>> Passwords are often sent in the clear, too. So
>> anybody able to snoop the network, can capture
>> the passwords. They're often /only/ hidden
>> from the person typing them in.

>> A bit OT, but in this line, does anyone have
>> experience with Anonymizer using SSH1 on the
>> Amiga? It would seem a good way to prevent
>> anyone on the cable loop from sniffing out a pw
>> or any other sensitive info.

> SSH as a substitute for Telnet certainly avoids
> the password-sniffing problems, and it also
> offers authentication methods more secure than
> passwords. SSH port forwarding can be used in
> *some* cases to protect other TCP-based
> services, but one needs to preconfigure a tunnel
> for each combination of host and port to be
> used, and the security is only valid for the
> path to the SSH server, which might not be the
> target server if the target server doesn't
> support SSH. The first requirement makes it
> practically useless for things like web access,
> where SSL is a much more reasonable approach.

> AFAIK Anonymizer is concerned just with web
> browsing, and is mainly concerned with issues
> other than passwords, so SSH doesn't have much
> bearing on it.

Actually, Anonymizer now offers SSH1 with port
forwarding to protect against sniffing. It
forwards port 80 for http, 110 & 25 for mail,
119 for news. It's a snap to setup on the pc,
but SSH1 on the Amiga is a straight unix port
and I'm not that clear on how to explain to the
program that I've root access so it will allow
port forwarding. Anonymizer's tech support is
limited to windows.

-- 

To unsubscribe send "unsubscribe miami-talk-ml" to
"[EMAIL PROTECTED]". For help on list commands send "help" to
"[EMAIL PROTECTED]".


Reply via email to