From owner-freebsd-hackers Tue Apr 23 12: 6:21 2002 Delivered-To: freebsd-hackers@freebsd.org Received: from guru.mired.org (dsl-64-192-6-133.telocity.com [64.192.6.133]) by hub.freebsd.org (Postfix) with ESMTP id 6AA9A37B421 for ; Tue, 23 Apr 2002 12:06:12 -0700 (PDT) Received: (from mwm@localhost) by guru.mired.org (8.11.1/8.11.2) id g3NJ6Bi38093 for hackers@FreeBSD.org; Tue, 23 Apr 2002 14:06:11 -0500 (CDT) (envelope-from mwm-dated-1020020771.b5d75f@mired.org) X-Authentication-Warning: guru.mired.org: mwm set sender to mwm-dated-1020020771.b5d75f@mired.org using -f MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit Message-ID: <15557.45217.735707.188605@guru.mired.org> Date: Tue, 23 Apr 2002 14:06:09 -0500 To: Jochem Kossen Cc: "Greg 'groggy' Lehey" , hackers@FreeBSD.org, "Greg 'groggy' Lehey" , hackers@FreeBSD.org Subject: Re: Security through obscurity? (was: ssh + compiled-in SKEY support considered harmful?) In-Reply-To: <20020423032146.A490@HAL9000.wox.org> References: <200204231009.51297.j.kossen@home.nl> <20020423183452.M6425@wantadilla.lemis.com> <200204231206.01451.j.kossen@home.nl> <11670.1019530386@winston.freebsd.org> <20020423131646.I6425@wantadilla.lemis.com> <20020423032146.A490@HAL9000.wox.org> X-Mailer: VM 6.90 under 21.1 (patch 14) "Cuyahoga Valley" XEmacs Lucid X-face: "5Mnwy%?j>IIV\)A=):rjWL~NB2aH[}Yq8Z=u~vJ`"(,&SiLvbbz2W`;h9L,Yg`+vb1>RG% *h+%X^n0EZd>TM8_IB;a8F?(Fb"lw'IgCoyM.[Lg#r\ From: Mike Meyer X-Delivery-Agent: TMDA/0.51 (Python 2.2 on FreeBSD/i386) Sender: owner-freebsd-hackers@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.ORG In <200204231206.01451.j.kossen@home.nl>, Jochem Kossen typed: > On Tuesday 23 April 2002 11:04, you wrote: > OK, then i suggest we mention it in the handbook, the security policy > document, the manpage AND the release notes :) None of those are things that are on the "Must read" list for people tracking -STABLE, instead of -RELEASE. I believe UPDATING is the only such document. FWIW, I ran into this, and asked about it on -questions. Got the solution, then finally got around to making ssh forward X11 properly so I no longer use it. http://www.mired.org/home/mwm/ Independent WWW/Perforce/FreeBSD/Unix consultant, email for more information. To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-hackers" in the body of the message