[171] in Security FYI
[Security-fyi] athena.dialup.mit.edu to require encryption
daemon@ATHENA.MIT.EDU (Jonathon Weiss)
Thu Feb 20 06:03:20 2003
Message-Id: <200302200646.BAA23312@bearing-an-hourglass.mit.edu>
From: Jonathon Weiss <jweiss@mit.edu>
To: bug-dialup@mit.edu
Date: Thu, 20 Feb 2003 01:46:48 -0500
Errors-To: security-fyi-bounces@mit.edu
This change has been made. Yes, it happened one day late (at least
partially due to the snow.) My appologies for the delay.
Jonathon
------- Forwarded Message
Message-Id: <200301210655.BAA29672@bearing-an-hourglass.mit.edu>
From: Jonathon Weiss <jweiss@MIT.EDU>
To: bug-dialup@mit.edu
X-bcc: itpartners, infosys, cfyi, security-internal, sipb-office, hd, security-fyi
Subject: athena.dialup.mit.edu to require encryption
Date: Tue, 21 Jan 2003 01:55:49 -0500
Sender: jweiss@MIT.EDU
As you may be aware, Athena Server Operations and the MIT Network
Security team have been working together to eliminate connections to
the Athena dialups (Athena.dialup.mit.edu, x.dialup.mit.edu, etc.)
that allow passwords to travel over the network without encrypting
them. This is being done as part of a larger project to eliminate all
unencrypted passwords from MITnet. Last fall we disabled unencrypted
connections (both telnet and ftp) to the dialups originating from
on-campus machines, and machines connected via tether. Since then we
have continued to notify, on a weekly basis, users who make
unencrypted connections to the dialups from off-campus. The next
milestone is to disable unencrypted connections to the dialups
originating from off-campus machines. We are planning to do this very
early in the morning of Wednesday, February 19th, 2003 (a little under
a month from now). If this affects you personally, you should have
already heard from us. However, some of you may have co-workers who
are affected even if you are not.
Please let us know if you have any questions or concerns.
Jonathon Weiss
jweiss@mit.edu
Team Leader, MIT/IS Athena Server Operations
------- End of Forwarded Message
_______________________________________________
Security-fyi mailing list
Security-fyi@mit.edu
http://mailman.mit.edu/mailman/listinfo/security-fyi