Re: OPIE considered insecure



On 2009-Feb-09 15:30:33 -0800, Lyndon Nerenberg <lyndon@xxxxxxxxxx> wrote:
From what you're describing, I would be more inclined to carry a bootable
OS on that USB stick and reboot into that.

Keep in mind that libraries, internet cafes etc aren't going to be keen
on you turning up with some (to them) random USB stick and wanting to
reboot their pride-and-joy off it.

I suspect your choices are to either use OPIE (or some adaption thereof)
with ssh on an untrusted computer and assume that anything you type will
be logged or carry your own trusted computer and use some form of wireless
(3G, NextG etc) to communicate with your systems.

Note that using very large sequence numbers should slow down an
attacker (though only linerarly) since they still need to iterate
MD5 by that many rounds.

--
Peter Jeremy

Attachment: pgptkTNv198Nn.pgp
Description: PGP signature



Relevant Pages

  • psm (pr kern/59067) and irq 16 rate, some observations
    ... It's clear that I am seeing the same out of control irq16 that some ... With no usb devices, the usb kernel ... After rebooting I tried the trackball on usb again, ... along with my keyboard, so I had to ssh in, rebuild the kernel, and reboot. ...
    (freebsd-current)
  • Re: modularized kernels
    ... I don't usually compile modules I don't plan to use. ... Linux, being a monolithic kernel, if any "subsystem" is in a serious state ... the only action I would trust is a reboot. ... I have encountered a USB controller problem a couple times on my Linux ...
    (comp.os.linux.development.system)
  • Re: cant boot F19 system
    ... And if you run it a second time with: ... It did not mount my external USB hard drive, ... So it should not reboot. ... That whole poweroff sequence should record a lot of debug ...
    (Fedora)
  • Re: WM6 Activesync with Exchange Server "Waiting for Network" problem
    ... Cisco ASA5505 Firewall configured to allow SSL to Exchange Server ... If I reboot my phone with the USB cable connected, I can use USB but not ... If I reboot my phone and use OTA sync, I cannot use USB until I reboot ...
    (microsoft.public.pocketpc.activesync)
  • USB install for HP49G+/HP50 on Win98 system
    ... had the problem that I would have to reboot the computer each time I ... I went to c:\Program Files\Hewlett-Packard\conn4x folder and looked ... the calc under my USB. ... quite right about this USB install for Windows. ...
    (comp.sys.hp48)