There is still a (microscopically small) risk if there are users with the
ability to display real storage and a lot of free time to hunt for TCP
buffers in real storage. If you are in LPAR mode and using real hipersockets
or a shared OSA, it is possible to intercept traffic -- the same is true
under VM, but it's harder to do as you'd have to crack both a userid with
appropriate privileges and known enough about how CP does it's work to track
down where the buffers are.

In most cases, only the absolutely ultra-super-mega-paranoid care about
this, but since you work for a health-care provider, you may be provided
with such people as security officers.  For all *normal* intents and
purposes, it's probably not worth worrying about it.  Tapping such a
connection is something that requires far too much knowledge for the average
luser.

I think a good case can be made that it's a waste of cycles to encrypt
something that never leaves the box. If someone does manage to tap that,
then you have way bigger problems than data transfer security.

-- db

David Boyes
Sine Nomine Associates


> -----Original Message-----
> From: Linux on 390 Port [mailto:[EMAIL PROTECTED] Behalf Of
> McKown, John
> Sent: Wednesday, July 09, 2003 1:22 PM
> To: [EMAIL PROTECTED]
> Subject: Really dumb question.
>
>
> Given that my OS/390 system and my Linux system are on the
> same box and
> using an OSA for all TCP/IP connectivity, is there any reason
> to do any sort
> of encryption between them for things like ftp or even things that may
> transport userids and passwords?
>
>
> --
> John McKown
> Senior Systems Programmer
> UICI Insurance Center
> Applications & Solutions Team
> +1.817.255.3225
>
> This message (including any attachments) contains
> confidential information
> intended for a specific individual and purpose, and its' content is
> protected by law.  If you are not the intended recipient, you
> should delete
> this message and are hereby notified that any disclosure, copying, or
> distribution of this transmission, or taking any action based
> on it, is
> strictly prohibited.
>

Reply via email to