4 ms·
I've been using iodine http://code.kryo.se/iodine/ http://code.kryo.se/iodine/ for a long time.
by mayli 11y ago
I've been using iodine http://code.kryo.se/iodine/ http://code.kryo.se/iodine/ for a long time.
- buserror 11y agoAh, I need to start using this. Work's firewall is completely bonkers, and they just removed access to webchat.freenode.net, so I need to find a way to punch thru... You can't even ssh out, or use websockets etc...
- chrismsnz 11y agoCircumventing your companies firewall is not a great idea in the first place. Additionally, if they have aggressive egress filtering, its likely that the only DNS communication will be via an internal resolver which is going to be monitored - iodine is going to leave a LOT of shit in those logs.
- buserror 11y agoWell I hope they don't proxy the DNS -- it's quite costly to do so, if they don't it'll be fine. If they do, well, I'll have to find another way using 'long' http transactions and such...
- chrismsnz 11y agoRunning an internal DNS resolver is actually very cheap, almost every broadband CPE device runs or can run its own DNS proxy resolver. It's also a great source of information when monitoring egress communication, so I would just make sure you know what you're doing.
- hueving 11y agoWhy would you think that's costly? A cheap home router can do it with dnsmasq.
- JoshTriplett 11y ago> Circumventing your companies firewall is not a great idea in the first place. Neither is putting in place a firewall that makes people need to circumvent it to get their jobs done. If you work at the NSA, sure, it makes sense that all access is heavily restricted. (Though if you work at the NSA, please reconsider what you're doing with your life.) But if you work at an ordinary company, and doing your job (note: not goofing off, but actually doing your job) requires you to work around the corporate firewall, that's a serious policy problem. And the answer isn't to sit on your hands until IT fixes the firewall, because IT departments invariably seem to have far too many people in them that forget that you can't create security by preventing work. A system encased in concrete is secure, but not useful.
- chrismsnz 11y agoI'm a security guy so I obviously have a differing viewpoint, but when it comes to ensuring what data comes in and leaves your environment there's little choice. The ability to analyse outgoing traffic is really a requirement for being able to effectively detect and respond to incidents. If your job involves idling on Freenode maybe take it up with management? EDIT: phrasing
- JoshTriplett 11y agoFirst, security is never a goal in itself; the goal is to get some job done, which involves having something to protect, and security's job is to protect it. Second, even when your metric is security, creating a policy that people have to circumvent to get their job done seems likely to reduce security. > when it comes to ensuring what data comes in and leaves your environment there's little choice The concept of your environment having an "inside" and an "outside" is dangerous. Better to assume that "inside" is just as hostile as "outside", and avoid having any insecure internal services or resources. Use TLS/HTTPS everywhere internally, require authentication for internal services, and otherwise make sure that an attacker gains nothing by compromising an end-user system except what's on that end-user system. > If your job involves idling on Freenode Forget "idling"; participating effectively in many Open Source projects (whether developing them or getting support for them) requires the ability to get on IRC. > maybe take it up with management Short of C-level executives, management rarely has the ability to change IT policy.
- xenophonf 11y agoWhy not just use your smartphone or something instead? As an infosec guy, I try to maintain the customer service-oriented attitude of "Oh, you snuck something past me? Nice one! Don't do it again. Here's why..." Then again, I am fortunate enough to work in a semi-open academic/clinical/research environment, where if you cross-your-heart-and-hope-to-die promise me that you won't misuse BitTorrent for warez or porn and that you truly have a business need for it, I'll entertain your request for a firewall/QoS exception. But if you work at the kind of place that is manned by totally bonkers jackbooted thugs, they won't be so lenient. When they find you, you could lose your job or worse. It sucks, but the network's not yours to hack around even if you really do know better than the people operating it (and you probably do). (signed, a former firewall piercer extraordinaire) ((I got so fed up with one customer's stupid firewall rules that I bought a dial-up subscription to Earthlink and an adapter that would let me hook my modem up to the handset of their digital phone.)) (((Holy shit! Earthlink still has dialup service!)))
- socceroos 11y agoAnything using an MD5 hash cannot be considered secure. Edit: From the site's blurb on Security: "iodine uses challenge-response login secured by MD5 hash." Sorry, but MD5 as 'secure' died a long time ago.
- fugyk 11y agoI had used it once. But the speed it gave to me is too slow. I could not even open a basic site without waiting for 10-15 seconds. Had I done something wrong or is this speed same to you?
- yaleman 11y agoIt can be very slow because of the nature of the communication method. :(