I'm sorry to pollute this list with yet one more lame message about this
lame topic, but the fact is I'm pretty annoyed, for a few reasons that I
hope create several NEW list topics:

First, several people are pissed off that some "source code" was publicly
released.  These people completely miss the point.  The significant portion
of Mike@eEye's alert is the useless encryption algorithym used by ipswitch,
not a snippet of example code.  A programmer doesn't even NEED that code to
create an exploit.  It was included as a "proof of concept" for
non-programmers like me.

Second, the released encryption information (whether released now or a year
ago, I don't care) demonstrates a potential security problem.  Some have
argued that "securing the console" brings them peace of mind.  Well, to me,
security is like an onion:  it has lots and lots of layers, from the
firewall to the securing the box to securing the OS and its the services to
securing the applications.  OK, so fine, your "console" is secure.  Can you
guarantee that there is not some other hole somewhere else?  Ever heard of a
buffer overflow? That's a place where some jerk can attempt to execute
arbitrary code, so picture that code digging through the ipswitch password
keys looking for the one root.

Third, ipswitch can choose NOT to address this.  I can choose NOT to use the
IMail user database and use instead NT or an external.  At least now that I
have this information, I can make an intelligent decision based on weighing
risks.  And don't tell me that the information didn't have to include the
encryption algorithym, because in a case like this, actually seeing it
drives home the point just how unsecure it is.  If someone just says: "the
encryption can be cracked" and leaves it that, I say so what.  Any
encryption can be cracked.  The question is really how easily can it be
cracked?.

Sorry for long-winded waste of bandwidth, but it sort of built up as I
followed the thread this morning.

-phil.

Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

Reply via email to