3 ms·
Thanks for catching that. We've spent the last week moving into a new office and it must have slipped by as we were getting everything reconfigured. It's been l
by Firehed 16y ago
Thanks for catching that. We've spent the last week moving into a new office and it must have slipped by as we were getting everything reconfigured. It's been locked down again.
- seiji 16y agoOne part of me wants to pat you on the back and say, "It's okay, everybody makes mistakes." The other part of me wants to say, "You have nine million dollars in funding. Figure shit out. This isn't a game."
- joeuser12 16y agoseiji, an open ssh port also isn't that big a deal. Every large network has an ssh entry point somewhere. I did a quick check before and at least it only accepted ssh-2. But yes, I agree with you that having that entry point on the main domain is a bad idea, but realistically we are talking about security through obscurity here. With enough guessing you can find the ssh entry point for any large site. The trick is whether you can get through it. They tend to all have 2-factor auth behind them making it extremely hard to bypass. I have no idea whether wepay has 2-factor auth behind theirs though.
- gesh 16y agoYou guys run your servers out of your offices?
- joeuser12 16y agoA quick traceroute would tell you that they don't. He probably meant the source ip range for restricting access changed due to the office move.