Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 2 Mar 1995 05:53:40 -0600
From:      rkw@dataplex.net (Richard Wackerbarth)
To:        Gary Roberts <gary@wcs.uq.oz.au>
Cc:        hackers@FreeBSD.org
Subject:   Re: key exchange for rlogin/telnet services?
Message-ID:  <v02110101ab7b615ba10f@[199.183.109.242]>

next in thread | raw e-mail | index | archive | help
>Mark Murray writes:
>I've followed this thread right from Jordan's original query about
>encrypting the whole session.  Some responses have suggested that you
>only need to encrypt the password passing stage.  Jordan was worried
>about the password being sniffed during an `su' if I recall correctly.

If you use s/key, you can use it for ALL passwords. That includes su.

Been there. Done that. Works fine....

This is not to say that encrypted sessions do not have value. Just that
they are not NESESSARY to accomplish password hiding.

----
Richard Wackerbarth
rkw@dataplex.net





Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?v02110101ab7b615ba10f>