Re: OPIE considered insecure
- From: Daniel Roethlisberger <daniel@xxxxxx>
- Date: Wed, 11 Feb 2009 13:22:00 +0100
Dag-Erling Smørgrav <des@xxxxxx> 2009-02-11:
Jason Stone <freebsd-security@xxxxxxxx> writes:
Right, but that's not the problem they're trying to solve.
They're trying to solve the problem of logging in _from_ an
untrusted machine, to a trusted machine.
If the machine you're logging in *from* is untrusted, you're
SOL. Even with OPIE or similar mechanisms, somebody might
piggyback on your SSH connection. The best you can do is boot
from a CD or USB fob you prepared yourself, and even then,
there might be a hardware key logger installed on the computer.
Or the BIOS trojaned.
Your statement is of course correct, logging in from untrusted
machines can never be secure. However, OPIE still raises the bar
on the required capabilities for an attack (active, real-time
attack versus passive keylogging / data dumping).
--
Daniel Roethlisberger
http://daniel.roe.ch/
_______________________________________________
freebsd-security@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@xxxxxxxxxxx"
- Follow-Ups:
- Re: OPIE considered insecure
- From: Dag-Erling Smørgrav
- Re: OPIE considered insecure
- References:
- OPIE considered insecure
- From: Benjamin Lutz
- Re: OPIE considered insecure
- From: Daniel Roethlisberger
- Re: OPIE considered insecure
- From: Lyndon Nerenberg
- Re: OPIE considered insecure
- From: Jason Stone
- Re: OPIE considered insecure
- From: Dag-Erling Smørgrav
- OPIE considered insecure
- Prev by Date: Re: OPIE considered insecure
- Next by Date: Re: OPIE considered insecure
- Previous by thread: Re: OPIE considered insecure
- Next by thread: Re: OPIE considered insecure
- Index(es):
Relevant Pages
|