Great Circle Associates Firewalls
(July 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Fw: Remote Access Software
From: David Miller <isdmill @ gatekeeper . ddp . state . me . us>
Date: Tue, 30 Jul 1996 09:35:34 -0400 (EDT)
To: C Matthew Curtin <cmcurtin @ research . megasoft . com>
Cc: LAN Administrator <bcislan @ txdirect . net>, firewalls @ GreatCircle . COM
In-reply-to: <199607301117 . HAA19841 @ goffette . research . megasoft . com>

On Tue, 30 Jul 1996, C Matthew Curtin wrote:

> >>>>> "jlb" == LAN Administrator <bcislan @
 txdirect .
 net> writes:
> 
> jlb> We are researching a product called Ascend Max used in
> jlb> cooperation with Security Dynamics SecurID and it looks very
> jlb> good. Pretty expensive but very secure.
> 
> Is SecurID an encrypted link? It's foggy-memory-time, but don't they
> just do hand-held authenticator things, or am I thinking of someoen
> else.

No, SecurID is only authentication, not encryption

> Anyway, hand-held authenticators are only good for passive attacks
> like sniffing. Given the relative ease with which someone can turn
> sniffing into session hijacking, cleartext one-time passwords aren't
> very useful. I would dismiss the product unless it has the ability for
> encrypted links, like SSH or STel.

I disagree:)

First, it screens out a large class of attacks (sniffing passwords).
Second, you can't hijack a connection until one is established, and the
hijackee may very well complain.  Third, the hijacked session may or may
not get the hijacker where she wants to go, and if the ultimate
destination is protected by SecurID the hijacked session won't help
without the card.

I agree that it's not a 100% fix.  End to end encryption would be a lot
closer.  Just because laws against murder don't prevent all murders
doesn't mean they're useless:)

--- David Miller

----------------------------------------------------------------------------
		It's *amazing* what one can accomplish when 
		    one doesn't know what one can't do!



References:
Indexed By Date Previous: RE: Java security
From: ray @ rayk . com (Ray Kaplan)
Next: Re: Sidewinder Versus EagleRaptor
From: Frederick M Avolio <avolio @ tis . com>
Indexed By Thread Previous: Re: Fw: Remote Access Software
From: C Matthew Curtin <cmcurtin @ research . megasoft . com>
Next: RE: Remote Access Software
From: Bill Maples <Bill . Maples @ express-hr . com>

Google
 
Search Internet Search www.greatcircle.com