-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Damn, print it, tape it to the wall, and xerox it for all employees.
This is exactly what I am talking about.

Kudos.

Mike
eEye Digital Security Team
www.eEye.com

Fingerprint:
AD0F 16F9 0067 7772 EFA9  996F 9AD2 5F16 A6AF EA7C
- ----- Original Message ----- 
From: "Phil Connolly" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Wednesday, December 22, 1999 12:16 PM
Subject: Re: [IMail Forum] [w00giving '99 #11] IMail's
passwordencryption scheme


> I'm sorry to pollute this list with yet one more lame message about
> this lame topic, but the fact is I'm pretty annoyed, for a few
> reasons that I hope create several NEW list topics:
> 
> First, several people are pissed off that some "source code" was
> publicly released.  These people completely miss the point.  The
> significant portion of Mike@eEye's alert is the useless encryption
> algorithym used by ipswitch, not a snippet of example code.  A
> programmer doesn't even NEED that code to create an exploit.  It
> was included as a "proof of concept" for
> non-programmers like me.
> 
> Second, the released encryption information (whether released now
> or a year ago, I don't care) demonstrates a potential security
> problem.  Some have argued that "securing the console" brings them
> peace of mind.  Well, to me, security is like an onion:  it has
> lots and lots of layers, from the firewall to the securing the box
> to securing the OS and its the services to securing the
> applications.  OK, so fine, your "console" is secure.  Can you
> guarantee that there is not some other hole somewhere else?  Ever
> heard of a buffer overflow? That's a place where some jerk can
> attempt to execute arbitrary code, so picture that code digging
> through the ipswitch password keys looking for the one root.
> 
> Third, ipswitch can choose NOT to address this.  I can choose NOT
> to use the IMail user database and use instead NT or an external. 
> At least now that I have this information, I can make an
> intelligent decision based on weighing risks.  And don't tell me
> that the information didn't have to include the encryption
> algorithym, because in a case like this, actually seeing it drives
> home the point just how unsecure it is.  If someone just says: "the
> encryption can be cracked" and leaves it that, I say so what.  Any
> encryption can be cracked.  The question is really how easily can
> it be cracked?.
> 
> Sorry for long-winded waste of bandwidth, but it sort of built up
> as I followed the thread this morning.
> 
> -phil.
> 
> Please visit http://www.ipswitch.com/support/mailing-lists.html 
> to be removed from this list.

-----BEGIN PGP SIGNATURE-----
Version: PGPfreeware 6.5.2 for non-commercial use <http://www.pgp.com>

iQA/AwUBOGGg2JrSXxamr+p8EQJOQACeP92JX70lfDLe6WZ17tuaGqp3kM4An3yQ
dH+yolwPJbCbELyYMRG2VJZK
=vAQV
-----END PGP SIGNATURE-----


Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

Reply via email to