Re: Is SSH worth it??

From: Devdas Bhagat (dvb@users.sourceforge.net)
Date: 10/10/02


Date: Thu, 10 Oct 2002 03:40:43 +0530
From: Devdas Bhagat <dvb@users.sourceforge.net>
To: security-basics@securityfocus.com

On 09/10/02 14:34 +0100, Trevor Cushen wrote:
<snip>
Some line length fixing and quoting order fixes, please?

> Can I ask you for a url to more info on this expect language and it usage.
> Again many thanks
IIRC, O'Reilly has a book on the topic. Also, man 1 expect might be
useful. Expect is a TCl addon, but can be used without TCl.
<snip>

> > I dont like RSA without passwords caus if your machine gets compromised,
> > the attacker would have root access to another machines in your network.
> > When I needed automated scripting using ssh and scp I used this programming
> > language called EXPECT, perl includes a module that implements the expect
> > language. It goes something like this:
I prefer the term passphrase.
Use strong passphrases to protect your keys, but don't use passwords.
Passwords are stored in plain text on the box, which means that your
protection has gone from key based to password based.
See man 1 ssh-agent for a way of handling your pass phrases relatively safely.

Devdas Bhagat



Relevant Pages

  • Re: Problem with Storable qw(store_fd fd_retrieve)
    ... language. ... my $numkeys = keys %; ... As there is nothing to read, the magic number check fails. ...
    (comp.lang.perl.misc)
  • Re: Statement on Schildt submitted to wikipedia today
    ... You use language oddly. ... Perhaps to you Schildt is an owned property. ... stack" are disparaged as misleading. ...
    (comp.lang.c)
  • Re: On the development of C
    ... The concepts are a good jumping off point. ... Lots of things other languages put in the language ... Many libraries exist that implement counted strings, ...
    (comp.lang.c)
  • Re: A lurkers take on C.L.C pedantry
    ... It's for discussing the C language. ... DEAD groups won't be singing the praises of eclipse. ... programmer in that he likes to dress everything up in obscure rhetoric ...
    (comp.lang.c)
  • Re: My Pharmacist Friend Called Me Yesterday
    ... > Heh Yeah, lots of things I could have done IF I could have gotten into ... > without knowing the first thing about their computers. ... > recommended the passwords NOT be taped to the monitor. ...
    (alt.2600)