OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: domain.name HOLD:[dynam.ip.addr] ?
From: Jim Seymour (jseymourLinxNet.com)
Date: Sat Apr 01 2000 - 07:42:13 CST


Matthias Andree <madt.e-technik.uni-dortmund.de> wrote:
>
> Craig Sanders <castaz.net.au> writes:
>
> > Taylor UUCP is highly recommended - it compiles on most (probably all)
> > unix systems and is available pre-packaged for all Linux and *BSD
> > systems that i know of. see http://www.airs.com/ian/ for more info.
>
> Note that the pre-packaged versions I have encountered OMIT encrypting
> the password file which is a compile-time option.

Which of course results in "WHAT?!?!" at first blush. But the file is
in a restricted directory (IIRC) and is not readable except by root
(again: IIRC), so the problem is not quite so big a one as it would of
course otherwise be.

The passwords in /etc/uucp/Systems in conventional HDB UUCP are in
clear text as well.

One could argue that clear text passwords in files in restricted
directories are safer than encrypted passwords in world-readable
files.

Regards,
Jim

-- 
Jim Seymour                  | PGP Public Key available at:
jseymourLinxNet.com         | http://www.cam.ac.uk.pgp.net/pgpnet/wwwkeys.html
http://home.msen.com/~jimsun | http://www.trustcenter.de/cgi-bin/SearchCert.cgi