|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
Re: [suse-security] Why Install Telnet by Default?
From: Marcus Meissner (meissner
suse.de)
Date: Thu Dec 08 2005 - 01:23:28 CST
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
On Thu, Dec 08, 2005 at 01:18:34AM -0500, WebDev wrote:
> I am not a security expert by any means, nor necessarily a "purist", when it
> comes to installing only the apps I need to run. I do install some apps that
> I want to tinker with, even though I may not use them regularly. However, I
> understand that we should avoid using telnet because it is "insecure". Yet,
> telnet is still installed by default on SUSE, when the secure alternatives
> seem to be more appropriate. I assume there is a reason for this.
>
> I ask, because I deselected telnet when I installed SUSE 10.0, and duringa
> repair process, my system reported that telnet was a core app. If we should
> avoid using it, shouldn't we avoid installing it to begin with?
The telnet protocol is unsafe, telnet the program is just another program
and can be used "safe" locally or for non-login purposes.
Ciao, Marcus
--
Check the headers for your unsubscription address
For additional commands, e-mail: suse-security-help
suse.com
Security-related bug reports go to security
suse.de, not here
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]