Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 11 Jul 1999 00:11:06 +0200
From:      Sheldon Hearn <sheldonh@uunet.co.za>
To:        chris@calldei.com
Cc:        Mark Murray <mark@grondar.za>, Ben Rosengart <ben@skunk.org>, "Brian F. Feldman" <green@FreeBSD.ORG>, hackers@FreeBSD.ORG
Subject:   Re: a BSD identd 
Message-ID:  <67484.931644666@axl.noc.iafrica.com>
In-Reply-To: Your message of "Sat, 10 Jul 1999 15:57:21 EST." <19990710155721.C57198@holly.dyndns.org> 

next in thread | previous in thread | raw e-mail | index | archive | help


On Sat, 10 Jul 1999 15:57:21 EST, Chris Costello wrote:

>    The whole point of ident was -- and still is -- to
> authenticate or verify who created a specific TCP connection.

Crhis, as Warner's already pointed out, you're wrong. :-)

Ident's intended purpose is for me to give you something to report back
to me when you think someone on my box is screwing around. Ident
responses are not useful to anyone but the owner of the box issuing
them, and even then they're only useful until the box is penetrated.

This is all silliness. The service has a place, it's just mostly
misunderstood, and none of this has anything to do with Brian Feldman's
original mail.

I _will_ have a problem with anyone changing inetd to provide real
usernames in response to auth (ident) service requests, where it did not
do so before. I don't have a problem with inetd being _able_ to do so if
it's given some extra option, so long as that doesn't become a new
default for existing configurations.

Ciao,
Sheldon.


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-hackers" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?67484.931644666>