Re: appl/simple/client/sim_client.c uses internal APIs

Sam Hartman <[email protected]>
Newsgroups gmane.comp.encryption.kerberos.general
Message-ID <0100018684e362d5-f4c8fd6d-ef2f-44b1-ab43-61a7d0aa20eb-000000@email.amazonses.com>
>>>>> "Chris" == Chris Hecker <[email protected]> writes:

    Chris> I guess if I’m on a tear saying forbidden things, sometimes
    Chris> identity is all you need, you don’t want all the samples to
    Chris> encrypt everything, because that makes it look like you have
    Chris> to, which you don’t?  It is use-case dependent, and krb5 is
    Chris> great because it is granular enough to let developers choose
    Chris> what they do for their own use-cases.


My suspicion is that people are still really bad at figuring out whether
they need integrity.
I think a sample that does not either use TLS or use integrity
protection does a disservice to the community.
Because basically I don't think there are a lot of cases where identity
is all you need (other than when running over TLS), and I think people
are far more likely to believe they can get away with just identity than
is actually the case.

--Sam

________________________________________________
Kerberos mailing list           [email protected]
https://mailman.mit.edu/mailman/listinfo/kerberos
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.