OPIE considered insecure

Michael Ekstrand michael at elehack.net
Mon Mar 2 10:05:08 PST 2009


Chris Palmer <chris at noncombatant.org> writes:
> Rich Healey writes:
>> I'm thinking about implementing OPIE, but after reading this I'm not so
>> sure. What's consensus on the best approach to one time logins?
>
> Why are people logging into their remote servers from assumed-untrustworthy
> clients at all?

Simple use case: checking e-mail from the library/Internet
cafe/relative's house.  With Mutt or Gnus.

- Michael

-- 
mouse, n: A device for pointing at the xterm in which you want to type.



More information about the freebsd-security mailing list