Subject: Re: solving various bug reports...
To: Simon J. Gerraty <sjg@quick.com.au>
From: Perry E. Metzger <perry@piermont.com>
List: tech-security
Date: 06/26/1997 20:58:15
"Simon J. Gerraty" writes:
> No they aren't or weren't.  I offered the patches to LBL before
> submitting them as a PR.   LBL's stance was that it would make
> password sniffing too easy.  I personally think that's lame,  but its
> their choice.  As I recall cgd knocked it back because of LBL's
> stance.

Every security guru on the planet (including me) has their set of
private patches to tcpdump to do this stuff, and none of us ever give
them out. My personal position is that at some point we have to face
the fact that networks are insecure and accept that giving out these
tools will only result in "The Right Thing" i.e. people using stuff
like ssh instead of telnet. However, I feel conflicted about whether
to do it now.

BTW, tcpdump beats everything else, in my opinion.

Perry