Hacker News new | ask | show | jobs
by meithecatte 1011 days ago
They want to consider normal connections legitimate, and only detect tunnels.
1 comments

Forgive me, my grok ability is low right now. I read the section about detecting TTY traffic, and in my mind, TTY traffic would be an example of a legit normal connection. Engineer accessing the system, etc.
I routinely use both forward and reverse tunnels in my day-to-day ssh use.