|
From: Phil Hall <hallp@ssax.com> > Alistair, > I gave you reasons in a later post why it wasn't 'daft', here's some more; > 1. It's a public (in the sense that IBM expect you to perform operations on > the object) object > > 2. There are API's to retrieve and set entries in this object > > 3. The entries are encrypted, poorly (in the sense the keyspace is > restricted by the system values that control what can be used as a > password), but still encrypted > > 4. Tools other than the API's (since V4R5 by default, and lower release by > applying PTF's) do not return the contents of the object - thus unless you > have been given access to the API's (they come as public *EXCLUDE, and you > need to have *SECADM special auth too) you won't see any data. > These words from Bruce Schneier (Preface to Applied Cryptography) may also be applicable: If I take a letter, lock it in a safe, hide the safe somewhere in New York, then tell you to read the letter, that's not security. That's obscurity. On the other hand, if I take a letter and lock it in a safe, and then give you the safe along with the design specifications of the safe and a hundred identical safes with their combinations so that you and the world's best safecrackers can study the locking mechanism - you still can't open the safe and read the letter - that's security. +--- | This is the Midrange System Mailing List! | To submit a new message, send your mail to MIDRANGE-L@midrange.com. | To subscribe to this list send email to MIDRANGE-L-SUB@midrange.com. | To unsubscribe from this list send email to MIDRANGE-L-UNSUB@midrange.com. | Questions should be directed to the list owner/operator: david@midrange.com +---
As an Amazon Associate we earn from qualifying purchases.
This mailing list archive is Copyright 1997-2024 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact [javascript protected email address].
Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.