Security

  1. Eavesdropping
    • VNC & X11 data transferred in plain text!
    • SSH tunnels vs IPSEC
      • intermittant vs semi-permanent
      • remote control vs lan
      • IPSEC is harder to set up
    • Examples
      • Tunnel to a VNC server, but use port 5901 on my computer

           ssh -L 5901:127.0.0.1:5900 mike@142.161.33.115
      • Tunnel to a MySQL server

           ssh -L 3306:127.0.0.1:3306 ubergeek@someplace.dyndns.org
  2. Untrustworthy Computers
    • Public key on USB key
  3. Rogue ServersYOU are the risk!