5 ms·
Reports of Telnet's death have been greatly exaggerated
- ChrisArchitect 8mo agoRelated: The Day the Telnet Died https://news.ycombinator.com/item?id=46967772 https://news.ycombinator.com/item?id=46967772
- peterburkimsher 8mo agoRelated: PTT BBS is a popular Telnet-based forum in Taiwan, still actively used these days. https://en.wikipedia.org/wiki/PTT_Bulletin_Board_System https://en.wikipedia.org/wiki/PTT_Bulletin_Board_System
- m-hodges 8mo agoGlad this one didn’t open with a song parody.
- RupertSalt 8mo agoInstead, they chose a classic, yet timeless pop-culture reference: Mark Twain in 1897. http://isabevigodadead.com/ http://isabevigodadead.com/ [That's right, kids. There is no HTTPS server.]
- jmclnx 8mo agoThe main question is why use Telnet when ssh is available. Some people mentioned routers, maybe that is why. But I would think in this day and age routers would now use ssh. I do remember reading a long time ago telnet does/can support encryption. But when I looked at the systems I have access to, the manuals have no mention of that.
- drum55 8mo agoProbably because ssh ciphers change, telnet doesn’t, and you’re not really supposed to be internet exposing those interfaces anyway.
- Nextgrid 8mo agoSSH without proper key management offers marginal benefits compared to telnet.
- gzread 8mo ago[dead]
- Quarrel 8mo agoHowever bad your key management is, unless you're on an older ssh that will let you choose to use the "None" cipher, you're still better off than telnet!
- signalblur 8mo agoRight? It doesn’t even make sense - on any actively updated ssh agent you’d have to go out of your way. Also - SSH offers more than just encryption, but also data integrity - you can modify / manipulate a telnet session in ways you just can’t via SSH
- trumpdong 8mo ago[dead]
- themafia 8mo agoWhy use ssh when wireguard is available?
- 01HNNWZ0MV43FF 8mo agoSo I don't need root permission or kernel networking stuff setup. (I do run Wireguard, it just feels like sometimes a VPN is a sledgehammer to solve a port forwarding problem)
- yjftsjthsd-h 8mo agoBecause I want to login to my user account without sending a password over the wire. If telnet can use keypairs to authenticate users then I guess I don't mind that as a solution, but I haven't heard of it? Also I do care about per-user auth because some of us still work in environments where servers have multiple users.
- themafia 8mo ago> over the wire You know what wireguard is? > If telnet can use keypairs Kerberos exists, so, yes, it can.
- yjftsjthsd-h 8mo ago>> over the wire > You know what wireguard is? I suppose if you prefer, I can write "over the network". The point is that the password leaves my machine. As a practical example: With password auth, if an attacker gets root on a server then they can read your password and log in to other machines. With SSH keypairs, this isn't possible (unless you go out of your way to forward an SSH agent, and even then there are mitigations). >> If telnet can use keypairs > Kerberos exists, so, yes, it can. This sounds promising, and in fact at least one page I found about it claims that kerberos+telnet encrypts the session, at which point I don't immediately see what we need wireguard or ssh for. On the other hand, it looks like eg. GNU inetutils telnet doesn't support it? In fact, https://web.mit.edu/kerberos/krb5-1.5/krb5-1.5.4/doc/krb5-user/telnet.html https://web.mit.edu/kerberos/krb5-1.5/krb5-1.5.4/doc/krb5-us... says > The Kerberos V5 telnet command works exactly like the standard UNIX telnet program, with the following Kerberos options added: which makes it sound like they've just made a special telnet variant with these features, at which point it rather feels like we've just re-invented ssh under a different name.
- shevy-java 8mo agoI had a similar question. I use ssh usually these days. Telnet has one thing going for itself though: simplicity.
- skissane 8mo agoThe biggest remaining production use of telnet is IBM mainframe and midrange systems. tn3270 which is a telnet extension implementing support for 3270 block mode terminal data streams is still in widespread use, and there is also tn5250 which does the same for 5250 terminals (used on IBM i / AS/400) This use case is perfectly secure, because IBM mainframe/midrange telnet servers support telnet-over-TLS, and that’s what people run in production For connecting to mainframes, SSH has no real advantage over TLS, and its major disadvantage is that there is no standardised way to transmit 3270/5250 data streams over it But people looking for telnet traffic over the public Internet probably won’t even notice this, because they aren’t looking for telnet over TLS - which is difficult to distinguish from whatever else over TLS - and because almost all of it goes over VPNs not the public Internet
- RupertSalt 8mo agoThis is, as far as I know, a completely accurate and factual take. It is also nearly irrelevant. The two entities which have reported on this event are looking for tcp traffic on port 23, not TELNET protocol traffic. So indeed, as you say, if they are tunneled in VPN, or encapsulated or using an alternate port, tn3270 traffic will not be detect on port 23/tcp. Telnet over TLS is assigned to port 992, so any RFC-compliant implementation would be found there, and irrelevant, again, to the telnetd CVE reported this year. There are two facets to January's incident: the vulnerability in the GNU implementation of telnetd, and the purported, widespread blocking of port 23. The original report went out because of the coincidence they perceived there, and especially because the latter preceded the disclosure of the vulnerability! Mainframe tn3270 servers would not be subject to this vulnerability. If there had been a port filter in place, it only would've tripped-up the mainframes that still used port 23, which is evidently optional, and it says here that many admins want to keep AIX's telnetd bound to port 23 anyway. So it is good to know that TELNET protocol, and its extensions, are alive and well. We may not actually know how many clients and servers implement the protocol itself, since MUDs made this a routine thing, but certainly the deployment of IBM systems is formidable, considering the sheer mass of the iron in their rack mounts.
- harrall 8mo agoYou can wrap any TCP protocol in TLS which means every TCP protocol supports encryption, Telnet included. The app (and server) simply need to wrap their connections in TLS, which is trivial in many programming ecosystems. And IMO, X.509 (used in TLS) is virtually superior over SSH’s bespoke certificate format in every way. You get both regular certificate pinning (like what SSH uses now) AND full certificate authority chains (if you want). The main downside is that X.509 is more complex.
- yjftsjthsd-h 8mo ago> You get both regular certificate pinning (like what SSH uses now) AND full certificate authority chains (if you want). It doesn't do full chains, but SSH does have certificate authorities. I agree that the lack of intermediate CAs is a limitation (a CA can only sign a leaf node public key directly), but it's still super useful.
- benjojo12 8mo agoIt is surprisingly common to find routers with " export firmware " installed out of the box, that do not have ssh support to avoid the interactions with US Cryptographic export licencing complications
- evanelias 8mo agoWell, that certainly explains why no one in the US telnet BBS community seemed to be discussing having connectivity problems.
- nnurmanov 8mo agoDo you have to restart your computer to exit telnet?:)
- user3939382 8mo agoI think scoffing at plaintext protocols is silly. Contemporary security architecture is a nightmare. It’s like scoffing at keyboards for sending key codes in the open to the HID controller because you’ve failed to secure your machine so badly you have adversaries in your HID controller. If you have a well secured LAN where trust is social SSH gets you nothing. SMTP telnet http being plain were from days when users were able to actually reason about what was happening within their OS. If there’s anything that should be scoffed at its us now with our bloated opaque corporate controlled OSes.
- eurleif 8mo agoTangentially, I saw an ad the other day for software which purports to encrypt your keystrokes: https://www.keystrokelock.com/ https://www.keystrokelock.com/ I have no idea what that means.
- 01HNNWZ0MV43FF 8mo ago"Award-winning journalist on Fox News" and the padlock with an American flag really sells it for me. Maybe I should get in on this grift. Curl American Patriot Gold Marine Corps Never Forget 9/11 Edition for only $200. Loads _any_ URL.
- ErroneousBosh 8mo ago> "Award-winning journalist on Fox News" and the padlock with an American flag really sells it for me. About 20 years ago I worked on backend stuff for the sales site for a well-known UK retailer that advertised their spiffy new web store on TV. Part of the TV ad had a couple of smiley young people with Techie Girl typing on a computer, and a big animated padlock swooping in and clicking shut and Mumsy Middle-Aged Manager smiling happily, and cut to Hacker Guy typing furiously in a darkened room as a big padlock pops up on the screen and "SECURITY LOCKED" popping up, as he scowls at the screen. The VO was something like "and it's safe to buy online - our site has Security Built In" <fx: heavy padlock clunks shut> This sequence - the animation and filming this part right their in our own web dev office - cost over five grand of mid-2000s money to make, most of which being the padlock animations. The clunk was my bike lock. £5000. Five Thousand Pounds. I can tell you they spent well under 1/20th of that in developer time to actually write the security code for the site. It didn't even use HTTPS, which was kind of a requirement even in 2006.
- cobertos 8mo ago> However, in the context of data from Terrace and others we believe a more likely factor is the vantage point itself. Internet scanning often consists of large campaigns coordinated by specific actors, How does one do a measurement of traffic like this? You would have to own the nodes in the packet route to be able to see traffic, but TerraceNetworks or GreyNoise don't seem to be companies that do that. How do they get the data to analyze?
- ericpauley 8mo agoThis is a very challenging problem, especially if you don’t want to be over-concentrated on specific threat actors (as we suspect has happened here).
- signalblur 8mo agoGreynoise and others have shell companies and spin up exposed infra specifically to pick up scanning activity. They have them all over the world to get attackers scanning only certain regions etc. I should also note - I’m extremely skeptical of the OPs claims or inference that the attackers have potentially fingerprinted greynoises sensors. To suggest this while some traffic increased from specific ASN’s seems unlikely that this was the case. If it’s not clear - this was written by a competitor of theirs.
- ericpauley 8mo agoWe cannot know for certain what the root cause is. However, honeypot fingerprinting is a well-known risk for any vantage point, particularly a high-profile one.
- RupertSalt 8mo agoIf you want a disinterested perspective from the Research & Education community, look to CAIDA, the Center for Applied Internet Data Analysis: https://www.caida.org/ https://www.caida.org/ Also I just found "Hawkeye" the author of TinyFugue, Ken Keys, employed here! Cool beans!
- 8mo ago
- shevy-java 8mo agoI first used telnet in the 1990s to connect and play a text-based MUD. Back then we had large monitors with black background and green text font; for most people black background and white text was probably more common, but I remember having played that MUD for some weeks on such a setup (on a campus site, so these computers were used by students; we only had access to the campus on the weekend as the main guy's father in our group worked at that university). It actually was fun to use telnet like that and play the MUD, even if inconvenient. Of course our group soon switched to MUD clients that were more convenient to use, so using telnet became super-rare. I only used telnet a few more times after that. About three times again playing lateron when I had no internet connection, and for a few other things too, unrelated to MUDs, e. g. testing websites and similar activities. For connections, I kind of use ssh much more frequently so, even on windows via the tabby terminal. It is not as convenient on Linux (there I tend to prefer KDE konsole) but it works fairly well. I have not used telnet in quite some years now, but I still remember fondly to having typed commands to search for herbs in a meadow on that MUD (well, room designated was meadows and you could find herbs which would replenish over time, so you could search, sell and so forth; I have not played any MUDs since decades but it was fun in the 1990s era). Telnet will probably never die since it is so simple, but I think it is also not quite as important as it was, say, in the 1990s or so. Would be interesting for statistics that could measure this more objectively.
- ericpauley 8mo agoSurprisingly measuring legitimate Telnet usage may be even harder than measuring attacks! Getting representative metrics of benign src-dst endpoint pairs while controlling neither approaches impossibility, especially since at global scale it’d be mixed with (I suspect) orders of magnitude more attack traffic. Best you could probably do is measure on a clean-ish ISP like a university network.
- RupertSalt 8mo agoWere your MUDs on port 23? <runs and hides> For Tiny* servers, "raw telnet" was considered a ghetto experience. The worst part was that the asynchronous output would just stream in whether or not you were done typing, and you'd invariably lose track of what your input line looked like. So the primary task of a TinyMUD client was to separate them. Some used a "split screen", and some just kept refreshing the input line as new output was displayed. None of our MUDs ever appeared on port 23 and none of our servers ever spoke "The TELNET Protocol" as found in RFC 854. Telnet was simply the bundled TCP client that you could use for anything. The other cool features for a MUD client was using macros to perform repeated tasks or say interesting things, and /hilite and /gag were indispensable. /gag silenced/muted a player or a pattern-match of your choice, and so to play with "raw telnet" was to unblock all your /gagged players and let them get under your skin again. A fate truly worse than death (well you got paid "insurance" for dying, so many people enjoyed the experience.) Also popular in Tiny* clients was cursor line-editing and a command history. One client developer was sort of a troll, and so when he forked "tinywar" it began to feature some automation that could permit a player to make a real nuisance of themselves. But he was also a great programmer, and not all tinywar users were trolls, so it got put to good use. Ultimately, Explorer_Bob wrote TinyFugue, and Ken Keys "Hawkeye" took over development, pushing it into amazing heights on a level with MUSH programming, and TinyFugue basically became the gold standard client for Unix and was also ported to Win32, and ultimately abandoned in an extremely stable state. I went to school with Ken. Miss you, man!
- exabrial 8mo agoI [ab]use telnet regularly as a debugging tool than its intended purpose. Pretty handy tool to check TCP connectivity.
- ktm5j 8mo agoYeah it's an easy way to check if a port is responding, and you can actually drive some protocols using telnet. Eg: `telnet some.http.addr 80` and then type in `GET /index.html HTTP/1.0` and hit enter twice. You can use it to test SMTP servers too.
- vonunov 8mo agohttps://i.vgy.me/JuGzDb.png https://i.vgy.me/JuGzDb.png (user input marked)
- creatonez 8mo agoWrong tool for the job. Netcat gives you raw TCP as stdin/stdout without injecting or interpreting control codes.
- batrat 8mo agoI use it strictly on older systems that only use telnet and for casual port checking on some equipment. Last time I had to check if AIS equipment is working properly. Some people think "servers" are the only thing in this world. Telnet is one of those things that probably keeps this world function properly.
- jiehong 8mo agoSome audio/video receivers still use telnet to control them over the network, like those still sold by Denon/Marantz [0]. [0]: https://assets.denon.com/documentmaster/us/heos_cli_protocolspecification-version_04062020.pdf https://assets.denon.com/documentmaster/us/heos_cli_protocol...
- w4der 8mo agoSome of KUKA's controllers still use telnet in their startup sequence.
- paradox460 8mo agoLutron used it for their integrations platform up til very recently. It was extremely convenient, being able to write little scripts that do things like turn off all the lights
- deleted 8mo ago[deleted]
- nubinetwork 8mo agoTelnet scanning is definitely down overall from what I can tell, but only by half of what it was in past months. It spiked a bunch around the time of the telnetd cve, but that's to be expected.
- laurensr 8mo agoUnfortunately towel.blinkenlights.nl is permanently dead
- alexpotato 8mo agoI upvoted your comment for the news but wish I could downvote the news.
- cbarrick 8mo agoIt's not though. I thought it was, and posted this same comment on the other telnet article. But I was informed that it is back! And I was able to confirm it myself. I don't have a telnet client on my Mac, but I was able to confirm with nc. nc towel.blinkenlights.nl 23
- nancyminusone 8mo agoNo it's not, it only works on ipv6 now.
- laurensr 8mo agoThanks for pointing that out! My ISP, (Orange Belgium), does not support IPv6 yet!
- reeddev42 8mo ago[dead]
- the_biot 8mo agoFrankly I'm a little sceptical about the claim that large ISPs are blocking telnet on their core routers. Core routers need to forward traffic, not inspect it. I don't see why a large ISP should burden its core infrastructure with something so trivial as telnet-specific traffic.
- IAmLiterallyAB 8mo agoHalf the time when people say they're using telnet (including in this thread) they're really just using the client as a TCP client, not doing anything with the Telnet protocol. No one is stopping you from using the telnet client. And really you should just use netcat
- dekhn 8mo agoThere's one thing I haven't figured out with netcat- how do you know it connected? (I just looked it up, after many years: the -v flag. Which makes sense because netcat is supposed to be "transparent").
- yamapikarya 8mo agotelnet is very popular tool to check the port firewall
- simpleusername 8mo ago[dead]
- Bender 8mo agoIn my opinion just like IPv4, telnet and ftp will be around long after all of us. Teach your grand-kids all the escape sequences, variables and terminal types. This will be required for their Pip-Boy to connect to mainframes and terminals when keys are missing.