Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Why do these fucking quasi-products never actually say what the fuck they DO? "<this> replaces sshd, possibly the most critical piece of software your server runs, with a magic black box".

There's nothing in the rather meagre list of suggestions at the top of the readme that can't be done already and 0 detail on how they intend to achieve it and why their dubious methods require wholesale replacement of your, did I say it's critical?, ssh daemon.

SSH is definitely not a tool I'll be replacing any time soon with the latest fly-by-night product from CADT BikeShedders Inc.



There was one very interesting feature, recording of sessions.

There is an increasing demand in large organisations to manage server sessions better.

That is to have accountability and manage access centrally.

So far I've only reviewed one solution, Cyberark, they promised to manage all our server sessions centrally with 2FA, recording ssh and rdp, and more. But in the end we weren't motivated enough to pick them.

I haven't seen any open source offering to do this.

Of course this product would be outside of your normal SSH server, as an additional proxying layer and not a replacement for ssh. Just saying that there was one very interesting point in that repo, I wouldn't replace OpenSSH ligthly either.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: