Web app authentication methods - do you agree?

2002-06-07 Thread John Christopher
I am interested in hearing your opinions regarding the advice given in an article entitled Dos and Don’ts of Client Authentication on the Web which can be found at http://pdos.lcs.mit.edu/cookies/pubs/webauth:tr.pdf Do you see any problems with the advice given in this article? Thanks - J

tripwire config

2001-12-30 Thread John Christopher
Hi - A few questions about configuring Tripwire (BTW, I am using the academic release version on various Linux, FreeBSD and OpenBSD boxes, which are configured as single-function servers [i.e. www servers, firewalls, database servers, etc.]): 1. When creating the policy file that instructs

security tools with email notification

2001-11-30 Thread John Christopher
Hi - Many security tools (logcheck, for example) provide a facility for sending warnings, etc. to an email address. 1. Can anyone see any security problems with sending such info to a yahoo.com email address (in other words, how secure is yahoo mail)? 2. Is it possible for an attacker to