From owner-freebsd-security Fri Jan 19 8:27:41 2001 Delivered-To: freebsd-security@freebsd.org Received: from homer.softweyr.com (bsdconspiracy.net [208.187.122.220]) by hub.freebsd.org (Postfix) with ESMTP id D87D937B404 for ; Fri, 19 Jan 2001 08:27:24 -0800 (PST) Received: from [127.0.0.1] (helo=softweyr.com ident=Fools trust ident!) by homer.softweyr.com with esmtp (Exim 3.16 #1) id 14JeV5-0000BV-00; Fri, 19 Jan 2001 09:34:55 -0700 Message-ID: <3A686CAF.C195C392@softweyr.com> Date: Fri, 19 Jan 2001 09:34:55 -0700 From: Wes Peters Organization: Softweyr LLC X-Mailer: Mozilla 4.75 [en] (X11; U; Linux 2.2.12 i386) X-Accept-Language: en MIME-Version: 1.0 To: Garrett Wollman Cc: freebsd-security@FreeBSD.ORG Subject: Re: A wish and a dream... References: <3A641F3F.55AA9322@sarenet.es> <3A642174.9A7A8068@tempest.sk> <3A65548B.E3D7ADA4@softweyr.com> <200101191532.KAA10045@khavrinen.lcs.mit.edu> Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.org Garrett Wollman wrote: > > < said: > > > The iKey looks great, but I've been told it has a known exploit (a hard- > > coded keyphrase built into the hardware, or something like that.) > > However, all that gives an attacker is the chance to attempt to > brute-force the pass-phrase(s) your key(s) is/are protected under. Right, and the whole idea with something like the iKey is to only connect it to the machine when you need the key. I don't forsee someone mugging the FreeBSD SO in order to send out properly signed nefarious security patch. At least not this week. -- "Where am I, and what am I doing in this handbasket?" Wes Peters Softweyr LLC wes@softweyr.com http://softweyr.com/ To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message