[81784] in Cypherpunks

home help back first fref pref prev next nref lref last post

Re: Impact of Netscape kernel hole

daemon@ATHENA.MIT.EDU (Eric Murray)
Fri Jun 13 22:29:04 1997

From: Eric Murray <ericm@lne.com>
To: nobody@huge.cajones.com
Date: Fri, 13 Jun 1997 18:08:42 -0700 (PDT)
Cc: cypherpunks@cyberpass.net
In-Reply-To: <199706132241.PAA09924@fat.doobie.com> from "Huge Cajones Remailer" at Jun 13, 97 03:41:03 pm
Reply-To: Eric Murray <ericm@lne.com>

Huge Cajones Remailer writes:
> 
> It'd be nice to have more specifics about the whole situation, but
> regardless - any preliminary threat assessments?  Exactly how widely
> exploited do you think this has been?
> 
> Tim's post (although refuted by Marc) raises some serious issues since I
> suspect that Joe Public has his secret key sitting in c:\pgp\secring.pgp

Of course that's IDEA-encrypted (or maybe something better in PGP 5) so
the attacker would need a lot of compute power to brute-force the key.
I wouldn't worry too much about someone getting my secring.pgp.  However
I would worry about them getting my mail folder, my .rhosts, my
/etc/password, etc.

> Some coherent input on the possible impact of this would be appreciated.

Yes, a description of the exploit would be very helpful.  It should
be fairly easy to hack a proxy to search and destroy the Java/Javascript
CaptiveX attacklet as it's being received.


-- 
                   Eric Murray  ericm@lne.com 
  Network security and encryption consulting.    PGP keyid:E03F65E5 


home help back first fref pref prev next nref lref last post