Re: [HACKERS] [Fwd: [CORE SDI ADVISORY] MySQL weak authentication]

2000-10-25 Thread Marko Kreen
On Wed, Oct 25, 2000 at 10:27:15AM -0600, Bruce Guenter wrote: > On Tue, Oct 24, 2000 at 10:25:14AM -0400, Lamar Owen wrote: > > I am forwarding this not to belittle MySQL, but to hopefully help in the > > development of our own encryption protocol for secure password > > authentication over the n

Re: [HACKERS] [Fwd: [CORE SDI ADVISORY] MySQL weak authentication]

2000-10-25 Thread Marko Kreen
On Tue, Oct 24, 2000 at 10:25:14AM -0400, Lamar Owen wrote: > I am forwarding this not to belittle MySQL, but to hopefully help in the > development of our own encryption protocol for secure password > authentication over the network. > > The point being is that if we offer the protocol to do it,

Re: [HACKERS] [Fwd: [CORE SDI ADVISORY] MySQL weak authentication]

2000-10-25 Thread Lamar Owen
Bruce Guenter wrote: > On Tue, Oct 24, 2000 at 10:25:14AM -0400, Lamar Owen wrote: > > The point being is that if we offer the protocol to do it, we had better > > ensure its security, or someone WILL find the hole. Hopefully it will > > be people who want to help security and not exploit it. >

Re: [HACKERS] [Fwd: [CORE SDI ADVISORY] MySQL weak authentication]

2000-10-25 Thread Bruce Guenter
On Tue, Oct 24, 2000 at 10:25:14AM -0400, Lamar Owen wrote: > I am forwarding this not to belittle MySQL, but to hopefully help in the > development of our own encryption protocol for secure password > authentication over the network. > > The point being is that if we offer the protocol to do it,