Re: Some security-related suggestions

John Gardiner Myers <jgm+@cmu.edu> Thu, 09 June 1994 02:09 UTC

Received: from ietf.nri.reston.va.us by IETF.CNRI.Reston.VA.US id aa09567; 8 Jun 94 22:09 EDT
Received: from CNRI.RESTON.VA.US by IETF.CNRI.Reston.VA.US id aa09563; 8 Jun 94 22:09 EDT
Received: from ANDREW.CMU.EDU by CNRI.Reston.VA.US id aa20308; 8 Jun 94 22:09 EDT
Received: (from postman@localhost) by andrew.cmu.edu (8.6.7/8.6.6) id WAA18880; Wed, 8 Jun 1994 22:05:29 -0400
Received: via switchmail; Wed, 8 Jun 1994 22:05:28 -0400 (EDT)
Received: from hogtown.andrew.cmu.edu via qmail ID </afs/andrew.cmu.edu/service/mailqs/testq0/QF.QhxbWNi00WBw43eE5Z>; Wed, 8 Jun 1994 22:04:10 -0400 (EDT)
Received: from hogtown.andrew.cmu.edu via qmail ID </afs/andrew.cmu.edu/usr7/jm36/.Outgoing/QF.8hxbWBu00WBwA10Lll>; Wed, 8 Jun 1994 22:03:58 -0400 (EDT)
Received: from BatMail.robin.v2.14.CUILIB.3.45.SNAP.NOT.LINKED.hogtown.andrew.cmu.edu.sun4c.411 via MS.5.6.hogtown.andrew.cmu.edu.sun4c_411; Wed, 8 Jun 1994 22:03:54 -0400 (EDT)
Message-ID: <MhxbW_i00WBw810LYy@andrew.cmu.edu>
Date: Wed, 08 Jun 1994 22:03:54 -0400
Sender: ietf-archive-request@IETF.CNRI.Reston.VA.US
From: John Gardiner Myers <jgm+@cmu.edu>
To: POP3 IETF Mailing List <ietf-pop3+@andrew.cmu.edu>
Subject: Re: Some security-related suggestions
In-Reply-To: <19940608225946.AAA8960@rome.software.com>
References: <19940608225946.AAA8960@rome.software.com>
Beak: is Not

Mike@Software.com (Michael D'Errico) writes:
> All of my mail goes out as "mike" but I can set up a POP account for
> me as "2Yhd%0_" if I want....

Or you could alternately leave your account as "mike" and require your
password to start with "2Yhd%0_", with no increase in security risk.
Two reusable passwords are no better than one twice as long.

If people want text like that given by Steve Dorner in the Security
Considerations section, fine.  I do, however, object to prohibiting
servers from issuing useful error messages on the USER command.

-- 
_.John G. Myers		Internet: jgm+@CMU.EDU
			LoseNet:  ...!seismo!ihnp4!wiscvm.wisc.edu!give!up