| home | help | back | first | fref | pref | prev | next | nref | lref | last | post |
Date: Fri, 9 Feb 1996 20:10:07 +0100 To: cypherpunks@toad.com From: anon-remailer@utopia.hacktic.nl (Name Withheld by Request) Heads up: A discussion is starting up on the telnet-ietf list re: adding message integrity checking to option negotiation, so it can't be hacked with an active attack to defeat, for example, the AUTH and ENCRYPT options. Highlights: - Authentication and encryption are (should be) orthogonal. - The "default" encryption should be something stronger than DES OFB, which supposedly was chosen to accomodate dog-slow PCs. - Negotiation for non-authenticated, non-encrypted connections has to be protected, too, to prevent attacks. 'telnet berserkly.cray.com 23000' gets you to an interactive browser of the list archives. Subscriptions to telnet-ietf-request@cray.com. a
| home | help | back | first | fref | pref | prev | next | nref | lref | last | post |