<<On Sun, 16 Jul 2000 16:46:58 -0400, Christopher Masto <[EMAIL PROTECTED]> said:

> Huh?  Security through ignorance?

Remember that `lpr' is setuid-root and uses a ``privileged'' port for
its communications.  Many sites may still be using trusted-host
``authentication'' internally, and LPRng's ``feature'' may enable a
compromise of some such service.  (Got enough scare quotes there?)


