> Any encryption can be cracked.
> The question is really how easily can it be cracked?.

That's one question. My question would be, what will the cracker do with
this knowledge, once it is acquired?

Perhaps it never occurred to Mike that he could consult with the affected
parties - like subscribers to this forum - and ask what they would like him
to do about it. My guess is that he would not be advised to go as far as he
has gone, and that this other info - the "old news" aspect, or what IPSwitch
should do, would have arisen in the course of the discussion.

I am not particularly troubled by his actions, nor do I have any illusions
about security - but I don't appreciate the manner in which this information
was publicized.

Lastly, I happen to think this is a worthwhile discussion, even if some
folks want to put a dagger in it.

Gary Mauer

[EMAIL PROTECTED]

Host/Moderator of the Window Cleaning Network
  - Your People, Product and Information Site -
       http://www.window-cleaning-net.com/

       Email Groups - 980 Networking Links
    8 Bulletin Board and 21 Trade Show Links



> -----Original Message-----
> From: [EMAIL PROTECTED]
> [mailto:[EMAIL PROTECTED]]On Behalf Of Phil Connolly
> Sent: Wednesday, December 22, 1999 12:16 PM
> To: [EMAIL PROTECTED]
> Subject: Re: [IMail Forum] [w00giving '99 #11] IMail's
> passwordencryption scheme
>
>
> I'm sorry to pollute this list with yet one more lame message about this
> lame topic, but the fact is I'm pretty annoyed, for a few reasons that I
> hope create several NEW list topics:
>
> First, several people are pissed off that some "source code" was publicly
> released.  These people completely miss the point.  The
> significant portion
> of Mike@eEye's alert is the useless encryption algorithym used by
> ipswitch,
> not a snippet of example code.  A programmer doesn't even NEED
> that code to
> create an exploit.  It was included as a "proof of concept" for
> non-programmers like me.
>
> Second, the released encryption information (whether released now
> or a year
> ago, I don't care) demonstrates a potential security problem.  Some have
> argued that "securing the console" brings them peace of mind.
> Well, to me,
> security is like an onion:  it has lots and lots of layers, from the
> firewall to the securing the box to securing the OS and its the
> services to
> securing the applications.  OK, so fine, your "console" is
> secure.  Can you
> guarantee that there is not some other hole somewhere else?  Ever
> heard of a
> buffer overflow? That's a place where some jerk can attempt to execute
> arbitrary code, so picture that code digging through the ipswitch password
> keys looking for the one root.
>
> Third, ipswitch can choose NOT to address this.  I can choose NOT
> to use the
> IMail user database and use instead NT or an external.  At least
> now that I
> have this information, I can make an intelligent decision based
> on weighing
> risks.  And don't tell me that the information didn't have to include the
> encryption algorithym, because in a case like this, actually seeing it
> drives home the point just how unsecure it is.  If someone just says: "the
> encryption can be cracked" and leaves it that, I say so what.  Any
> encryption can be cracked.  The question is really how easily can it be
> cracked?.
>
> Sorry for long-winded waste of bandwidth, but it sort of built up as I
> followed the thread this morning.
>
> -phil.
>
> Please visit http://www.ipswitch.com/support/mailing-lists.html
> to be removed from this list.
>

Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

Reply via email to