|
|
#37 (permalink) |
|
Registered User
Fresh Surpasser
Joined in Apr 2005
27 posts
Gave thanks: 1
Thanked 1 Time in 1 Post
|
SSH in it's self is hardly a security risk, it's just a means of connecting computers together. Once connected to your webspace via SSH you are not given a normal BASH promt but are put into a little program call jailshell. In jail shell you can't do all the things you would be able to do with a normal BASH shell, making it secure but limited. I still use it as it's good for mass moving of files, changing file permissions, renaming etc which just can't be done with FTP.
I for one welcome the change in policy, and hope it will be extended to reseller sub-accounts in the future. |
|
|
|
|
|
#38 (permalink) |
|
Marketing Maven
Surpass Staff
Joined in May 2003
Lives in Orlando
24,749 posts
Gave thanks: 946
Thanked 806 times
|
I don't think anyone is understanding this yet. I'll try again, though we normally keep most security info private, because what's security if all the details are out in the open? In this case I will just spill the beans.
I was talking with other admins here and their biggest concern is that even in a jailed SSH environment, brute force attacks on remote servers can still be placed. There is a chance that our server could then be involved in an incident where proof of ID may be required by law enforcement. This has even occurred before, it's not new to us. Some of our users also use weak passwords to begin with, what if they then have SSH access with that same password, and they get brute forced themselves, then the attacker uses their account. This is basically adding another benefit for customers, but also another way (besides the mentioned cron jobs) that servers can be abused by users themselves or third parties. With that in mind, why is it so hard to give us an ID? If you aren't up to anything, have a good password, and keep your own site secure and up to date, there is nothing to worry about. You do not have anything to worry about by giving us your ID, it is in safe hands. Maybe other hosts that don't require it are taking security more lightly than us. That's their business..
__________________
|
|
|
|
| These users thank Kayla for this great post! | Brandonnn (January 27th, 2007), DewKnight (January 27th, 2007), The Wicked Flea (February 6th, 2007) |
|
|
#39 (permalink) | |
|
pineapples are sharp
Super #1
Joined in Dec 2005
5,777 posts
Gave thanks: 147
Thanked 151 times
|
Quote:
__________________
poof
|
|
|
|
|
|
|
#40 (permalink) | |
|
Surpass Fan
Comfy Contributor
Joined in May 2004
Lives in VA
106 posts
Gave thanks: 1
Thanked 0 times
|
Quote:
Good Start Though!
__________________
JFACADE Server: ??? Life is short eat your dessert first! |
|
|
|
|
|
|
#42 (permalink) |
|
Registered User
Fresh Surpasser
Joined in Feb 2007
1 posts
Gave thanks: 0
Thanked 0 times
|
I've got a legacy plan. I'm guessing that the setup fee will apply to me as well?
shirkahn busoutoshi.net
__________________
========================== Puff the fractal dragon was written in C, And frolicked while processes switched in mainframe memory...... ========================== |
|
|
|
|
|
#45 (permalink) | |
|
Marketing Maven
Surpass Staff
Joined in May 2003
Lives in Orlando
24,749 posts
Gave thanks: 946
Thanked 806 times
|
Quote:
Please send an email to me at kayla(at)surpasshosting.com.
__________________
|
|
|
|
|