Re: Service location vs. careless privacy infringement

Hallvard B Furuseth <[email protected]> Thu, 2 Jul 1998 15:30:40 +0200
Newsgroups gmane.ietf.lsd
Message-ID <[email protected]>
Thomas Lenggenhager writes:
> I doubt whether obscurity (open directory server, just not known
> by DNS announcement) is the right way to solve the problem.

So do I, and we should of course encourage admins to shield such servers
or do the necessary paperwork to make them legal.  However, that's a
losing battle -- look at all the address lists on WWW, for example.

> If you are determined it is rather easy to scan the hosts for an
> answer on the LDAP port. If such a person is clever enough they are
> not spotted that easily.

Right.  But there is a huge difference between data which *can* be found
by determined user and data which is automatically provided to any
novice.  So I'm just aiming for the second for now:  Avoid magnifying the
effects of *careless* privacy violation.

> The right way is to improve the LDAP servers deploied with appropriate
> configuration methods to distinguish between local and non local users.

True.  That's a nice dream:-(

--
Hallvard