Path: utzoo!utgpu!news-server.csri.toronto.edu!rpi!zaphod.mps.ohio-state.edu!swrinde!cs.utexas.edu!helios!inetg1!news From: gwhite@arco.com Newsgroups: comp.protocols.appletalk Subject: Re: Cayman's 'Watch' is security threat. Message-ID: <1991May15.234714.11517@Arco.COM> Date: 15 May 91 23:47:14 GMT References: <23491.9105141352@crete.dcs.glasgow.ac.uk> Sender: news@Arco.COM Organization: ARCO Oil and Gas Co. Lines: 10 >What I dread has finally happened - our students have discovered >Cayman's Watch program and with glee watched user's login passwords >fly by on their screens while running Watch. Actually there are several PC and Unix programs that do the same thing, although maybe not with the easy Mac approach. Let's not blame Watch too much for doing what is not uncommon. The long-term answer would be Kerberos or something similar, which avoids allowing clear-text passwords on the net. -Gary