To LUGNET HomepageTo LUGNET News HomepageTo LUGNET Guide Homepage
 Help on Searching
 
Post new message to lugnet.admin.nntpOpen lugnet.admin.nntp in your NNTP NewsreaderTo LUGNET News Traffic PageSign In (Members)
 Administrative / NNTP / 826 (-10)
  Re: E-mail authentication during posting
 
"Kerry Raymond" <kerry@dstc.edu.au> wrote in message news:GF5uAo.5x1@lugnet.com... (...) in (...) That's quite a neat idea, but as you say prone to risk of revealing the password. I still think that using NNTP authentication will work, esp. if it (...) (23 years ago, 19-Jun-01, to lugnet.admin.nntp)
 
  Re: E-mail authentication during posting
 
(...) It would be nice if each NNTP message could carry its own authentication in some simple software-independent solution. One way that might work (for LUGnet members anyway) would be to search the message body for the string (say): (...) (23 years ago, 19-Jun-01, to lugnet.admin.nntp)
 
  Re: E-mail authentication during posting
 
(...) And it'd have to be something that can't be easily automated by the poster - this defeats the scheme. I've seen some web pages which generate a bitmap containing a string which isn't easily scanned, and asks you to type the string in to (...) (23 years ago, 19-Jun-01, to lugnet.admin.nntp)
 
  Re: E-mail authentication during posting
 
(...) I think that's a concern we all share, including Todd. I know that he has been very concerned about that every time the issue has come up in the past. What we have to do is work towards a system which is as painless as possible, which does not (...) (23 years ago, 19-Jun-01, to lugnet.admin.nntp)
 
  Re: E-mail authentication during posting
 
Hi Todd - I'd also like to thank you for this. Now LUGNET is more secure. I do want to continue to voice the concerns a few others have had here though. I also use a newsreader 90% of the time to post, and its an inconvenience. It would be great if (...) (23 years ago, 19-Jun-01, to lugnet.admin.nntp)
 
  Re: E-mail authentication during posting
 
(...) Personally, I am not a big fan of doing anything IP based. There are far too many problems. AOL dials, multiple computers (I regularly use three myself) and many other issues have made me decide against this method time and time again. <END (...) (23 years ago, 19-Jun-01, to lugnet.admin.nntp)
 
  Re: E-mail authentication during posting
 
(...) IP addresses can easily be spoofed, as long as you don't need an interactive session... as in, if I just need to send an HTTP POST, and don't need to read the reply, I can spoof the source ip with no problem. :/ (23 years ago, 19-Jun-01, to lugnet.admin.nntp)
 
  Re: E-mail authentication during posting
 
(...) Not currently, no. Let me think about IP-based authentication for a while. (...) This I can definitely do, but it will have to be at least somewhat interactive so that someone doesn't accidentally cause a message to get posted simply by (...) (23 years ago, 19-Jun-01, to lugnet.admin.nntp)
 
  Re: E-mail authentication during posting
 
(...) What Dan said, plus I think IP addresses could be spoofed... ++Lar (23 years ago, 19-Jun-01, to lugnet.admin.nntp)
 
  Re: E-mail authentication during posting
 
(...) but by doing that, you'll be breaking the whole authentication process - If I know that you have such a rule that auto authorizes posts by you, I can spoof posts as you with no problem... your auto-reply will authorize them without (...) (23 years ago, 19-Jun-01, to lugnet.admin.nntp)


Next Page:  5 more | 10 more | 20 more

Redisplay Messages:  All | Compact

©2005 LUGNET. All rights reserved. - hosted by steinbruch.info GbR