OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: ssh - are you nuts?!?
From: Simon J. Gerraty (sjgquick.com.au)
Date: Sun Dec 17 2000 - 16:01:16 CST


>There are OTP authentication mechanisms available for SSH. And an OTP
>authenticated telnet session isn't going to be encrypted, so you still
>run the risk of having your keystrokes sniffed.

Sniffing is perhaps the lesser issue. Without session integrity checks
(and encryption provides a good form), your authenticated telnet session
can be stollen from you - thus strong authentication by itself is
almost useless.

--sjg