From owner-freebsd-hackers Sat Jul 10 17: 1: 6 1999 Delivered-To: freebsd-hackers@freebsd.org Received: from mailgw01.execpc.com (mailgw01.execpc.com [169.207.2.78]) by hub.freebsd.org (Postfix) with ESMTP id 54FBA14D01; Sat, 10 Jul 1999 17:00:49 -0700 (PDT) (envelope-from hamilton@pobox.com) Received: from woodstock.monkey.net (kronos-2-54.mdm.mkt.execpc.com [169.207.85.182]) by mailgw01.execpc.com (8.9.1) id TAA25155; Sat, 10 Jul 1999 19:00:46 -0500 Received: from pobox.com (localhost [127.0.0.1]) by woodstock.monkey.net (Postfix) with ESMTP id 381BD1E1; Sat, 10 Jul 1999 16:25:50 -0500 (CDT) To: Mark Murray Cc: Ben Rosengart , "Brian F. Feldman" , hackers@FreeBSD.ORG Subject: Re: a BSD identd In-reply-to: Your message of "Sat, 10 Jul 1999 21:49:12 +0200." <199907101949.VAA14008@gratis.grondar.za> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Date: Sat, 10 Jul 1999 16:25:50 -0500 From: Jon Hamilton Message-Id: <19990710212550.381BD1E1@woodstock.monkey.net> Sender: owner-freebsd-hackers@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.ORG In message <199907101949.VAA14008@gratis.grondar.za>, Mark Murray wrote: } > On Sat, 10 Jul 1999, Mark Murray wrote: } > } > > There is the question - what for? identd is of questionable use at best. } > } > I used to run a public shell machine, and one of my users cracked } > someone else's site. Identd made it much easier to figure out who the } > problem user was. } } That represents tiny percentage of identd use. The rest is noise. } } Pidentd+DES _is_ useful in the situation you mention above. It is } on average useless to most security folk, as it can also be used } to obfuscate the problem. Crack root on the box, and identd is no } longer trustworthy. Just because it's useless in some situations doesn't mean it's not useful in others. Yours is an argument against _misusing_ identd, not an argument against _using_ it. -- Jon Hamilton hamilton@pobox.com To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-hackers" in the body of the message