> If I use an OTP to log into a remote system via an untrusted host, > and I don't type any further passwords in, what exposure am I > presenting?
What exactly do you think "untrusted" means in the phrase "untrusted host"? Come on, THINK...
> If I use an OTP to log into a remote system via an untrusted host, > and I don't type any further passwords in, what exposure am I > presenting?
What exactly do you think "untrusted" means in the phrase "untrusted host"? Come on, THINK...