OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: about the complexity estimate
From: Marc Esipovich (marcmucom.co.il)
Date: Thu Jun 08 2000 - 11:44:13 CDT


On Thu, Jun 08, 2000 at 07:59:30AM +0100, Antonomasia wrote:
> Marc Esipovich:
>
> > Security of your code aside for a minute, Where's the real authentication?
> > You obviously need something secure from a cryptographic point of view.
> > (you don't want imposters going around adding users, changing passwords...)
>
> Ideally cryptographic authentication would have been my choice too, but
> I was expected to make it in a hurry.
>
> The fact that I have still not been given the username
> list for _existing_ user accounts to make the initial file
> suggests to me that the rush request was more designed to
> make us say "yes you can have root" than to get a technical
> solution inside a few days. Quite possibly this will never
> get used.
>

 Seems to me that you could have done it all, authenticated, finished and
debugged, instead of discussing it in great length on this list ;)

        Marc.