On Iau, 2003-07-10 at 01:53, David Boyes wrote:
> If you've poisoned the DNS from the outside (ie, both hosts consult an
> corrupted outside DNS), then encrypting the data isn't any real defense
> either -- you need connection authentication; whether the data is encrypted
> or not isn't the issue, it's whether you recognize your peer that counts.
> Not really the same problem, although linked.

Its a defence because your encryption keys are not tied to DNS. Yes you
stole my data, no you can't read it

> I don't deny that encryption is *good*. The question was whether it is
> *necessary* in an environment where most of the common attacks you mention
> are difficult or impossible to perform if the administrator is even
> moderately alert.

I guess you have more faith in your administrator's powers than me.

Reply via email to