Skip to content
Artwork for SysAdmin Weekly
SysAdmin Weekly · Friday · 1 hr 14 min

059 - How Should SysAdmins Handle Remote Access in 2026?

Which protocol you use to reach the box is the least interesting decision you will make about remote access. Andy Syrewicze and Eric Siron go after the piece they cut from the tools episode. Eric lands the sharpest version half an hour in: what you are actually doing is moving from one-sided authentication to mutual authentication. Around that sit overlay networks against the VPN concentrator, the RMM console as the most attractive target in an MSP estate, the outbound tunnel nobody watches for, and whether just-in-time access holds up at 3am with something down and nobody awake to approve it. Chapters: 00:00:00 - Cold Open: Remote Access Gets Its Own Episode 00:01:20 - Welcome and Show Plugs 00:04:16 - News React: Anthropic Safety Researcher Resigns 00:12:54 - News React: Broadcom Pulls Public VDDK Access 00:16:21 - Nerd Hour: Eric's Hugo Migration 00:17:24 - Three Gates Against a Runaway API Bill 00:20:38 - Main Topic: The Tooling Is the Small Part 00:23:08 - SSH on 22, and the Port Change Experiment 00:24:21 - Name a Reason to Expose a Management Port 00:27:10 - Overlay Networks, Tailscale, and WireGuard 00:29:31 - Eric: This Is About Mutual Authentication 00:32:20 - RMM Tools and the Central Console Problem 00:33:41 - Do You Need Remote Management All the Time? 00:34:36 - Just Enough Administration Meets Just in Time 00:36:00 - Eric: I Attack the Endpoint, Not the Protocol 00:40:16 - Risk Assessment Is a SysAdmin Skill 00:42:47 - The Firewall Is Also the VPN, and Fortinet 00:45:17 - Outbound Access, Attacker's Side 00:47:32 - Is Anyone Watching Outbound Traffic? 00:50:52 - The 3am Phone Call 00:52:46 - Eric: MFA Everything, No Remember Me 00:55:44 - PAM, PIM, and Where to Read Up 00:56:14 - Nothing Revokes Itself Unless You Build It 00:58:13 - Key Takeaways: Never Rely on One Control 00:59:40 - Access Should Be Ephemeral 01:01:46 - Risk Profiles: Tomcat vs Medical Records 01:03:52 - The Tools: Tailscale, SSH, Remmina 01:07:56 - Eric's Kit: PuTTY, WinSCP, rsync 01:11:17 - Do This Monday 01:13:52 - Wrap Up and Outro Resources / Show Notes: - NBC News, Anthropic researcher Jacob Coxon resigns: https://www.nbcnews.com/tech/tech-news/anthropic-safety-researcher-resigned-warning-rapid-ai-development-gamb-rcna596767 - RentAHuman, where AI agents hire people for real world tasks: https://rentahuman.ai - Brandon Lee (vExpert), Broadcom pulled public VDDK access: https://www.virtualizationhowto.com/2026/09/leaving-vmware-just-got-harder-after-broadcom-pulled-vddk-downloads/ - CISA, hardening Fortinet devices after credential exposure: https://www.cisa.gov/news-events/alerts/2026/06/18/cisa-urges-hardening-fortinet-devices-after-reports-credential-exposure - Microsoft Learn, Entra PIM, eligible versus active access: https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-configure - Tailscale, free Personal plan covers 6 users: https://tailscale.com/pricing - WireGuard, what Tailscale manages under the hood: https://www.wireguard.com - Cisco Duo, free tier for teams of 10 or fewer: https://duo.com - Remmina, open source RDP, VNC and SSH client: https://remmina.org - PuTTY: https://www.chiark.greenend.org.uk/~sgtatham/putty/ - WinSCP: https://winscp.net - SysAdmin Weekly: https://www.sysadminweekly.com - SysAdmin Weekly Newsletter: https://newsletter.sysadminweekly.com - AndyOnTech: https://www.andyontech.com - Project Runspace: https://www.projectrunspace.org - GitHub Discussions: https://github.com/ProjectRunspace/sysadmin-weekly/discussions

0:00-1:14:30

transcript

No transcript — this publisher did not publish one.

show notes

Which protocol you use to reach the box is the least interesting decision you will make about remote access.


Andy Syrewicze and Eric Siron go after the piece they cut from the tools episode. Eric lands the sharpest version half an hour in: what you are actually doing is moving from one-sided authentication to mutual authentication. Around that sit overlay networks against the VPN concentrator, the RMM console as the most attractive target in an MSP estate, the outbound tunnel nobody watches for, and whether just-in-time access holds up at 3am with something down and nobody awake to approve it.


Chapters:

00:00:00 - Cold Open: Remote Access Gets Its Own Episode

00:01:20 - Welcome and Show Plugs

00:04:16 - News React: Anthropic Safety Researcher Resigns

00:12:54 - News React: Broadcom Pulls Public VDDK Access

00:16:21 - Nerd Hour: Eric's Hugo Migration

00:17:24 - Three Gates Against a Runaway API Bill

00:20:38 - Main Topic: The Tooling Is the Small Part

00:23:08 - SSH on 22, and the Port Change Experiment

00:24:21 - Name a Reason to Expose a Management Port

00:27:10 - Overlay Networks, Tailscale, and WireGuard

00:29:31 - Eric: This Is About Mutual Authentication

00:32:20 - RMM Tools and the Central Console Problem

00:33:41 - Do You Need Remote Management All the Time?

00:34:36 - Just Enough Administration Meets Just in Time

00:36:00 - Eric: I Attack the Endpoint, Not the Protocol

00:40:16 - Risk Assessment Is a SysAdmin Skill

00:42:47 - The Firewall Is Also the VPN, and Fortinet

00:45:17 - Outbound Access, Attacker's Side

00:47:32 - Is Anyone Watching Outbound Traffic?

00:50:52 - The 3am Phone Call

00:52:46 - Eric: MFA Everything, No Remember Me

00:55:44 - PAM, PIM, and Where to Read Up

00:56:14 - Nothing Revokes Itself Unless You Build It

00:58:13 - Key Takeaways: Never Rely on One Control

00:59:40 - Access Should Be Ephemeral

01:01:46 - Risk Profiles: Tomcat vs Medical Records

01:03:52 - The Tools: Tailscale, SSH, Remmina

01:07:56 - Eric's Kit: PuTTY, WinSCP, rsync

01:11:17 - Do This Monday

01:13:52 - Wrap Up and Outro


Resources / Show Notes:


- NBC News, Anthropic researcher Jacob Coxon resigns: https://www.nbcnews.com/tech/tech-news/anthropic-safety-researcher-resigned-warning-rapid-ai-development-gamb-rcna596767


- RentAHuman, where AI agents hire people for real world tasks: https://rentahuman.ai


- Brandon Lee (vExpert), Broadcom pulled public VDDK access: https://www.virtualizationhowto.com/2026/09/leaving-vmware-just-got-harder-after-broadcom-pulled-vddk-downloads/


- CISA, hardening Fortinet devices after credential exposure: https://www.cisa.gov/news-events/alerts/2026/06/18/cisa-urges-hardening-fortinet-devices-after-reports-credential-exposure


- Microsoft Learn, Entra PIM, eligible versus active access: https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-configure


- Tailscale, free Personal plan covers 6 users: https://tailscale.com/pricing


- WireGuard, what Tailscale manages under the hood: https://www.wireguard.com


- Cisco Duo, free tier for teams of 10 or fewer: https://duo.com


- Remmina, open source RDP, VNC and SSH client: https://remmina.org


- PuTTY: https://www.chiark.greenend.org.uk/~sgtatham/putty/


- WinSCP: https://winscp.net


- SysAdmin Weekly: https://www.sysadminweekly.com


- SysAdmin Weekly Newsletter: https://newsletter.sysadminweekly.com


- AndyOnTech: https://www.andyontech.com


- Project Runspace: https://www.projectrunspace.org


- GitHub Discussions: https://github.com/ProjectRunspace/sysadmin-weekly/discussions


links16