Re: [LEDE-DEV] [PATCH] prereq-mk: Change wget dependency to curl one.

2018-03-10 Thread Michelle Sullivan
er in the long run, but I do believe unless there is any compelling reason why like security issues or something available using curl that is not available in wget - *that is required for building* - leave it the hell alone! Regards, Michelle -- Michelle Sullivan http://www.mhix.org/ ___

Re: [LEDE-DEV] [PATCH v1 1/1] openssh: disable passwords for openssh server

2018-02-14 Thread Michelle Sullivan
here though. Please let's not encourage bogus security-through-obscurity measures in that context. +1 -- Michelle Sullivan http://www.mhix.org/ ___ Lede-dev mailing list Lede-dev@lists.infradead.org http://lists.infradead.org/mailman/listinfo/lede-dev

Re: [LEDE-DEV] [PATCH v1 1/1] openssh: disable passwords for openssh server

2018-02-14 Thread Michelle Sullivan
Philip Prindeville wrote: On Feb 13, 2018, at 9:14 PM, Michelle Sullivan wrote: [snip] Personally - my thoughts There should be an option to enable passwords (default off...) A warning should be placed on the checkbox to inform the user it is not a good idea to enable them. SSH should

Re: [LEDE-DEV] [PATCH v1 1/1] openssh: disable passwords for openssh server

2018-02-13 Thread Michelle Sullivan
ersonally though I think anyone using SSH instead of the webinterface is more than likely going to know what they are doing and therefore it should not be an issue... ie err on the side of 'there is an idiot at the controls, lets make it default as secure as possible'... -- Michelle

Re: [LEDE-DEV] [PATCH v1 1/1] openssh: disable passwords for openssh server

2018-02-10 Thread Michelle Sullivan
hat even in their semi-residential products - ie their small office gear doesn't support it either I'd suggest that any support for uPNP is off by default and gives a warning if someone tries to enable it.) -- Michelle Sullivan http://www.mhix.org/ __

Re: [LEDE-DEV] [PATCH v1 1/1] openssh: disable passwords for openssh server

2018-02-10 Thread Michelle Sullivan
Philip Prindeville wrote: On Feb 10, 2018, at 6:03 PM, Michelle Sullivan wrote: Paul Oranje wrote: Your aptness for seeing the possible attack vectors warrants your judgement ... Op 10 feb. 2018, om 17:07 heeft Philip Prindeville het volgende geschreven: On Feb 10, 2018, at 3:28 AM

[LEDE-DEV] minor patch for the freeradius3 package

2017-07-29 Thread Michelle Sullivan
Patch here: http://flashback.sorbs.net/packages/LEDE/freeradius3-sql.diff It enables SQL backends of MySQL, PostgreSQL and SQLite3.. it also allows sqlippool as a config option which makes use of the DHCP server that is compiled in. Regards, -- Michelle Sullivan http://www.mhix.org