|
From: <hzu...@ra...> - 2004-03-16 20:50:23
|
On 03/16/2004 02:43:30 PM Friedrich Lobenstock wrote: >Bruce Smith wrote on 16.03.2004 20:08 MET: >>>>>>I'm sure they come up with some better authentication in the >future. >>>>> >>>>>Or even better authorization. :-) >>>> >>>>Minor details..... ;-) >>> >>>Either one would be an improvement! :-) >> >> >> WAIT A MINUTE! (imagine light bulb going on over my head :) >> >> You supply two prime numbers (manually) while running "make". >> This would be in the DL build process? This means the encryption is >> static and can only be changed by recompiling DL? This means the key >> is burned on the CD and is the same for everyone with a stock distro? >> SECURITY HOLE!!! I changed my mind about including this! Or at least >> turn it off by default for all distro's available for download. YUCK! > >I know. But you would not enable it from any IP, would you? Maybe those >numbers can be supplied on some other way in the future. May let's mail >the >author. What do you think? Good idea. Don't forgett he's in an early stage of the development and probably didn't consider distro's like DL. Heiko |