[13400] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: moving to IPv6

daemon@ATHENA.MIT.EDU (Gary E. Miller)
Wed Nov 5 03:43:16 1997

Date: Wed, 5 Nov 1997 00:35:34 -0800 (PST)
From: "Gary E. Miller" <gem@rellim.com>
Reply-To: gary miller <gem@rellim.com>
To: Jeremy Porter <jerry@fc.net>
cc: nanog@merit.edu
In-Reply-To: <199711032106.PAA11188@freeside.fc.net>

Yo Jeremy!

On Mon, 3 Nov 1997, Jeremy Porter wrote:

> If you have a payload that is encrypted and signed, there is fundementally
> no reason for the application to know anything other than a magic cookie
> return address.

SSH keeps track, forever, of the remote IP address/key pair to prevent
man-in-the-middle and trojan horse attacks.  The authors mention in their 
material that it is an important defense.

Check out http://www.cs.hut.fi/ssh for further info.

RGDS
GARY
---------------------------------------------------------------------------
Gary E. Miller Rellim 2680 Bayshore Pkwy, #202 Mountain View, CA 94043-1009
        gem@rellim.com  Tel:+1(650)964-1186 Fax:+1(650)964-1176


home help back first fref pref prev next nref lref last post