
059 - How Should SysAdmins Handle Remote Access in 2026?
transcript
show notes
Which protocol you use to reach the box is the least interesting decision you will make about remote access.
Andy Syrewicze and Eric Siron go after the piece they cut from the tools episode. Eric lands the sharpest version half an hour in: what you are actually doing is moving from one-sided authentication to mutual authentication. Around that sit overlay networks against the VPN concentrator, the RMM console as the most attractive target in an MSP estate, the outbound tunnel nobody watches for, and whether just-in-time access holds up at 3am with something down and nobody awake to approve it.
Chapters:
00:00:00 - Cold Open: Remote Access Gets Its Own Episode
00:01:20 - Welcome and Show Plugs
00:04:16 - News React: Anthropic Safety Researcher Resigns
00:12:54 - News React: Broadcom Pulls Public VDDK Access
00:16:21 - Nerd Hour: Eric's Hugo Migration
00:17:24 - Three Gates Against a Runaway API Bill
00:20:38 - Main Topic: The Tooling Is the Small Part
00:23:08 - SSH on 22, and the Port Change Experiment
00:24:21 - Name a Reason to Expose a Management Port
00:27:10 - Overlay Networks, Tailscale, and WireGuard
00:29:31 - Eric: This Is About Mutual Authentication
00:32:20 - RMM Tools and the Central Console Problem
00:33:41 - Do You Need Remote Management All the Time?
00:34:36 - Just Enough Administration Meets Just in Time
00:36:00 - Eric: I Attack the Endpoint, Not the Protocol
00:40:16 - Risk Assessment Is a SysAdmin Skill
00:42:47 - The Firewall Is Also the VPN, and Fortinet
00:45:17 - Outbound Access, Attacker's Side
00:47:32 - Is Anyone Watching Outbound Traffic?
00:50:52 - The 3am Phone Call
00:52:46 - Eric: MFA Everything, No Remember Me
00:55:44 - PAM, PIM, and Where to Read Up
00:56:14 - Nothing Revokes Itself Unless You Build It
00:58:13 - Key Takeaways: Never Rely on One Control
00:59:40 - Access Should Be Ephemeral
01:01:46 - Risk Profiles: Tomcat vs Medical Records
01:03:52 - The Tools: Tailscale, SSH, Remmina
01:07:56 - Eric's Kit: PuTTY, WinSCP, rsync
01:11:17 - Do This Monday
01:13:52 - Wrap Up and Outro
Resources / Show Notes:
- NBC News, Anthropic researcher Jacob Coxon resigns: https://www.nbcnews.com/tech/tech-news/anthropic-safety-researcher-resigned-warning-rapid-ai-development-gamb-rcna596767
- RentAHuman, where AI agents hire people for real world tasks: https://rentahuman.ai
- Brandon Lee (vExpert), Broadcom pulled public VDDK access: https://www.virtualizationhowto.com/2026/09/leaving-vmware-just-got-harder-after-broadcom-pulled-vddk-downloads/
- CISA, hardening Fortinet devices after credential exposure: https://www.cisa.gov/news-events/alerts/2026/06/18/cisa-urges-hardening-fortinet-devices-after-reports-credential-exposure
- Microsoft Learn, Entra PIM, eligible versus active access: https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-configure
- Tailscale, free Personal plan covers 6 users: https://tailscale.com/pricing
- WireGuard, what Tailscale manages under the hood: https://www.wireguard.com
- Cisco Duo, free tier for teams of 10 or fewer: https://duo.com
- Remmina, open source RDP, VNC and SSH client: https://remmina.org
- PuTTY: https://www.chiark.greenend.org.uk/~sgtatham/putty/
- WinSCP: https://winscp.net
- SysAdmin Weekly: https://www.sysadminweekly.com
- SysAdmin Weekly Newsletter: https://newsletter.sysadminweekly.com
- AndyOnTech: https://www.andyontech.com
- Project Runspace: https://www.projectrunspace.org
- GitHub Discussions: https://github.com/ProjectRunspace/sysadmin-weekly/discussions
- https://www.nbcnews.com/tech/tech-news/anthropic-safety-researcher-resigned-warning-rapid-ai-development-gamb-rcna596767nbcnews.com
- https://rentahuman.airentahuman.ai
- https://www.virtualizationhowto.com/2026/09/leaving-vmware-just-got-harder-after-broadcom-pulled-vddk-downloads/virtualizationhowto.com
- https://www.cisa.gov/news-events/alerts/2026/06/18/cisa-urges-hardening-fortinet-devices-after-reports-credential-exposurecisa.gov