-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Damn, print it, tape it to the wall, and xerox it for all employees.
This is exactly what I am talking about.
Kudos.
Mike
eEye Digital Security Team
www.eEye.com
Fingerprint:
AD0F 16F9 0067 7772 EFA9 996F 9AD2 5F16 A6AF EA7C
- ----- Original Message -----
From: "Phil Connolly" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Wednesday, December 22, 1999 12:16 PM
Subject: Re: [IMail Forum] [w00giving '99 #11] IMail's
passwordencryption scheme
> I'm sorry to pollute this list with yet one more lame message about
> this lame topic, but the fact is I'm pretty annoyed, for a few
> reasons that I hope create several NEW list topics:
>
> First, several people are pissed off that some "source code" was
> publicly released. These people completely miss the point. The
> significant portion of Mike@eEye's alert is the useless encryption
> algorithym used by ipswitch, not a snippet of example code. A
> programmer doesn't even NEED that code to create an exploit. It
> was included as a "proof of concept" for
> non-programmers like me.
>
> Second, the released encryption information (whether released now
> or a year ago, I don't care) demonstrates a potential security
> problem. Some have argued that "securing the console" brings them
> peace of mind. Well, to me, security is like an onion: it has
> lots and lots of layers, from the firewall to the securing the box
> to securing the OS and its the services to securing the
> applications. OK, so fine, your "console" is secure. Can you
> guarantee that there is not some other hole somewhere else? Ever
> heard of a buffer overflow? That's a place where some jerk can
> attempt to execute arbitrary code, so picture that code digging
> through the ipswitch password keys looking for the one root.
>
> Third, ipswitch can choose NOT to address this. I can choose NOT
> to use the IMail user database and use instead NT or an external.
> At least now that I have this information, I can make an
> intelligent decision based on weighing risks. And don't tell me
> that the information didn't have to include the encryption
> algorithym, because in a case like this, actually seeing it drives
> home the point just how unsecure it is. If someone just says: "the
> encryption can be cracked" and leaves it that, I say so what. Any
> encryption can be cracked. The question is really how easily can
> it be cracked?.
>
> Sorry for long-winded waste of bandwidth, but it sort of built up
> as I followed the thread this morning.
>
> -phil.
>
> Please visit http://www.ipswitch.com/support/mailing-lists.html
> to be removed from this list.
-----BEGIN PGP SIGNATURE-----
Version: PGPfreeware 6.5.2 for non-commercial use <http://www.pgp.com>
iQA/AwUBOGGg2JrSXxamr+p8EQJOQACeP92JX70lfDLe6WZ17tuaGqp3kM4An3yQ
dH+yolwPJbCbELyYMRG2VJZK
=vAQV
-----END PGP SIGNATURE-----
Please visit http://www.ipswitch.com/support/mailing-lists.html
to be removed from this list.