Re: Security through obscurity? (was: ssh + compiled-in SKEY supportconsidered harmful?)

2002-04-23 Thread Frank Mayhar
Robert, it's really, really simple. For new installs, install the new, more secure behavior. Be sure to loudly document this behavior so that those of us who expect the _old_ behavior don't get bitten by the change. And don't change the old behavior in upgrades of existing systems. As I said i

Re: Security through obscurity? (was: ssh + compiled-in SKEY supportconsidered harmful?)

2002-04-23 Thread Frank Mayhar
Jochem Kossen wrote: > It does work. But i think you mean the tcp connections. > Does that mean you vote for enabling _all_ services? They don't work out > of the box as well... This is ridiculous. You know as well as I do that that's _not_ what Greg means. Just don't change stuff out from und