Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Sure. It is convenient.

Consider the security implications of arbitrary commands like he suggests, instead of using, I dunno, SSH or whatever.



Well, (a) he's not suggesting that, and (b) even if he were, it doesn't seem like a huge deal.

If an attacker has access to Hubot, then they already have access to everything the Hubot server can do.


If they can TALK to hubot. So whatever the security is on campfire, or whatever it is.


Campfire's a webapp, so presumably https.


Use an IRC server with SSL and client cert authentication? It's a standard feature in many daemons and clients nowadays.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: