[asterisk-dev] Security Request for discussion: Should sip.conf allowguest=yes be the default

Tilghman Lesher tlesher at digium.com
Thu Nov 12 14:31:12 CST 2009


On Thursday 12 November 2009 14:00:44 Jeff LaCoursiere wrote:
> On Thu, 12 Nov 2009, Atis Lezdins wrote:
> > On Thu, Nov 12, 2009 at 8:34 PM, Tzafrir Cohen <tzafrir.cohen at xorcom.com> 
wrote:
> >> Please explain to me why exactly allowing guests is a bad thing. How can
> >> I allow people to call me from the internet? Create a local account for
> >> each and every one in my addressbook?
> >
> > How about creating context "guest" or "public", and setting it as
> > default in samples? That would make user to think much more before
> > adding some code there.
>
> That sounds like the most reasonable suggestion yet.

That sounds fine to me.

-- 
Tilghman Lesher
Digium, Inc. | Senior Software Developer
twitter: Corydon76 | IRC: Corydon76-dig (Freenode)
Check us out at: www.digium.com & www.asterisk.org



More information about the asterisk-dev mailing list