home *** CD-ROM | disk | FTP | other *** search
Wrap
Newsgroups: sci.crypt Path: sparky!uunet!sdl!tal From: limonce@pilot.njin.net (Tom Limoncelli) Subject: Re: Secure netnews Message-ID: <f12@pilot.njin.net> Summary: Oh nothing important. I just have this Perl script that I use to generate this stream of posts whenever someone posts the silly suggestion that netnews could be made secure. Keywords: silly automated Sender: tal@Warren.MENTORG.COM (Tom Limoncelli) Organization: New Jersey Intercampus Network References: <f11@drew.drew.edu> <f10@Warren.MENTORG.COM> <f9@pilot.njin.net> <f8@drew.drew.edu> <f7@Warren.MENTORG.COM> <f6@pilot.njin.net> <f5@drew.drew.edu> <f4@Warren.MENTORG.COM> <f3@pilot.njin.net> <f2@drew.drew.edu> <f1@Warren.MENTORG.COM> <9208182108.AA09132@news.cis.ohio-state.edu> Date: Wed, 19 Aug 1992 23:15:56 GMT Lines: 30 In <f11@drew.drew.edu> tlimonce@drew.drew.edu (Tom Limoncelli) writes: > Then do it. Design and implement secure news. Since TCP isn't entirely > secure, you'll have to add some authentication protocol on top of that. > Since UUCP is spoofable, you'll need to use it there as well. It's not > going to be easy. However, Brad Templeton is always looking to take a dare and would respond to this paragraph. He'll suggest his cancel-password scheme. Though he'll admit something like way back in <1992Jun24.065423.17252@clarinet.com> he <brad@clarinet.com> wrote: > I pointed out back then the flaw in my own scheme. The concept of > a cancel daemon *is* useful for things like renaming groups, deleting > groups, post-moderating groups and yes, even the legitimate control of > crossposting. (For example, if the charter of alt.cascade had read, > "cascades are not to be crossposted to other groups" then a properly > working cancel-daemon would be appropriate.) > > Cancel passwords would make all this difficult or impossible. Tom -- There is nothing wrong with talking to yourself... at least you know you're going to win any arguments! -- Tom Limoncelli -- tal@warren.mentorg.com (work) -- tal@plts.uucp (play) "Oh! I thought it was one of those useless demos of everything that a GUI builder could do." -Anonymous person watching demo of Solaris 2.0's graphical tool for managing NIS+