[ITA] rsh-0.17-3

Corinna Vinschen corinna-cygwin@cygwin.com
Mon Jul 16 09:33:00 GMT 2018


On Jul 16 11:16, Corinna Vinschen wrote:
> On Jul 16 11:03, Achim Gratz wrote:
> > Takashi Yano writes:
> > > I agree rlogin/rsh/rexec are outdated. However, most major Linux
> > > and BSD distributions still provide them as a package.
> > >
> > > Should not Cygwin follow these as well?
> > 
> > Even on the UN*X side the r-tools have been deprecated for so long it
> > doesn't really make sense to use them anymore.  The only sane way to use
> > them is in fully isolated networks and I haven't seen any of those in
> > decades.  With Cygwin running on top of Windows there is ahole other set
> > of issues to deal with and that makes it even more inappropriate to even
> > offer those tools.  IMHO, deferring to the security lead for Cygwin.
> 
> We have a security lead?

Personally I agree with Takashi, btw.  Linux still provides the old r*
tools including rsh-server.  There may still be legit uses of the tools
in controlled environments.  if we remove all packages which can be used
to shoot yourself in the foot, there's not much left, I guess.

As a compromise, we could continue to provide the client package and
just discontinue the server package, but it's your choice.


Corinna

-- 
Corinna Vinschen                  Please, send mails regarding Cygwin to
Cygwin Maintainer                 cygwin AT cygwin DOT com
Red Hat
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <http://cygwin.com/pipermail/cygwin-apps/attachments/20180716/55ecb16b/attachment.sig>


More information about the Cygwin-apps mailing list