Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Can someone talk about what this "auth" library is that djb talks about? What is its security model?

As best I can tell, it doesn't protect from MITM attacks. If so, I'm confused about what the point is.



An implementation of auth is identd.

https://en.wikipedia.org/wiki/Ident_protocol

It is a way for the server to verify which username initiated a connection from the client by connecting back to the client on a privileged port and ask, referencing the local and remote port of the target connection.


There's definitely more to it than this, but keep in mind that djb was a teenager at the time, likely flaming for the sake of flaming as we all have at some point in our misguided youth, and no doubt, he was quite proud of his library.


He said "above TCP".

> it eliminates mail and news forgery above TCP

I have some trouble guessing offhand what flavor of security confusion was fresh in mind from the preceding 3 to 10 years (and I was yet to be born), but after glancing at RFC 931, I'm going to guess that before this, user-hostname identifiers were handled in varied ad-hoc ways allowing spoofing of sender, or connecting user. I'm careful not to say "authenticating" user.

https://datatracker.ietf.org/doc/html/rfc931

It's actually an evergreen problem, happened on a new social site, last week.

A message from your good friend, Amazon S3:

https://pbs.twimg.com/media/FvW7NJtWAAAocCe?format=jpg&name=...




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: