Path: utzoo!mnetor!tmsoft!torsqnt!news-server.csri.toronto.edu!bonnie.concordia.ca!uunet!shelby!agate!usenet.ins.cwru.edu!pyrite!mike From: mike@pyrite.SOM.CWRU.Edu (Michael Kerner) Newsgroups: comp.sys.mac.misc Subject: Re: APPLE & FCC PETITION (PRESS RELEASE) Message-ID: <1991Feb6.131553.29092@usenet.ins.cwru.edu> Date: 6 Feb 91 13:15:53 GMT References: <1991Feb4.184339.24202@csn.org> <1991Feb4.233214.486@cs.uiuc.edu> <1991Feb5.182303.11214@MDI.COM> Sender: news@usenet.ins.cwru.edu Organization: WSOM CSG, CWRU, Cleve. OH Lines: 30 X-Post-Machine: pyrite.som.cwru.edu Nntp-Posting-Host: pyrite.som.cwru.edu In article <1991Feb5.182303.11214@MDI.COM> jackb@MDI.COM (Jack Brindle) writes: >The other thing to remember is that even Ethernet is not fully secure. If >someone really wants at your data, they could throw enough resources at >decoding the electromagnetic field given off by the ethernet cable that >they could get anything that you send across your network. And that data is >almost never encrypted Uuuugh, I hope none of you have illusions about Ethernet being secure, because if you do, you are kidding yourself. Between our hardware specialist and our network specialist, we have a net worm we've been playing with that can take on any identity the user chooses and then do all kinds of packet nasties - and I would say that we're pretty tight on the EM. However, even the MIT standard encrypted packets only work until the bad guys run enough keys through DECRYPT via all the unique text sources they can find. It's sort of a standard UNIX practice to UNIQUE all the text you can get your hands on, run them through DES, and start comparing the results until you get a match. We figured somewhere in the neighborhood of a couple of hours tops in the worst case (using a SPARC). Why do we need radio waves? Why not go infra-red or something on that end with a long enough wavelength that it won't be going anywhere? Granted you are limited to line-of-sight, but a re-transmitter station can be small and cheap and you don't pollute your environment with additional EM's. One last thing: Those wanting to capture your data can just monitor the EM from your keyboard and such - seems easier than packet sniffing. Mikey. Body by Nautilus...Brain by (I'm gonna get sued for this) Macintosh.