home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.security.misc
- Path: sparky!uunet!indetech!cirrus!dhesi
- From: dhesi@cirrus.com (Rahul Dhesi)
- Subject: Re: unhappy about overloading finger
- Message-ID: <1992Jul26.211735.5134@cirrus.com>
- Sender: news@cirrus.com
- Organization: Cirrus Logic Inc.
- References: <1992Jul24.100650.9235@nntpd.lkg.dec.com> <dag.712016415@ossi.com>
- Date: Sun, 26 Jul 1992 21:17:35 GMT
- Lines: 15
-
- In <dag.712016415@ossi.com> dag@ossi.com (Darren Alex Griffiths) writes:
-
- >This allows the pond scum who try and
- >break into systems to get a list off all users and then attempt to crack the
- >password for each of these users. Even worse, [you can find idle usernames].
-
- Isn't this carrying security by obscurity just a bit too far? In
- today's networking world, finding usernames is too easy. Just scan
- Usenet and collect email addresses -- you can build up a HUGE
- collection in a day. If you want idle usenames, well, do another scan
- a month later, and look for the ones that aren't found any more.
- --
- Rahul Dhesi <dhesi@cirrus.com>
- also: dhesi@rahul.net
- "He's metabolically challenged, Jim."
-