Vulnerability Development mailing list archives

Re: Reachout 8.4x


From: rpc () INETARENA COM (rpc)
Date: Wed, 12 Apr 2000 10:39:15 -0700


Perhaps there were issues with exporting the products outside of the US
and Canada.

--rpc <h () ckz org>

On Mon, 10 Apr 2000, Seth R Arnold wrote:

* Chris Smith <chris () AMGROUPADMIN COM> [000410 18:57]:
to the recent issues with PCAnywhere 9 and Netopia's
Timbuktu Pro sending either completely cleartext or weakly
encrypted usernames and password using a simple
mathematical formula to en/decrypt.  I am wondering if

I am a little curious why these companies don't use Diffie-Hellman to
generate a session key for use with tripleDES or IDEA or ... and encrypt
*eveyrthing*, saving themselves a lot of hassle in the meantime.

Does anyone have reasons why this hasn't been done? (And if Symantec et
al do wish to implement it, could they give me some royalties? :)

--
Seth Arnold | http://www.willamette.edu/~sarnold/
Hate spam? See http://maps.vix.com/rbl/ for help



Current thread: