1) Cloud based. No, no, no, absolutely not, no way, no how. I am not hooking up server farms to the internet. Monitoring systems stay behind the firewall. Please come up with a self-hosted version.
Moreso when:
2) They log directly into the system. Unprivileged user or not, if you've got shell on my box, "you" being a random company on the internet, it's not my box anymore. Someone hacks you and by extension they've hacked me.
I agree with you, though other people may be entirely trusting of the SaaS in question or not care that much about security.
Commando.io is basicly the same service command-execution wise, however, it also offers the possibility for customers to run commando.io self-hosted (presumably enterprise pricing). Having a SaaS I presume, which is working (and successful) can be a boon to future enterprise sales that are concerned with the risks you mentioned.
I wish that all SaaS dealing with access to remote servers have some kind of (more up-front) disclaimer, noting that no matter how secure the service is advertised it will not be responsible for future mishaps/breaks/leaks.
It wasn't clear from reading the homepage, but I was hoping this only sent data OUT via HTTP and didn't require giving access to the system at all. If they actually require access to my system, that's a little disappointing.
Comments
I've got two problems here.
1) Cloud based. No, no, no, absolutely not, no way, no how. I am not hooking up server farms to the internet. Monitoring systems stay behind the firewall. Please come up with a self-hosted version.
Moreso when:
2) They log directly into the system. Unprivileged user or not, if you've got shell on my box, "you" being a random company on the internet, it's not my box anymore. Someone hacks you and by extension they've hacked me.
I agree with you, though other people may be entirely trusting of the SaaS in question or not care that much about security.
Commando.io is basicly the same service command-execution wise, however, it also offers the possibility for customers to run commando.io self-hosted (presumably enterprise pricing). Having a SaaS I presume, which is working (and successful) can be a boon to future enterprise sales that are concerned with the risks you mentioned.
I wish that all SaaS dealing with access to remote servers have some kind of (more up-front) disclaimer, noting that no matter how secure the service is advertised it will not be responsible for future mishaps/breaks/leaks.
It wasn't clear from reading the homepage, but I was hoping this only sent data OUT via HTTP and didn't require giving access to the system at all. If they actually require access to my system, that's a little disappointing.
I'd like to second this. Add a self hosted version and you have a new customer.