[49645] in Cypherpunks

home help back first fref pref prev next nref lref last post

Telnet-ietf: AUTH, ENCRYPT

daemon@ATHENA.MIT.EDU (Name Withheld by Request)
Fri Feb 9 14:16:17 1996

Date: Fri, 9 Feb 1996 20:10:07 +0100
To: cypherpunks@toad.com
From: anon-remailer@utopia.hacktic.nl (Name Withheld by Request)


Heads up:
	A discussion is starting up on the telnet-ietf list re: adding
message integrity checking to option negotiation, so it can't be hacked
with an active attack to defeat, for example, the AUTH and ENCRYPT options.
Highlights:
	- Authentication and encryption are (should be) orthogonal.
	- The "default" encryption should be something stronger than DES
	  OFB, which supposedly was chosen to accomodate dog-slow PCs.
	- Negotiation for non-authenticated, non-encrypted connections has to
	  be protected, too, to prevent attacks.

'telnet berserkly.cray.com 23000' gets you to an interactive browser of the
list archives.  Subscriptions to telnet-ietf-request@cray.com.

a


home help back first fref pref prev next nref lref last post