i was going to suggest that, too, but if their security policy does 
not allow anon cvs, it won't allow anon ssh either. moreover, the 
encryption puts a considerable load on the server for no real purpose.

the downside of tunneling (and of transmitting everything and their 
grandmother over port 80, for that matter) is that you can't enforce 
policies by packet filtering any more.

granted, i tunnel in and out of networks like there's no tomorrow, 
but then i'm a _sysadmin_. i would *hate* the thought that my 
_users_ did it, too :-D

