[147444] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: [Cryptography] Why is emailing me my password?

daemon@ATHENA.MIT.EDU (Russ Nelson)
Wed Oct 2 10:23:33 2013

X-Original-To: cryptography@metzdowd.com
Date: Wed, 2 Oct 2013 01:17:37 -0400
From: Russ Nelson <nelson@crynwr.com>
To: "cryptography@metzdowd.com List" <cryptography@metzdowd.com>
In-Reply-To: <C786C135-7784-4BE2-A7E2-141A98B0FE0F@kinostudios.com>
Errors-To: cryptography-bounces+crypto.discuss=bloom-picayune.mit.edu@metzdowd.com

Greg writes:
 > This falls somewhere in the land of beyond-the-absurd.
 > So, my password, iPoopInYourHat, is being sent to me in the clear by your servers.

Repeat after me: "crypto without a threat model is like cookies without
milk."

If you are proposing that something needs stronger encryption than
ROT-26, please explain the threat model that justifies your choice of
encryption and key distribution algorithms.

-- 
--my blog is at    http://blog.russnelson.com
Crynwr supports open source software
521 Pleasant Valley Rd. | +1 315-600-8815
Potsdam, NY 13676-3213  |     Sheepdog       
_______________________________________________
The cryptography mailing list
cryptography@metzdowd.com
http://www.metzdowd.com/mailman/listinfo/cryptography

home help back first fref pref prev next nref lref last post