Karl Auer kauer at
Tue Nov 11 21:22:05 UTC 2014

On Tue, 2014-11-11 at 07:44 -0800, Michael Thomas wrote:
Well - yes. That's sort of my point. If you are going to send a password
over a network, make sure it's encrypted. Telnet isn't encrypted.

> An active MITM attack or passive snooping on telnet streams seems like 
> it would be orders of magnitude less dangerous on a list of threats.
>  SSH is definitely a Good Thing, but it's not a sliver bullet.

I didn't say it was. I just said that sending passwords in clear text
over the network is a very bad idea. Telnet does that, so using telnet
is a very bad idea. Use ssh, and the problem is gone. There are other
ways to make the problem disappear, and obviously neither they nor ssh
will protect you if you do any of a dozen other silly things.

Don't use telnet access for management of anything valuable unless you
own every inch of the path from you to it, or unless you can encrypt the
channel via other means.

