Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's not the developers who did this, it's the "network security" people. If you block all outgoing ports except for HTTPS and ssh, everything is henceforth going to be tunneled over HTTPS or ssh.

This is also the reason why, if you allow outgoing HTTPS connections, you should as a general rule be allowing all outgoing connections except for SMTP. Because actually malicious traffic is just going to be tunneled over HTTPS anyway and all you're doing is inhibiting the deployment of any new protocols that don't take on the complexity and inefficiency of the tunnel.



And this is how we end up with clown-maxing abominations like DNS-over-HTTPS.


Every place I've ever worked that blocked ports, blocked SSH, it's no exception.


It's an extremely common exception for exactly the reason you don't like it. If you block it you get widespread breakage because so many things use it. Then even more things use it because it's allowed and novel protocols aren't.

And what do you think happens in the places that do block ssh, instead of unblocking other things? I hope you like VSCode over ssh over HTTPS VPN.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: