[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
FOLLOW UP: (ssh - are you nuts!?!)
If you are reading this, DO NOT followup to the mailing list.
Unforutnately my current software does not permit the
addition of a "followup-to:" tag. I'll try to fix this
in future postings.
As suggested by many I have read some articles on SSH.
One in particular seems to be filling with in-accuracies
and bad advise.
That article is at:
http://www.devshed.com/Server_Side/Administration/SSH/
In a minute, I'll point out the problems. But first
for those of you that have read the article, or those
of you about to read it. My questions is:
Would you support this article as being technically
accurate or informationally correct?
So, as many people have asked me -- please point out
objections to SSH. At this point, I will point to this
article and ask for opinions.
Here are my objects to this article:
In section SSH:
"SSH always encrypts data tranmissions and thus secures
sensitive information from falling into the hand of
others."
>From my perspective, this is technically incorrect.
While SSH can hide the information from the "hands of
others", there is nothing I have found that points to
any way to prevent "others" from capturing data.
Capturing data is a side-effect of an open network.
Further since SSH runs on top of TCP, a "sniffer"
can at least see the data going from A to B.
So in review, this type of statement is from truthful
and useful, since it portrays a falsehood as truth.
I will note that I have marked six (6) other problems
with this article. So, please follow-up only to me.
Lastly, I will NOT maker further posting to these mailing
lists, unless other damming evidence of this matter
is available. Time is running short and I have only
15 review days before my talk. :-)
Jessem.