[13400] in North American Network Operators' Group
Re: moving to IPv6
daemon@ATHENA.MIT.EDU (Gary E. Miller)
Wed Nov 5 03:43:16 1997
Date: Wed, 5 Nov 1997 00:35:34 -0800 (PST)
From: "Gary E. Miller" <gem@rellim.com>
Reply-To: gary miller <gem@rellim.com>
To: Jeremy Porter <jerry@fc.net>
cc: nanog@merit.edu
In-Reply-To: <199711032106.PAA11188@freeside.fc.net>
Yo Jeremy!
On Mon, 3 Nov 1997, Jeremy Porter wrote:
> If you have a payload that is encrypted and signed, there is fundementally
> no reason for the application to know anything other than a magic cookie
> return address.
SSH keeps track, forever, of the remote IP address/key pair to prevent
man-in-the-middle and trojan horse attacks. The authors mention in their
material that it is an important defense.
Check out http://www.cs.hut.fi/ssh for further info.
RGDS
GARY
---------------------------------------------------------------------------
Gary E. Miller Rellim 2680 Bayshore Pkwy, #202 Mountain View, CA 94043-1009
gem@rellim.com Tel:+1(650)964-1186 Fax:+1(650)964-1176