HTTPS / Secure forms of Authentication
Posted: Sat Jun 27, 2009 9:29 pm
I have opened another forum topic for this for assistance, so far I have been able to get one of many of the pages to work over HTTPS.
Aside from this ALL Traffic to your amahi server is plain text. Even Samba traffic, this is no good. I'd also like to point out that simply forcing a user to authenticate with a user name and password does not mean it's encrypted, and is plainly visable to the savvy users.
I realize most people dont think about this, but especially when you consider this is your DHCP server, DNS server, File server, Torrent box, VPN, etc, the insecurity really adds up quickly. Even if you use a seperate user and pass for your shares, apps, etc to access your system, it only takes me about 36 seconds to pull a password out of a wire shark capture and another few minutes to escilate privledges in many cases.
I was recently asked by a friend how I liked my Amahi/Fedora install (he and myself both fedora haters) and my only gripe was the complete lack of security for remote authentication. Beyond that, with the latest patches, F9 is relatively secure and I am extremely happy with the Amahi product as a whole aside from this.
Aside from this ALL Traffic to your amahi server is plain text. Even Samba traffic, this is no good. I'd also like to point out that simply forcing a user to authenticate with a user name and password does not mean it's encrypted, and is plainly visable to the savvy users.
I realize most people dont think about this, but especially when you consider this is your DHCP server, DNS server, File server, Torrent box, VPN, etc, the insecurity really adds up quickly. Even if you use a seperate user and pass for your shares, apps, etc to access your system, it only takes me about 36 seconds to pull a password out of a wire shark capture and another few minutes to escilate privledges in many cases.
I was recently asked by a friend how I liked my Amahi/Fedora install (he and myself both fedora haters) and my only gripe was the complete lack of security for remote authentication. Beyond that, with the latest patches, F9 is relatively secure and I am extremely happy with the Amahi product as a whole aside from this.