3 ms·
This is a throwaway. Five years ago I worked for a company that was still using telnet for everything. Despite assurances of using encryption to clients, we we
by throwaway387234 9y ago
This is a throwaway. Five years ago I worked for a company that was still using telnet for everything.
Despite assurances of using encryption to clients, we were taking no security measures. Connections to servers were possible with UUCP and Telnet over the internet and modem.
We "upgraded" to SCO OpenServer 6 because we were already grandfathered in to it and three servers had died.
We also had a zero password policy. If you could find the port or the phone number and you could guess a username, such as oh I don't know: "root", then you could get in.
And people were. We were regularly getting modem calls after hours. We had medical records, private financial data, social insurance numbers, ...
It was such a painful work environment. I switched us over by claiming that OpenServer 6 did not have a telnet server and that we were going to have to switch to SSH. I also lied and said that passwordless SSH sessions weren't a configurable option.
My point? This sort of half-assed mitigation of people stuck in their ways doesn't accomplish much. Best to just lie to them, if they were educated they would have already made the change of their own volition.