Earlier quoted context omitted.
It’s pretty much impossible to validate that you are meeting the terms of your contract re: security policy if you’re doing that. You almost certainly were if you were providing SOC services to a big telco. I have terminated contracts for cause and in one case got a vendor suspended from a big centralized procurement contract for pulling bullshit like what you described.
The telco was providing the managed services in this case. That is interesting, so it sounds like this was a complete breakdown in the process somewhere. We weren’t doing it for fun or sport, we were doing it because it was the only way to effectively do our job.
Free book to master SSH tunneling concepts
21–28 of 28 posts
Re: Free book to master SSH tunneling concepts
#22Earlier quoted context omitted.
It’s pretty much impossible to validate that you are meeting the terms of your contract re: security policy if you’re doing that. You almost certainly were if you were providing SOC services to a big telco. I have terminated contracts for cause and in one case got a vendor suspended from a big centralized procurement contract for pulling bullshit like what you described.
>You almost certainly were if Don't you mean they almost certainly weren't? It's hard to understand the rest otherwise.
Once you start poking holes into the security it's hard to assure you only did it for a good cause or with good intentions (whatever that means).
Re: Free book to master SSH tunneling concepts
#23Looks interesting, will give it a read as it looks to cover more than the basics. Years ago I worked in a SOC doing managed services for a major telco provider, and for some reason they thought that we didn't have the need to do any kind of SSH tunneling to manage routers/switches/firewalls. They kept blocking it at various layers, and we kept having to find more and more creative ways to get around it. I think at on…
It’s pretty much impossible to validate that you are meeting the terms of your contract re: security policy if you’re doing that. You almost certainly were if you were providing SOC services to a big telco. I have terminated contracts for cause and in one case got a vendor suspended from a big centralized procurement contract for pulling bullshit like what you described.
Re: Free book to master SSH tunneling concepts
#24Re: Free book to master SSH tunneling concepts
#25Earlier quoted context omitted.
It’s pretty much impossible to validate that you are meeting the terms of your contract re: security policy if you’re doing that. You almost certainly were if you were providing SOC services to a big telco. I have terminated contracts for cause and in one case got a vendor suspended from a big centralized procurement contract for pulling bullshit like what you described.
The telco was providing the managed services in this case. That is interesting, so it sounds like this was a complete breakdown in the process somewhere. We weren’t doing it for fun or sport, we were doing it because it was the only way to effectively do our job.
Re: Free book to master SSH tunneling concepts
#26Re: Free book to master SSH tunneling concepts
#27Re: Free book to master SSH tunneling concepts
#28Earlier quoted context omitted.
>You almost certainly were if Don't you mean they almost certainly weren't? It's hard to understand the rest otherwise.
No, gp is speaking from the point of view of those who set up the security measure. Once you start poking holes into the security it's hard to assure you only did it for a good cause or with good intentions (whatever that means).
The original:
"It’s pretty much impossible to validate that you are meeting the terms of your contract re: security policy if you’re doing that. You almost certainly were if you were providing SOC services to a big telco."
That second sentence seems to be only interpretable as:
You almost certainly were meeting the terms of your contract re: security policy if you were providing SOC services to a big telco.
However it also says it's impossible to validate - so if it is impossible to validate that you were meeting the terms of your contract re: security policy, it must mean you weren't meeting the terms of your contract because such a contract will require validation.
But I guess I should let it go.