From: Christopher Fowler <cfowler@outpostsentinel.com>
To: linux-ppp@vger.kernel.org
Subject: Re: Blowfish encryption
Date: Thu, 10 Mar 2005 18:24:23 +0000 [thread overview]
Message-ID: <1110479063.18073.445.camel@linux.linxdev.com> (raw)
In-Reply-To: <1110403872.18073.330.camel@linux.linxdev.com>
Some of these tin-hat people I tell them to simply buy encrypted modems
that do the encryption between the. Are there anyone out there selling
good ones anymore?
Th issue is that there are two boxes connected via a modem and using PPP
for IP traffic. The customer wants to be sure all traffic across that
phone line is encrypted. Since they use so many network product some
old those protocol may be plain-text. By having ppp encrypt what it
sends that would cover any data that travels across.
On Thu, 2005-03-10 at 13:17, James Carlson wrote:
> Christopher Fowler writes:
> > The only problem with ssh is that it is one protocol. There are many
> > protocols that travel across the ppp link. Some fo them not encryted
> > and can not be encrypted.
> >
> > I stopped using telnet a long time ago. Also with these devices there
> > are protocols that are routed across that link we have no control over
> > so doing encryption inside of ppp would cover all the bases.
>
> As I mentioned, if it's really a PPP issue (not clear that it is, as
> the threat model isn't clear), then ECP is likely to be the right
> answer.
>
> If it's an IP issue (are you worried about non-IP protocols?), then
> I'd certainly recommend the use of IPsec. It defends against things
> that ssh (and, for that matter, SSL/TLS) cannot, works whether or not
> you use PPP, works on an end-to-end basis, and doesn't require
> changing everyone's implementations.
next prev parent reply other threads:[~2005-03-10 18:24 UTC|newest]
Thread overview: 15+ messages / expand[flat|nested] mbox.gz Atom feed top
2005-03-09 21:31 Blowfish encryption Christopher Fowler
2005-03-10 12:36 ` James Carlson
2005-03-10 17:53 ` Bill Unruh
2005-03-10 18:01 ` Christopher Fowler
2005-03-10 18:17 ` James Carlson
2005-03-10 18:24 ` Christopher Fowler [this message]
2005-03-10 19:00 ` James Carlson
2005-03-10 19:10 ` Christopher Fowler
2005-03-10 19:13 ` James Carlson
2005-03-10 19:13 ` Bill Unruh
2005-03-10 19:17 ` Bill Unruh
2005-03-10 19:43 ` John Hasler
2005-03-10 19:59 ` James Carlson
2005-03-10 20:06 ` Christopher Fowler
2005-03-11 10:50 ` Bill Unruh
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1110479063.18073.445.camel@linux.linxdev.com \
--to=cfowler@outpostsentinel.com \
--cc=linux-ppp@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.