Re: A simple question FORK! Something that bugs me about net-installs and security

2007-01-29 Thread celejar
On 1/28/07, Hodgins Family <[EMAIL PROTECTED]> wrote: > Firewalling routers are $50 and do a reasonably > good job. Any recommendations? What are you using? I believe that just about any home wireless AP / switch / router these days does stateful packet inspection and NAT, making it a decent H

Re: A simple question FORK! Something that bugs me about net-installs and security

2007-01-28 Thread Zach
On 1/28/07, John L Fjellstad <[EMAIL PROTECTED]> wrote: Make sure you buy v4 or below. v5 can't be upgraded (and doesn't run Linux) The WRT54G v4 was re-released as the WRT54GL - the L for Linux. Zach -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble?

Re: A simple question FORK! Something that bugs me about net-installs and security

2007-01-28 Thread John L Fjellstad
Ron Johnson <[EMAIL PROTECTED]> writes: > On 01/28/07 13:32, John L Fjellstad wrote: >> Make sure you buy v4 or below. v5 can't be upgraded (and doesn't run >> Linux) > > I thought that was the difference between the WRT54GL and WRT54G. You're right. The WRT54GL is the linux version. From what

Re: A simple question FORK! Something that bugs me about net-installs and security

2007-01-28 Thread Douglas Allan Tutty
On Sun, Jan 28, 2007 at 08:08:55AM -0700, Hodgins Family wrote: > > Firewalling routers are $50 and do a reasonably > > good job. > > Any recommendations? > What are you using? Get any old (now 486 or newer) box and install basic debian on it. Add shorewall and you have a totally configurable fi

Re: A simple question FORK! Something that bugs me about net-installs and security

2007-01-28 Thread Ron Johnson
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/28/07 13:32, John L Fjellstad wrote: > Hodgins Family <[EMAIL PROTECTED]> writes: > >>> The Linux geek fave is the Linksys WRT54GL, since it runs Linux and >>> can be upgraded with 3rd-party binaries. It's a wireless access >>> port, but also h

Re: A simple question FORK! Something that bugs me about net-installs and security

2007-01-28 Thread John L Fjellstad
Hodgins Family <[EMAIL PROTECTED]> writes: >> The Linux geek fave is the Linksys WRT54GL, since it runs Linux and >> can be upgraded with 3rd-party binaries. It's a wireless access >> port, but also has 4 RJ45 jacks and has a firewall. US$54 at Newegg. > > Thanks! Make sure you buy v4 or below.

Re: A simple question FORK! Something that bugs me about net-installs and security

2007-01-28 Thread Hodgins Family
> I use a Netgear RP614v2, but don't like it. > > The Linux geek fave is the Linksys WRT54GL, since it runs Linux and > can be upgraded with 3rd-party binaries. It's a wireless access > port, but also has 4 RJ45 jacks and has a firewall. US$54 at Newegg. Thanks! -- To UNSUBSCRIBE, email to [

Re: A simple question FORK! Something that bugs me about net-installs and security

2007-01-28 Thread Ron Johnson
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/28/07 09:08, Hodgins Family wrote: >> Firewalling routers are $50 and do a reasonably >> good job. > > Any recommendations? > What are you using? I use a Netgear RP614v2, but don't like it. The Linux geek fave is the Linksys WRT54GL, since it

Re: A simple question FORK! Something that bugs me about net-installs and security

2007-01-28 Thread Hodgins Family
> Firewalling routers are $50 and do a reasonably > good job. Any recommendations? What are you using? -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: A simple question FORK! Something that bugs me about net-installs and security

2007-01-27 Thread Douglas Allan Tutty
On Fri, Jan 26, 2007 at 10:01:43PM -0600, Ron Johnson wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > On 01/26/07 19:03, Hodgins Family wrote: > > Many people are installing Debian "from the internet". Yet, the Securing > > Debian Manual suggests no contact with the internet until the

Re: A simple question FORK! Something that bugs me about net-installs and security

2007-01-27 Thread Ron Johnson
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/27/07 01:44, Andrei Popescu wrote: > On Sat, 27 Jan 2007 01:24:33 -0600 > Ron Johnson <[EMAIL PROTECTED]> wrote: > >>> Shouldn't the setup of a firewall be part of the installation >>> routine? Perhaps prior to running tasksel, some script could

Re: A simple question FORK! Something that bugs me about net-installs and security

2007-01-26 Thread Andrei Popescu
On Sat, 27 Jan 2007 01:24:33 -0600 Ron Johnson <[EMAIL PROTECTED]> wrote: > > Shouldn't the setup of a firewall be part of the installation > > routine? Perhaps prior to running tasksel, some script could query > > the user about using a firewall and/or help him/her set an > > appropriate one up?

Re: A simple question FORK! Something that bugs me about net-installs and security

2007-01-26 Thread Ron Johnson
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/27/07 01:16, Hodgins Family wrote: >> Did you *read* the link you posted? > Yes, I've read/seen this Appendix F section in various versions. > > Up until the last version that I read (version 3.10 of last November) > there has been a "FIXME: tes

Re: A simple question FORK! Something that bugs me about net-installs and security

2007-01-26 Thread Hodgins Family
> Did you *read* the link you posted? Yes, I've read/seen this Appendix F section in various versions. Up until the last version that I read (version 3.10 of last November) there has been a "FIXME: test this setup to see if it works properly." Didn't exactly inspire me to use it as an aid for net

Re: Re: A simple question FORK! Something that bugs me about net-installs and security

2007-01-26 Thread Angelo Bertolli
Hmmm, every time I do a net install, it installs the base files first, reboots, and then uses the actual system to install the rest... Angelo -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: A simple question FORK! Something that bugs me about net-installs and security

2007-01-26 Thread Ron Johnson
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/26/07 19:03, Hodgins Family wrote: > Many people are installing Debian "from the internet". Yet, the Securing > Debian Manual suggests no contact with the internet until the > installation is "secure." > > The manual states that installing the O

Re: A simple question FORK! Something that bugs me about net-installs and security

2007-01-26 Thread Joey Hess
Hodgins Family wrote: > Are net installs (let's say for a Desktop environment) totally without > vulnerability risks? > > When, during an installation, do/should people think about > security/vulnerability issues of the software they are installing? Well, let's see.. to perform a network install,

Re: A simple question FORK! Something that bugs me about net-installs and security

2007-01-26 Thread Hodgins Family
Many people are installing Debian "from the internet". Yet, the Securing Debian Manual suggests no contact with the internet until the installation is "secure." The manual states that installing the OS off the web is not the best idea (Section 3.3 found here: http://www.debian.org/doc/manuals/secu