Re: Need urgent help regarding security

From: Arne (arne_woerner_at_yahoo.com)
Date: 11/22/05

  • Next message: Roger Marquis: "Re: Need urgent help regarding security"
    Date: Tue, 22 Nov 2005 11:12:30 -0800 (PST)
    To: Roger Marquis <marquis@roble.com>, freebsd-security@freebsd.org
    
    

    --- Roger Marquis <marquis@roble.com> wrote:
    > Obscurity is an important and wholly necessary part
    > of the security toolkit. Take passwords for example.
    > Defining a non-dictionary password is security by
    > obscurity. It is, however, weak protection if you
    > do not also log dictionary attacks and blackhole
    > offenders before they can try many username/password
    > pairs.
    >
    I can say that again... :-)

    I personally do not like passwords, because:
    1. I could forget it.
    2. A bad guy could treat me bad in order to get the password.

    So I was very happy, when I found out, that ssh protocol offers
    this passphrase-less, password-less RSA (today it seems to be DSA)
    authentication, which seems to be very secure, and which makes me
    uninteresting for authentication and for a bad guy (he or she only
    needs my hard disc, which he or she can get without hurting me).

    Maybe that could help in this specific security problem
    discussion.

    Furthermore I would ask, if it might be a good idea in this case
    to use a good-guy list instead of a bad-guy list.

    Ceterum censeo: Finger prints make everything worse (not just for
    thiefs, who have to wear gloves nowadays), because I have heard of
    a case, where a robber took away the ring-finger of his victim,
    because his victim was unable to get off the ring (published in
    german TV by a governmental broadcasting carrier (ZDF) in
    "Aktenzeichen XY ... noch nicht gelöst" (which translates to "case
    number XY ... not solved yet")). There has been a case near
    Kiel,SH,F.Rep.Germ, where the robber became a killer, because the
    victim refused to give 10USD, that belonged to his employer.

    -Arne
    who said the mother of all passwords loudly in the public, while
    one of his colleagues was talking to him on the phone

                    
    __________________________________
    Yahoo! FareChase: Search multiple travel sites in one click.
    http://farechase.yahoo.com
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"


  • Next message: Roger Marquis: "Re: Need urgent help regarding security"

    Relevant Pages

    • Re: Concepts: Security and Obscurity
      ... Passwords have their issues - but they are not a obscurity factor. ... encryption algorithms do not suffer from security ... Many ports advertise themselves ...
      (Security-Basics)
    • Re: OT: disabling APIs to prevent keystroke logging
      ... I have googled keylogging but there's a ton of info a mostly ads. ... I've dealt with security issues in my work as a software ... Researcher refutes Microsoft's account of hijacked Hotmail passwords ... passwords were obtained in a massive phishing attack. ...
      (alt.sys.pc-clone.dell)
    • RE: passwords in asp pages
      ... and using integrated security for connecting to the database- this will ... remove cleartext passwords from the files. ... grab the raw asp source from the server. ... to facilitate one-on-one interaction with one of our expert instructors. ...
      (Security-Basics)
    • Re: Oh Dear, Where to start?!
      ... > sort of security solution? ... > use, passwords, physical security, backup/disaster ... > admin, network admin, tech support, programming, and ... Theres lots of software out there for backups. ...
      (Security-Basics)
    • Re: Final Year Project Brainstorming
      ... An interesting and always relevant topic is passwords. ... with a real-life scenario where Ubuntu's security is better than Vista ... The computers were very old so they were told they would have to ... Figure the cost of IT person for Vista vs ...
      (Ubuntu)

  • Quantcast