>by "telnet" I am including one-time passwords, ssh and other similar
>items.
>
>David Lang
telnet != ssh
Also, just using one time passwords to authenticate to a firewall is
not really sufficient in today's Internet (and on today's intranets)
because of the lack of privacy of the datastream and also the fact
that it is now possible for a reasonbly sophisticated individual
to modify the datastream in transit or just hijack the TCP session.
H. Morrow Long, Yale Univ IT ISO -Info Technology Services Info Security Officer
175 Whitney Avenue, New Haven, CT 06520-8276, (203)432-1248(voice) 432-0593(FAX)
INET: http://pantheon.yale.edu/~long/ mailto:Morrow .
Long @
yale .
edu
PAGE: (203)370-3081, (800)347-2574, mailto:1165469 @
pager .
mcb .
com PIN# 1165469
PGP 1024/54F9FD69 1997/08/25 fp 97 ED E7 9D 41 8A 90 8C 4D 7C 22 56 80 BA 84 09
|
|