Re: OPIE considered insecure
- From: Dag-Erling Smørgrav <des@xxxxxx>
- Date: Wed, 11 Feb 2009 12:47:28 +0100
Jason Stone <freebsd-security@xxxxxxxx> writes:
Right, but that's not the problem they're trying to solve. They're
trying to solve the problem of logging in _from_ an untrusted machine,
to a trusted machine.
If the machine you're logging in *from* is untrusted, you're SOL. Even
with OPIE or similar mechanisms, somebody might piggyback on your SSH
connection. The best you can do is boot from a CD or USB fob you
prepared yourself, and even then, there might be a hardware key logger
installed on the computer.
DES
--
Dag-Erling Smørgrav - des@xxxxxx
_______________________________________________
freebsd-security@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@xxxxxxxxxxx"
- Follow-Ups:
- Re: OPIE considered insecure
- From: Daniel Roethlisberger
- Re: OPIE considered insecure
- References:
- OPIE considered insecure
- From: Benjamin Lutz
- Re: OPIE considered insecure
- From: Daniel Roethlisberger
- Re: OPIE considered insecure
- From: Lyndon Nerenberg
- Re: OPIE considered insecure
- From: Jason Stone
- OPIE considered insecure
- Prev by Date: Re: ipv6 and ipfw
- Next by Date: Re: OPIE considered insecure
- Previous by thread: Re: OPIE considered insecure
- Next by thread: Re: OPIE considered insecure
- Index(es):
Relevant Pages
|