You are not logged in. Login Now
 0-3   4-24         
 
Author Message
steve
Board meeting agenda 10/21/08 Mark Unseen   Oct 21 20:13 UTC 2008

   Agenda for the board meeting of Oct 21

 - finances

 - strategies for grex
   + staff members
   + board members and board size
   + town hall meeting
   + what we want to be

 - staff report

 - ?
24 responses total.
lees
response 1 of 24: Mark Unseen   Oct 21 22:09 UTC 2008

Floor suggestion: newuser (Dan has some details I sent him - can be 
worked in quite well with the existing system).
tsty
response 2 of 24: Mark Unseen   Oct 22 14:53 UTC 2008

looks like starting about ~70 neuusers ago the new shell is in use.
cross
response 3 of 24: Mark Unseen   Oct 23 19:41 UTC 2008

resp:1 A big chunk of the discussion in the Tuesday night board meeting
was, in fact, newuser; I'd even go so far as to say that discussion about
newuser comprised the majority of the meeting.

As TS noted in resp:2, we are, in fact, using a new shell for newuser right
now.  This is somewhat different from the scheme that Lee proposed to me, but
it was something I did as a stop-gap to stop ongoing attacks.

In a nutshell: New users on Grex no longer get access to an "unrestricted"
Unix shell.  Instead, they get something very limited in scope that allows
them to run only a few commands that, for better or worse, can be very tightly
controlled.  At the same time, I changed backtalk's authentication mechanism
so that users running that new shell did not have write access to backtalk.
The shell doesn't support running party, tel, write, fronttalk, or picospan,
and thus, new users have essentially no access to party or the conferences.

As I said, this was something of a stop-gap.  Moving forward, I'd like to
work up a somewhat more robust mechanism for not just issuing accounts, but
granting higher levels of access to the system.  We're working on it; I think
pretty much everyone's on roughly the same sheet of music, both technically
and politically.  Lee sent in a pretty specific outline that jived well with
the general ideas that I and others have been having, so I think we're all
headed in pretty much the same direction.  Now, it's just a small matter of
programming.
 0-3   4-24         
Response Not Possible: You are Not Logged In
 

- Backtalk version 1.3.30 - Copyright 1996-2006, Jan Wolter and Steve Weiss