icon Get the most out of Surmunity, read our tips here! Need an interesting blog to read? You've got to read the Surpass Blog! | Welcome! Please register to access all of our features.

» Surpass Web Hosting Forums » Surpass Customers » The Sofa » Discuss [Policy change] Jailed SSH access, now free.

Reply
 
LinkBack Thread Tools Search this Thread Rate Thread
Old January 27th, 2007, 9:53 AM   #37 (permalink)
Registered User
Fresh Surpasser
 
Joined in Apr 2005
27 posts
Gave thanks: 1
Thanked 1 Time in 1 Post
SSH in it's self is hardly a security risk, it's just a means of connecting computers together. Once connected to your webspace via SSH you are not given a normal BASH promt but are put into a little program call jailshell. In jail shell you can't do all the things you would be able to do with a normal BASH shell, making it secure but limited. I still use it as it's good for mass moving of files, changing file permissions, renaming etc which just can't be done with FTP.

I for one welcome the change in policy, and hope it will be extended to reseller sub-accounts in the future.
bluenova is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old January 27th, 2007, 6:30 PM   #38 (permalink)
Marketing Maven
Surpass Staff
 
Kayla's Avatar
 
Joined in May 2003
Lives in Orlando
24,749 posts
Gave thanks: 946
Thanked 806 times
I don't think anyone is understanding this yet. I'll try again, though we normally keep most security info private, because what's security if all the details are out in the open? In this case I will just spill the beans.

I was talking with other admins here and their biggest concern is that even in a jailed SSH environment, brute force attacks on remote servers can still be placed. There is a chance that our server could then be involved in an incident where proof of ID may be required by law enforcement. This has even occurred before, it's not new to us.

Some of our users also use weak passwords to begin with, what if they then have SSH access with that same password, and they get brute forced themselves, then the attacker uses their account.

This is basically adding another benefit for customers, but also another way (besides the mentioned cron jobs) that servers can be abused by users themselves or third parties. With that in mind, why is it so hard to give us an ID? If you aren't up to anything, have a good password, and keep your own site secure and up to date, there is nothing to worry about. You do not have anything to worry about by giving us your ID, it is in safe hands. Maybe other hosts that don't require it are taking security more lightly than us. That's their business..
__________________
Follow Surpass on Twitter and Facebook
Check out the Surpass Blog



Kayla is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
These users thank Kayla for this great post!
Brandonnn (January 27th, 2007), DewKnight (January 27th, 2007), The Wicked Flea (February 6th, 2007)
Old January 27th, 2007, 6:34 PM   #39 (permalink)
pineapples are sharp
Super #1
 
Brandonnn's Avatar
 
Joined in Dec 2005
5,777 posts
Gave thanks: 147
Thanked 151 times
Quote:
Originally Posted by Kayla View Post
With that in mind, why is it so hard to give us an ID? If you aren't up to anything, have a good password, and keep your own site secure and up to date, there is nothing to worry about. You do not have anything to worry about by giving us your ID, it is in safe hands. Maybe other hosts that don't require it are taking security more lightly than us. That's their business..
PUT VERY NICELY
__________________
poof
Brandonnn is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old January 28th, 2007, 1:53 AM   #40 (permalink)
Surpass Fan
Comfy Contributor
 
jfacade's Avatar
 
Joined in May 2004
Lives in VA
106 posts
Gave thanks: 1
Thanked 0 times
Cool

Quote:
Originally Posted by Kayla View Post
Jailed SSH access is now free on all shared and reseller plans except:

Power Shared
Bronze Reseller
(These two plans will still require the $20 one time fee to enable access.)
Couldn't you make it free for these accounts if you pay yearly... then it truly would be ALL!

Good Start Though!
__________________
JFACADE


Server: ???
Life is short eat your dessert first!
jfacade is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old February 5th, 2007, 4:50 PM   #41 (permalink)
Registered User
Fresh Surpasser
 
Joined in Jul 2006
6 posts
Gave thanks: 0
Thanked 0 times
Quote:
Originally Posted by Kayla View Post
Jailed SSH access is now free on all shared and reseller plans except:

Power Shared
Bronze Reseller
(These two plans will still require the $20 one time fee to enable access.)
What about OC5? How do I use SSH on OC5?
nricciardi is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old February 7th, 2007, 11:15 AM   #42 (permalink)
Registered User
Fresh Surpasser
 
shirkahn's Avatar
 
Joined in Feb 2007
1 posts
Gave thanks: 0
Thanked 0 times
I've got a legacy plan. I'm guessing that the setup fee will apply to me as well?

shirkahnbusoutoshi.net
__________________
==========================
Puff the fractal dragon was written in C,
And frolicked while processes switched in mainframe memory......
==========================
shirkahn is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old February 8th, 2007, 11:13 PM   #43 (permalink)
Registered User
Seasoned Poster
 
Joined in Feb 2007
65 posts
Gave thanks: 4
Thanked 5 times
Quote:
Originally Posted by jfacade View Post
Couldn't you make it free for these accounts if you pay yearly... then it truly would be ALL!

Good Start Though!
That would certainly be nice. I wouldn't even mind the ID requirement.
decx is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old February 8th, 2007, 11:34 PM   #44 (permalink)
Marketing Maven
Surpass Staff
 
Kayla's Avatar
 
Joined in May 2003
Lives in Orlando
24,749 posts
Gave thanks: 946
Thanked 806 times
Quote:
Originally Posted by nricciardi View Post
What about OC5? How do I use SSH on OC5?
It's free for you, just need to put in the request.
__________________
Follow Surpass on Twitter and Facebook
Check out the Surpass Blog



Kayla is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old February 8th, 2007, 11:35 PM   #45 (permalink)
Marketing Maven
Surpass Staff
 
Kayla's Avatar
 
Joined in May 2003
Lives in Orlando
24,749 posts
Gave thanks: 946
Thanked 806 times
Quote:
Originally Posted by shirkahn View Post
I've got a legacy plan. I'm guessing that the setup fee will apply to me as well?

shirkahnbusoutoshi.net
Which plan exactly is it that you have?

Please send an email to me at kayla(at)surpasshosting.com.
__________________
Follow Surpass on Twitter and Facebook
Check out the Surpass Blog



Kayla is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On