Re: Cisco VPN password recovery program

2005-10-19 Thread Alaric Dailey
these modems from the CodeRED worm is to change the port the web interface is listening on. Cisco seems to be doing these kinds of boneheaded things for quite sometime. -- *Alaric Dailey* Everyone deserves privacy. Thawte ‘Web of Trust’ Notary Seal <http://www.thawte.com/wot> • T

Re: Another entry in the internet security hall of shame....

2005-09-07 Thread Alaric Dailey
see the same flaw, with ATMs websites or anything else, a shared key isn't a secret, and if you are professing it is, how are you to know it hasn't been comprimised? Anne & Lynn Wheeler wrote: >Alaric Dailey wrote: > > ATMs would be infeasible if they were not a 2 factor a

Re: Another entry in the internet security hall of shame....

2005-09-07 Thread Alaric Dailey
Peter Gutmann wrote: >Alaric Dailey <[EMAIL PROTECTED]> writes: > > > >>While I admit that PKI is flawed, I don't see anyway that PSK could used >>effectively. >> >>How are PSKs going to be shared in a secure way? >>are we talking about gene

Re: Another entry in the internet security hall of shame....

2005-09-01 Thread Alaric Dailey
thing usable handed off to an attacker. Furthermore the site could be sure of the users identity, something none of the other solutions I have seen address. -- Pengdows eMail Signature

Re: Another entry in the internet security hall of shame....

2005-08-26 Thread Alaric Dailey
> > Think "end-to-end".. Even jabber has a way to encrypt messages > end-to-end using > user certificates (or PGP). > > -derek > I am aware of Jabbers support for GPG/PGP, but did I miss their support for user certificates? I have seen no indication of such support, what client supports it? Alar

Re: Another entry in the internet security hall of shame....

2005-08-24 Thread Alaric Dailey
Tim Dierks wrote: >[resending due to e-mail address / cryptography list membership issue] > >On 8/24/05, Ian G <[EMAIL PROTECTED]> wrote: > > >>Once you've configured iChat to connect to the Google Talk service, you may >>receive a warning message that states your username and password will be >