|
From: Martin M. <mm...@si...> - 2001-09-15 11:34:44
|
On Sat, Sep 15, 2001 at 01:20:45PM +0200, Friedrich Lobenstock wrote: > If you run the same CD for 1-2 years you are out of luck anyway, because > you're hopefully out of date - what, if one of the daemons or the kernel > has a bug? Well, most of them have a quite minimal setup, they are just NAT boxes, that only allow ssh from the internal network ... so there aren't any deamons to be out of date, and I know of no kernel-bug, that allows a remote exploit except a DOS attack. Well in case that happens, just hit the reset button and you're set. > I would suggest updating the CD _at least_ every 6 month. > How about the CD-ROM drives themself, how long do the work flawlessly? > If they only work for 1-2 year what's the cost of a new drive? Only about > $47 / 100 DM / 700 ATS. That's _nothing_ compared to the costs when you're > cracked. It's not the cost of a cdrom drive, or the CDROM, it's the maintenance cost, to have someone change the drive for you and have a downtime. Most of the people I made the CDs for, have _no_ clue about hardware or computers except using a webbrowser, and they're often a couple of hundreds of kilometers away. So the onyl thing I can do for them is send them a CD via mail, but they have to get the hardware serviced themselves, which involves paying quite a lot for changing a CDROM. > How? A descent firewall should be the point of attack not the systems > behind it. Do you use ip-port-forwarding? Well, just NAT behind a single ip-address, no daemons, no other stuff. bye MM Martin Mueller Phone: +49 39298 4125 e-mail: mm...@si... ICQ: 99023536 mm...@lu... PGP/GPG mail welcome, keys as well other stuff at: http://themm.net |