Re: Telnet and FTP to Historic

Christian Huitema <huitema@huitema.net> Thu, 03 December 2020 06:47 UTC

Return-Path: <huitema@huitema.net>
X-Original-To: ietf@ietfa.amsl.com
Delivered-To: ietf@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E204E3A064A for <ietf@ietfa.amsl.com>; Wed, 2 Dec 2020 22:47:15 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.89
X-Spam-Level:
X-Spam-Status: No, score=-1.89 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, NICE_REPLY_A=-0.001, SPF_HELO_NONE=0.001, T_SPF_PERMERROR=0.01] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id kFk0mMkTgsSK for <ietf@ietfa.amsl.com>; Wed, 2 Dec 2020 22:47:14 -0800 (PST)
Received: from mx36-out10.antispamcloud.com (mx36-out10.antispamcloud.com [209.126.121.30]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AEC083A0644 for <ietf@ietf.org>; Wed, 2 Dec 2020 22:47:14 -0800 (PST)
Received: from xse316.mail2web.com ([66.113.197.62] helo=xse.mail2web.com) by mx169.antispamcloud.com with esmtp (Exim 4.92) (envelope-from <huitema@huitema.net>) id 1kkiOT-0004fa-JS for ietf@ietf.org; Thu, 03 Dec 2020 07:47:12 +0100
Received: from xsmtp21.mail2web.com (unknown [10.100.68.60]) by xse.mail2web.com (Postfix) with ESMTPS id 4CmmV50Skwz7qnQ for <ietf@ietf.org>; Wed, 2 Dec 2020 22:42:21 -0800 (PST)
Received: from [10.5.2.49] (helo=xmail11.myhosting.com) by xsmtp21.mail2web.com with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:256) (Exim 4.92) (envelope-from <huitema@huitema.net>) id 1kkiJo-00068t-UY for ietf@ietf.org; Wed, 02 Dec 2020 22:42:20 -0800
Received: (qmail 25918 invoked from network); 3 Dec 2020 06:42:20 -0000
Received: from unknown (HELO [192.168.1.106]) (Authenticated-user:_huitema@huitema.net@[172.58.43.42]) (envelope-sender <huitema@huitema.net>) by xmail11.myhosting.com (qmail-ldap-1.03) with ESMTPA for <cabo@tzi.org>; 3 Dec 2020 06:42:20 -0000
Subject: Re: Telnet and FTP to Historic
To: Mark Andrews <marka@isc.org>, Stephen Farrell <stephen.farrell@cs.tcd.ie>
Cc: Phillip Hallam-Baker <phill@hallambaker.com>, IETF Discussion Mailing List <ietf@ietf.org>, Michael Richardson <mcr+ietf@sandelman.ca>, "John C. Klensin" <john-ietf@jck.com>, Carsten Bormann <cabo@tzi.org>
References: <AA1E0A8464BC45FB4FA44684@PSB> <2D63A357-E253-462C-864D-2BF96D3E2E18@tzi.org> <F4CD3381C5D0E24C91FC4A91@PSB> <20201201030759.GJ5364@mit.edu> <5720F933910C959C9278EBCF@PSB> <CAMm+LwgpcLxSdzgfJy2441hjNWP=Fui-f8Oq1bZB=2QdZeOUNQ@mail.gmail.com> <0c5a4935-f0b6-4b86-dc0e-3b4466bc09a4@nostrum.com> <F1FF9720-AA72-4B92-ABE7-6E0E875059BA@tzi.org> <16446.1606931808@localhost> <CAMm+Lwj51YLpwZLCxsVeg=6tBwaG845Kg4WN4hbA8Bv=pjjKrQ@mail.gmail.com> <C9D1281FC33DACED4FB385A3@PSB> <6B1BC8E3-913D-4683-A463-AD6099103749@sobco.com> <08035677-a35e-45ed-39e9-b01df6d01010@cs.tcd.ie> <AD188A77-24EA-4C63-B9A8-2F901969269D@isc.org> <db927a1a-a723-93d2-fa47-eb50c3a3fe09@cs.tcd.ie> <3FF23E6F-65A3-44C0-9A49-F0C7D4042378@isc.org>
From: Christian Huitema <huitema@huitema.net>
Message-ID: <c9483300-b1b9-0244-542e-1071457da567@huitema.net>
Date: Wed, 02 Dec 2020 22:42:19 -0800
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:78.0) Gecko/20100101 Thunderbird/78.5.0
MIME-Version: 1.0
In-Reply-To: <3FF23E6F-65A3-44C0-9A49-F0C7D4042378@isc.org>
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Transfer-Encoding: 8bit
Content-Language: en-US
X-Originating-IP: 66.113.197.62
X-Spampanel-Domain: xsmtpout.mail2web.com
X-Spampanel-Username: 66.113.197.0/24
Authentication-Results: antispamcloud.com; auth=pass smtp.auth=66.113.197.0/24@xsmtpout.mail2web.com
X-Spampanel-Outgoing-Class: unsure
X-Spampanel-Outgoing-Evidence: Combined (0.60)
X-Recommended-Action: accept
X-Filter-ID: Mvzo4OR0dZXEDF/gcnlw0ecN11dQIc3aKzz9DU5dqGmpSDasLI4SayDByyq9LIhVnxTeLFuoYWyY DoDtRECY8UTNWdUk1Ol2OGx3IfrIJKywOmJyM1qr8uRnWBrbSAGDAzc5Jb/eaE0k3pqeq35lKbgN zB/4Jkrw1eDLcif59fs6tR4SHlEKhYJO0q0oJCNFU7Tmz6iKnkQL9gqsxD347235Nhqq+/HvroPq 8GSPg+60/QPNqXybIny9WGhadIo/1Ofn8DBBgDynfYj8uZOR2ryme9ldZJ7uNXfg/GfS8fUvP/L5 rCqHDsKZM+xa1iwJX+gRCHfMVnsAk591zk0uilUI+ZL4xWiN8NS6C+dmX6OEdA4u1aThyWrQ/ou2 +v/lmX4Em37yFgrCB6NHRn1g+f3uncIqYSL3lhh5c81YyJqFoLZMmkWsaurVZfvqROaDnDtHb8z5 dpPkEuJ8Snwqla7jUnW3hy14Yji8fo+4xCnSRo4Rcu5Z37rMuDjCny5fE9ykbJ7I9co1MAEE3ruN Xsm8UJsAPvDcVSKtDCYkioPY5Qx4fJOk03R5fJtf/Dv/dkIzS7m4GUpXCY1Y3j3ilQ8EW2aDkYIa 2M5pALviQra5n1qAU0VTFRks+evUvJt4CHiFxWs93eppqRvkLjqfMDo3DOL/pCbBfIBQnVrntsUx iMxSpkvqIEtRL3s4ePxvne6Agjui5gKB/Byw/yqfyPKY2AXNZGS5G93aGyH8MqMlOQRMVMd0HCeT skOZ5TL8jX9qFf+mRv6O9IdBcdGihTXg724gFzhHYUe+7aKm0vViSBO7/LvsmNVpENJciwWuTi+J 2sBvM/O0p+zizleC4lU8fDj1CnRx+r4b/1Q/PZ9Sn7hkQmPn6Kh+SUdWG39uvOnCUbNPgcPcQwzM gKHyQxUo+ql2ySTkvEFH/23XMww2BnTTFGX5/yI4Ky+1ZJcbGqc5H4PEZHeoI/d6LWFf332z7LMw LGdoi9FMQ5j9dQUvMi1YKAun15JQSJLyCT5k+MTObVKxHy/dols381l9r9ft9daDonlwd6LnuX+J u10=
X-Report-Abuse-To: spam@quarantine11.antispamcloud.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/ietf/oXRzzw9x6xMNrVwoIKAVVGyHyeI>
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ietf/>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 03 Dec 2020 06:47:16 -0000

On 12/2/2020 5:52 PM, Mark Andrews wrote:

> And there are mechanism like one time passwords where that is mitigated.  You can
> also use telnet without passwords.  Whether to use telnet or ssh is about risk
> management.  Its also about what is provided.  There are things you will do on
> a home network that you wouldn’t do across the Internet.  Choosing to use telnet
> should be one of them.

Mark, you had me until "home network". Because most home networks are in 
fact *not* more secure than the open Internet. The illusion of using a 
'secure' network and thus allow unsafe practices is one of big sources 
of attacks!

-- Christian Huitema