incoming traffic by default Joe <joe@jretrading.com> - 2018-09-22 13:20 +0200
Re: Why does Debian allow all incoming traffic by default Pascal Hambourg <pascal@plouf.fr.eu.org> - 2018-09-22 17:10 +0200
Re: Why does Debian allow all incoming traffic by default Joe <joe@jretrading.com> - 2018-09-23 10:50 +0200
Re: Why does Debian allow all incoming traffic by default Pascal Hambourg <pascal@plouf.fr.eu.org> - 2018-09-27 14:00 +0200
Re: Why does Debian allow all incoming traffic by default Jonathan Dowland <jmtd@debian.org> - 2018-09-24 20:50 +0200
Page 2 of 5 — ← Prev page 1 [2] 3 4 5 Next page →
| From | Pascal Hambourg <pascal@plouf.fr.eu.org> |
|---|---|
| Date | 2018-09-22 17:00 +0200 |
| Message-ID | <wARy1-5J3-1@gated-at.bofh.it> |
| In reply to | #200431 |
Le 22/09/2018 à 13:31, Dan Ritter a écrit : > On Sat, Sep 22, 2018 at 12:55:24PM +0200, Pascal Hambourg wrote: >> I do not see how all this replies to my question : This comment was intended to Gene Heskett. >> Why should only TCP inbound responses be allowed ? What about UDP-based >> protocols, ping replies (ICMP echo reply), ICMP error messages, and so on ? > > Given that my entire point was that no firewall policy other > than "configure it yourself" will work, it's really you missing > the point to expect me to describe a complete firewall policy tuned > to your desires. It does not matter what you entire point was, and I do not expect you to describe a complete firewall policy. *You* exposed a supposedly default firewall policy which I happened to find questionable, so I questioned it. You would not have exposed a broken firewall policy on purpose in order to prove your point, would you ?
[toc] | [prev] | [next] | [standalone]
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2018-09-22 20:20 +0200 |
| Message-ID | <wAUFA-7Io-1@gated-at.bofh.it> |
| In reply to | #200439 |
On Saturday 22 September 2018 10:52:40 Pascal Hambourg wrote: > Le 22/09/2018 à 13:31, Dan Ritter a écrit : > > On Sat, Sep 22, 2018 at 12:55:24PM +0200, Pascal Hambourg wrote: > >> I do not see how all this replies to my question : > > This comment was intended to Gene Heskett. > > >> Why should only TCP inbound responses be allowed ? What about > >> UDP-based protocols, ping replies (ICMP echo reply), ICMP error > >> messages, and so on ? > > > > Given that my entire point was that no firewall policy other > > than "configure it yourself" will work, it's really you missing > > the point to expect me to describe a complete firewall policy tuned > > to your desires. > > It does not matter what you entire point was, and I do not expect you > to describe a complete firewall policy. *You* exposed a supposedly > default firewall policy which I happened to find questionable, so I > questioned it. > > You would not have exposed a broken firewall policy on purpose in > order to prove your point, would you ? The point I was trying to make is that in close to 2 decades of my somewhat volatile home setup all on a 192.168.nn.nn address, and with the exception in my sig being the only forward in the dd-wrt rules, and apache2 is running in a sandbox to serve my web page, the only person to gain access to this network and machine was given the username and password to do so by me. My only problem has been someone else logging into one of the wifi's, which are not bridged to this net, but to the internet, and using up more bandwidth in a month than I do. Still under my cap by quite a ways, but... So since I don't use the radios. ATM all the radios are turned off, they aren't needed until one of my boys comes to visit with a smartphone and needs net access. Take it for what you think its worth. It does work for me. IMO, those without a reflashed router running dd-wrt or one of the work-a-likes between their machines and the internet, running all their machine on un-routable addresses, is a bit dumb, asking for trouble, and it will find them sooner rather than later unless they've built their own firewall. Yes, there are $35 routers that can be updated to dd-wrt, I have such a netgear. But dd-wrt has stuff there is not room for in the more memory limited $35 model, 100% configurable port forwarding being on the missing list, so the netgear has logged a couple weeks when the buffalo got forgetfull. Take care Pascal. -- Cheers, Gene Heskett -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [prev] | [next] | [standalone]
| From | Richard Hector <richard@walnut.gen.nz> |
|---|---|
| Date | 2018-09-24 05:20 +0200 |
| Message-ID | <wBpzH-Bc-1@gated-at.bofh.it> |
| In reply to | #200444 |
[Multipart message — attachments visible in raw view] — view raw
On 23/09/18 6:19 AM, Gene Heskett wrote: > the exception in my sig being the only forward in the dd-wrt rules Remote access to your ammo box? Yikes :-) Richard
[toc] | [prev] | [next] | [standalone]
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2018-09-24 05:30 +0200 |
| Message-ID | <wBpJn-FO-3@gated-at.bofh.it> |
| In reply to | #200525 |
On Sunday 23 September 2018 23:13:43 Richard Hector wrote: > On 23/09/18 6:19 AM, Gene Heskett wrote: > > the exception in my sig being the only forward in the dd-wrt rules > > Remote access to your ammo box? Yikes :-) > > Richard Naw, I load them by hand, no internet connection to my powder cache. ;-) I plainly have too many hobbies. ;-) -- Cheers, Gene Heskett -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2018-09-24 09:10 +0200 |
| Message-ID | <wBtai-2Qo-7@gated-at.bofh.it> |
| In reply to | #200526 |
[Multipart message — attachments visible in raw view] — view raw
On Sun, Sep 23, 2018 at 11:22:41PM -0400, Gene Heskett wrote: [...] > Naw, I load them by hand, no internet connection to my powder cache. ;-) But hey, IoT, what could possibly go bang? > I plainly have too many hobbies. ;-) Just combine them ;-) Cheers -- t
[toc] | [prev] | [next] | [standalone]
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2018-09-24 11:00 +0200 |
| Message-ID | <wBuSJ-3F0-21@gated-at.bofh.it> |
| In reply to | #200531 |
On Monday 24 September 2018 03:07:37 tomas@tuxteam.de wrote: > On Sun, Sep 23, 2018 at 11:22:41PM -0400, Gene Heskett wrote: Off topic... > [...] > > > Naw, I load them by hand, no internet connection to my powder cache. > > ;-) > > But hey, IoT, what could possibly go bang? How about old meat in the pot? Its now on its 5th barrel, and is now just past a century old. And I'm always looking for the load that will put 10 shots in one small, ragged hole. > > I plainly have too many hobbies. ;-) > > Just combine them ;-) Old meat in the pot is why I bought a 70 year old Sheldon lathe and cnc'd it. I needed to replace a rusty barrel that wasn't shooting at all accurately, chambered for the Ackley-06, with something a bit easier on the shoulder at the rifle range, a 6.5 Creedmoor. There is a certain cachet to being able to say /I/ did it. Its just part of who I am. I have become good enough at the electronic arts, and the mechanicals too, that I have occasionally claimed to be a joat. But generally, I leave those comments to people that have watched me work. They've come up with some doozies a few times. Couple of parameds the insurance company sent around to see if I was breathing regularly before they'd issue a $50k life policy in 1977, asked to see my feet at the end of a sorta physical. I asked "whats my flat feet got to do with this?", "We heard you could walk on water, so we wanted to see if they were webbed." And he said it with a straight face... LMAO. And remembering that still puts a grin on my face. I expect you, Tomas, could tell similar tales. > Cheers > -- t -- Cheers, Gene Heskett -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2018-09-24 11:40 +0200 |
| Message-ID | <wBvvs-477-1@gated-at.bofh.it> |
| In reply to | #200533 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Mon, Sep 24, 2018 at 04:52:21AM -0400, Gene Heskett wrote: > On Monday 24 September 2018 03:07:37 tomas@tuxteam.de wrote: [...] > And he said it with a straight face... LMAO. And remembering that > still puts a grin on my face. I expect you, Tomas, could tell similar > tales. :-) I fear my tales aren't half as exciting. Afer all, you have ~33% headstart on me :-) Cheers - -- t -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAluosCoACgkQBcgs9XrR2kamVACfWFZbStve+Z1OhlvNo03iDZM6 XY8Anjd0NXste/Gb+AaimiqLZ6cSCMf0 =zYHW -----END PGP SIGNATURE-----
[toc] | [prev] | [next] | [standalone]
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2018-09-24 14:20 +0200 |
| Message-ID | <wBy0i-5FF-13@gated-at.bofh.it> |
| In reply to | #200534 |
On Monday 24 September 2018 05:36:42 tomas@tuxteam.de wrote: > On Mon, Sep 24, 2018 at 04:52:21AM -0400, Gene Heskett wrote: > > On Monday 24 September 2018 03:07:37 tomas@tuxteam.de wrote: > > I fear my tales aren't half as exciting. Afer all, you have ~33% > headstart on me :-) > True, but the life lesson is to remember the good times, they make the bad things that are also part of life, tolerable. I remember, but don't dwell at length, burying my first wife at age 34 in '68 from a stroke, and the loss of the 3 children she so enthusiasticly gave me over the last 20 years, two different cancers and a mix of scotch and Kia. So there are good times, and bad times. Some let the bad times overpower them, and you can't do that for long and survive as a careing human being. > Cheers > -- t Take care, Tomas. -- Cheers, Gene Heskett -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [prev] | [next] | [standalone]
| From | Dan Ritter <dsr@randomstring.org> |
|---|---|
| Date | 2018-09-22 20:30 +0200 |
| Message-ID | <wAUPf-7Li-1@gated-at.bofh.it> |
| In reply to | #200439 |
On Sat, Sep 22, 2018 at 04:52:40PM +0200, Pascal Hambourg wrote: > Le 22/09/2018 à 13:31, Dan Ritter a écrit : > > On Sat, Sep 22, 2018 at 12:55:24PM +0200, Pascal Hambourg wrote: > > > I do not see how all this replies to my question : > > This comment was intended to Gene Heskett. > > > > Why should only TCP inbound responses be allowed ? What about UDP-based > > > protocols, ping replies (ICMP echo reply), ICMP error messages, and so on ? > > > > Given that my entire point was that no firewall policy other > > than "configure it yourself" will work, it's really you missing > > the point to expect me to describe a complete firewall policy tuned > > to your desires. > > It does not matter what you entire point was, and I do not expect you to > describe a complete firewall policy. *You* exposed a supposedly default > firewall policy which I happened to find questionable, so I questioned it. You should certainly find it questionable, > You would not have exposed a broken firewall policy on purpose in order to > prove your point, would you ? Wouldn't I? I am explicitly describing a firewire policy for the sake of argument, and in no way advocating it. In fact, the ENTIRE FREAKING POINT WHICH I HAVE MADE TWICE NOW is that I am *not* advocating it. Do not use this firewall policy. If Debian were to do the stupid thing of instituting a default firewall policy other than what it doesn't do now, I would hope for a several month long debate in debian-developers about what it should be. -dsr-
[toc] | [prev] | [next] | [standalone]
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2018-09-22 22:20 +0200 |
| Message-ID | <wAWxH-mM-13@gated-at.bofh.it> |
| In reply to | #200445 |
On Saturday 22 September 2018 14:27:44 Dan Ritter wrote: > On Sat, Sep 22, 2018 at 04:52:40PM +0200, Pascal Hambourg wrote: > > Le 22/09/2018 à 13:31, Dan Ritter a écrit : > > > On Sat, Sep 22, 2018 at 12:55:24PM +0200, Pascal Hambourg wrote: > > > > I do not see how all this replies to my question : > > > > This comment was intended to Gene Heskett. > > > > > > Why should only TCP inbound responses be allowed ? What about > > > > UDP-based protocols, ping replies (ICMP echo reply), ICMP error > > > > messages, and so on ? > > > > > > Given that my entire point was that no firewall policy other > > > than "configure it yourself" will work, it's really you missing > > > the point to expect me to describe a complete firewall policy > > > tuned to your desires. > > > > It does not matter what you entire point was, and I do not expect > > you to describe a complete firewall policy. *You* exposed a > > supposedly default firewall policy which I happened to find > > questionable, so I questioned it. > > You should certainly find it questionable, > > > You would not have exposed a broken firewall policy on purpose in > > order to prove your point, would you ? > > Wouldn't I? > > I am explicitly describing a firewire policy for the sake of > argument, and in no way advocating it. In fact, the ENTIRE > FREAKING POINT WHICH I HAVE MADE TWICE NOW is that I am *not* > advocating it. > > Do not use this firewall policy. If Debian were to do the stupid > thing of instituting a default firewall policy other than what > it doesn't do now, I would hope for a several month long debate > in debian-developers about what it should be. > > -dsr- I would certainly hope so, AND give due consideration to just how big a headache any change means for the users. Rant mode on They have over the last two "upgrades" from wheezy to jessie and on to stretch, totally disabled any attempts to forward x to another machine, I suppose based on someones idea of security and my questions about fixing that pain in the arse, so it works once again, have been totally ignored. They HAVE been asked, but never acknowledged with the courtesy of even a reply with a link to a tut. We build (some buy) computers for us to use, and now if I want to edit gcode on another machine from a comfortable office chair, I am restricted to nano. Or going to that machine and standing at its operating position just to be able to use a decent editor. That is not fun when one is 2 weeks short of his 84th, and have 2 crushed disc's in my lower back limiting me to not more than an hour/day. Its very hard to concentrate on the code when your back is screaming at you. But someone with the power to "make it so" hides behind the word security, never deigning to explain it where the user public gets to read it. There is something drastically wrong with that picture when we don't get a choice, or a say in it. /rant -- Cheers, Gene Heskett -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2018-09-22 22:40 +0200 |
| Message-ID | <wAWR3-t5-1@gated-at.bofh.it> |
| In reply to | #200450 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Sat, Sep 22, 2018 at 04:15:42PM -0400, Gene Heskett wrote: [...] > They have over the last two "upgrades" from wheezy to jessie and on to > stretch, totally disabled any attempts to forward x to another machine, Just a tip: there's "ssh -X" or better "ssh -Y" for that. Perhaps it suits your needs... Cheers - -- tomás -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAlump78ACgkQBcgs9XrR2kaymgCdH3eBDppz4R0+AWQbYe8/ssP/ CUoAn29066dLQ3B1Go8NbhjXy/i+aPye =simb -----END PGP SIGNATURE-----
[toc] | [prev] | [next] | [standalone]
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2018-09-22 23:20 +0200 |
| Message-ID | <wAXtL-V6-3@gated-at.bofh.it> |
| In reply to | #200451 |
On Saturday 22 September 2018 16:36:15 tomas@tuxteam.de wrote: > On Sat, Sep 22, 2018 at 04:15:42PM -0400, Gene Heskett wrote: > > [...] > > > They have over the last two "upgrades" from wheezy to jessie and on > > to stretch, totally disabled any attempts to forward x to another > > machine, > > Just a tip: there's "ssh -X" or better "ssh -Y" for that. Perhaps it > suits your needs... > > Cheers > -- tomás Been using -Y for years, Tomas, doesn't work for newer than wheezy. -- Cheers, Gene Heskett -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [prev] | [next] | [standalone]
| From | Simon Kengelbacher <simon.kengelbacher@mail.ch> |
|---|---|
| Date | 2018-09-22 23:50 +0200 |
| Message-ID | <wAXWN-15E-1@gated-at.bofh.it> |
| In reply to | #200451 |
Am Samstag, den 22.09.2018, 22:36 +0200 schrieb tomas@tuxteam.de: > On Sat, Sep 22, 2018 at 04:15:42PM -0400, Gene Heskett wrote: > > [...] > > > They have over the last two "upgrades" from wheezy to jessie and on > > to > > stretch, totally disabled any attempts to forward x to another > > machine, > > Just a tip: there's "ssh -X" or better "ssh -Y" for that. Perhaps it > suits your needs... > > Cheers > -- tomás In this case I would prefer sshfs as "ssh -X" can be somewhat laggy when you don't have a fast connection.
[toc] | [prev] | [next] | [standalone]
| From | Pascal Hambourg <pascal@plouf.fr.eu.org> |
|---|---|
| Date | 2018-09-23 00:00 +0200 |
| Message-ID | <wAY6t-18Q-7@gated-at.bofh.it> |
| In reply to | #200455 |
Le 22/09/2018 à 23:35, Simon Kengelbacher a écrit : > Am Samstag, den 22.09.2018, 22:36 +0200 schrieb tomas@tuxteam.de: >> On Sat, Sep 22, 2018 at 04:15:42PM -0400, Gene Heskett wrote: >> >>> They have over the last two "upgrades" from wheezy to jessie and on >>> to >>> stretch, totally disabled any attempts to forward x to another >>> machine, >> >> Just a tip: there's "ssh -X" or better "ssh -Y" for that. Perhaps it >> suits your needs... > > In this case I would prefer sshfs as "ssh -X" can be somewhat laggy > when you don't have a fast connection. sshfs to run a remote shell and X programs ?
[toc] | [prev] | [next] | [standalone]
| From | Simon Kengelbacher <simon.kengelbacher@mail.ch> |
|---|---|
| Date | 2018-09-23 00:20 +0200 |
| Message-ID | <wAYpP-1u7-1@gated-at.bofh.it> |
| In reply to | #200457 |
Am Samstag, den 22.09.2018, 23:58 +0200 schrieb Pascal Hambourg: > Le 22/09/2018 à 23:35, Simon Kengelbacher a écrit : > > Am Samstag, den 22.09.2018, 22:36 +0200 schrieb tomas@tuxteam.de: > > > On Sat, Sep 22, 2018 at 04:15:42PM -0400, Gene Heskett wrote: > > > > > > > They have over the last two "upgrades" from wheezy to jessie > > > > and on > > > > to > > > > stretch, totally disabled any attempts to forward x to another > > > > machine, > > > > > > Just a tip: there's "ssh -X" or better "ssh -Y" for that. Perhaps > > > it > > > suits your needs... > > > > In this case I would prefer sshfs as "ssh -X" can be somewhat laggy > > when you don't have a fast connection. > > sshfs to run a remote shell and X programs ? > no, to edit the file on your local environment
[toc] | [prev] | [next] | [standalone]
| From | Étienne Mollier <etienne.mollier@mailoo.org> |
|---|---|
| Date | 2018-09-23 11:40 +0200 |
| Subject | SSH X forwarding going awry (Was: Why does Debian allow all incoming traffic by default) |
| Message-ID | <wB91T-7Fn-1@gated-at.bofh.it> |
| In reply to | #200450 |
Good Day, On 9/22/18 10:15 PM, Gene Heskett wrote: > I would certainly hope so, AND give due consideration to just > how big a headache any change means for the users. That is an understatement, this headache thing. > They have over the last two "upgrades" from wheezy to jessie > and on to stretch, totally disabled any attempts to forward x > to another machine, I suppose based on someones idea of > security and my questions about fixing that pain in the arse, > so it works once again, have been totally ignored. They HAVE > been asked, but never acknowledged with the courtesy of even a > reply with a link to a tut. If this can help, since Debian Jessie, SSH server is configured by default to listen to both IPv4 and v6 interfaces. When v6 links are unavailable, for /some reason/ (I don't recall the details), X forwarding attempts are prevented, but normal SSH continues as usual (with a warning about X11 forwarding having failed to start). To fix this, two different solutions are available: - make IPv6 interfaces available on SSH server side (and maybe on client side too, I haven't tested that solution extensively, it just works as is at home); - or simply configure sshd to listen only on IPv4 with the following directive in “/etc/ssh/sshd_config”: AddressFamiliy inet By default it is set to “any”, and X forwarding doesn't seem to like not finding any IPv6 interface at all. No idea if this is intelligent security design, or just a bug, but that caused quite some headaches in IPv4 only networks indeed. Maybe your problem is unrelated, especially if IPv6 is already available in your network, yet I hope this helps. Kind Regards, -- Étienne Mollier <etienne.mollier@mailoo.org> Or it is just xauth that is unavailable on server side, this thing also happens sometimes...
[toc] | [prev] | [next] | [standalone]
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2018-09-23 16:10 +0200 |
| Subject | Re: SSH X forwarding going awry FIXED (Was: Why does Debian allow all incoming traffic by default) |
| Message-ID | <wBdfb-1NS-11@gated-at.bofh.it> |
| In reply to | #200471 |
On Sunday 23 September 2018 05:35:41 Étienne Mollier wrote: > Good Day, > > On 9/22/18 10:15 PM, Gene Heskett wrote: > > I would certainly hope so, AND give due consideration to just > > how big a headache any change means for the users. > > That is an understatement, this headache thing. > > > They have over the last two "upgrades" from wheezy to jessie > > and on to stretch, totally disabled any attempts to forward x > > to another machine, I suppose based on someones idea of > > security and my questions about fixing that pain in the arse, > > so it works once again, have been totally ignored. They HAVE > > been asked, but never acknowledged with the courtesy of even a > > reply with a link to a tut. > > If this can help, since Debian Jessie, SSH server is configured > by default to listen to both IPv4 and v6 interfaces. When v6 > links are unavailable, for /some reason/ (I don't recall the > details), X forwarding attempts are prevented, but normal SSH > continues as usual (with a warning about X11 forwarding having > failed to start). > > To fix this, two different solutions are available: > > - make IPv6 interfaces available on SSH server side (and > maybe on client side too, I haven't tested that solution > extensively, it just works as is at home); > > - or simply configure sshd to listen only on IPv4 with the > following directive in “/etc/ssh/sshd_config”: > > AddressFamiliy inet On the pi-3b, running jessie, that line did not exist. Added it, restarted ssh, tried geany while logged into the pi with ssh, AND IT WORKS! Thats the important app, synaptic-pkexec still doesn't. ============= pi@picnc:~ $ synaptic-pkexec ==== AUTHENTICATING FOR com.ubuntu.pkexec.synaptic === Authentication is required to run the Synaptic Package Manager Multiple identities can be used for authentication: 1. ,,, (pi) 2. root Choose identity to authenticate as (1-2): 1 Password: polkit-agent-helper-1: error response to PolicyKit daemon: GDBus.Error:org.freedesktop.PolicyKit1.Error.Failed: No session for cookie ==== AUTHENTICATION FAILED === Error executing command as another user: Not authorized This incident has been reported. pi@picnc:~ $ synaptic-pkexec ==== AUTHENTICATING FOR com.ubuntu.pkexec.synaptic === Authentication is required to run the Synaptic Package Manager Multiple identities can be used for authentication: 1. ,,, (pi) 2. root Choose identity to authenticate as (1-2): 2 Password: polkit-agent-helper-1: pam_authenticate failed: Authentication failure ==== AUTHENTICATION FAILED === Error executing command as another user: Not authorized This incident has been reported. ================================================= So I'm still restricted to doing updates with apt. not a show stopper, but the rock64 can do that 20x faster. In this case I believe pam is the culprit. And again, the docs are top secret... Spit... Unforch, it did not work on the rock64, "cannot open display". It has other problems too, so its not usable to me yet. And until support is forthcoming from the armbian camp, its likely I've wasted 100+ dollars for 2 of them. Vastly more powerfull than a pi, its severely crippled by its broken usb-3 port, and total absence of a usable SPI driver, and docs on how to use what it does have. > By default it is set to “any”, and X forwarding doesn't seem > to like not finding any IPv6 interface at all. > > No idea if this is intelligent security design, or just a bug, > but that caused quite some headaches in IPv4 only networks > indeed. Indeed. Other that the local net here at home the nearest ipv6 address is proabably 100 miles southwest in Charleston, or 150 miles northeast in Pittsburg PA. I don't think it even makes it thru my cable modem. I've found before that ipv6 stuff, in an ipv4 environment is a right pain in the arse. My whole network here, hiding behind dd-wrt, is ipv4 only. My /etc/hosts files have had the ipv6 stuffs commented out as it greatly simplifies the internal networking setups. ipv6, when and if it ever arrives in small town USA, it may well be a working thing, but until its available from my cable modem, it will continue to be Excedrin headache #1 here. Sorely needed: a single point config option to shut it off. > Maybe your problem is unrelated, especially if IPv6 is already > available in your network, yet I hope this helps. > > Kind Regards, And many many thanks from me, and likely from others whose ipv6 connectivity is hundreds of miles away. -- Cheers, Gene Heskett -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [prev] | [next] | [standalone]
| From | Joe <joe@jretrading.com> |
|---|---|
| Date | 2018-09-23 23:00 +0200 |
| Subject | Re: SSH X forwarding going awry FIXED (Was: Why does Debian allow all incoming traffic by default) |
| Message-ID | <wBjDX-5n4-5@gated-at.bofh.it> |
| In reply to | #200490 |
On Sun, 23 Sep 2018 09:55:48 -0400 Gene Heskett <gheskett@shentel.net> wrote: > synaptic-pkexec still doesn't. > > > So I'm still restricted to doing updates with apt. > not a show stopper, but the rock64 can do that 20x faster. > I vaguely recall having trouble with this on sid years ago, and completely failing to fix it, so I changed the launch to gksudo synaptic, and it's still that way today. -- Joe
[toc] | [prev] | [next] | [standalone]
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2018-09-24 04:50 +0200 |
| Subject | Re: SSH X forwarding going awry FIXED (Was: Why does Debian allow all incoming traffic by default) |
| Message-ID | <wBp6F-cN-1@gated-at.bofh.it> |
| In reply to | #200516 |
On Sunday 23 September 2018 16:55:39 Joe wrote: > On Sun, 23 Sep 2018 09:55:48 -0400 > > Gene Heskett <gheskett@shentel.net> wrote: > > synaptic-pkexec still doesn't. > > > > > > > > So I'm still restricted to doing updates with apt. > > not a show stopper, but the rock64 can do that 20x faster. > > I vaguely recall having trouble with this on sid years ago, and > completely failing to fix it, so I changed the launch to gksudo > synaptic, and it's still that way today. I'll be dipped Joe, it works! I am suitably amazed. Thank you indeed. -- Cheers, Gene Heskett -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [prev] | [next] | [standalone]
| From | Jonathan Dowland <jmtd@debian.org> |
|---|---|
| Date | 2018-09-24 21:00 +0200 |
| Message-ID | <wBEfn-Mb-5@gated-at.bofh.it> |
| In reply to | #200450 |
On Sat, Sep 22, 2018 at 04:15:42PM -0400, Gene Heskett wrote: >But someone with the power to "make it so" hides behind the word >security, never deigning to explain it where the user public gets to >read it. There is something drastically wrong with that picture when we >don't get a choice, or a say in it. Please assume good faith on the part of the developers who have made whichever change it is that has broken the behaviour that you relied upon in prior Debian releases, did so for well-defined reasons. It's not fair to the developers, likely volunteers, to be described in negative terms such as "hiding" and so on. I don't know to where you have asked the questions that were totally ignored in your words, but a reasonable place to do so would be this very mailing list here. Please feel free to ask again. >/rant Indeed. -- ⢀⣴⠾⠻⢶⣦⠀ ⣾⠁⢠⠒⠀⣿⡁ Jonathan Dowland ⢿⡄⠘⠷⠚⠋⠀ https://jmtd.net ⠈⠳⣄⠀⠀⠀⠀ Please do not CC me, I am subscribed to the list.
[toc] | [prev] | [next] | [standalone]
Page 2 of 5 — ← Prev page 1 [2] 3 4 5 Next page →
Back to top | Article view | linux.debian.user
csiph-web