Received: from PACIFIC-CARRIER-ANNEX.MIT.EDU by po7.MIT.EDU (5.61/4.7) id AA03391; Sat, 24 Feb 96 15:47:16 EST
Received: by MIT.EDU 
	id AB14597; Sat, 24 Feb 96 15:46:46 EST
Date: Sat, 24 Feb 96 15:46:46 EST
From: MAILER-DAEMON@MIT.EDU (Mail Delivery Subsystem)
Subject: Returned mail: Cannot send message for 3 days
Message-Id: <9602242046.AB14597@MIT.EDU>
To: <owner-kerberos@MIT.EDU>
To: hartmans@PO9.LOCAL
To: proven@PO7.LOCAL
To: tytso@PO9.LOCAL
To: basch@lehman.com
To: jis@E40-PO.LOCAL
To: tlyu@PO9.LOCAL

   ----- Transcript of session follows -----
421 sci.uma.es.tcp... Deferred: Address family not supported by protocol family
451 jcrey@sci.uma.es... Cannot send message for 3 days
jcrey@sci.uma.es... Cannot send message for 3 days

   ----- Unsent message follows -----
Received: from pad-thai.cam.ov.com by MIT.EDU with SMTP
	id AA15477; Wed, 21 Feb 96 15:41:43 EST
Received:  by pad-thai.cam.ov.com (8.6.12/)
	id <PAA13165@pad-thai.cam.ov.com>; Wed, 21 Feb 1996 15:45:40 -0500
Received: from GATEWAY by pad-thai.cam.ov.com with netnews
	for kerberos-wrapper@cam.ov.com (kerberos@mit.edu)
To: kerberos@MIT.EDU
Date: 21 Feb 1996 09:35:37 GMT
From: choo@wam.umd.edu (Josh Daymont)
Message-Id: <4gep1a$ipp@cville-srv.wam.umd.edu>
Organization: University of Maryland College Park
Sender: usenet@cam.ov.com
References: <4gd97f$gdi@srvr1.engin.umich.edu>, <4gdc46$9tn@narnia.cs.purdue.edu>, <312AA5FD.2E1A@dnai.com>
Subject: Re: Kerberos Weakness (COAST Findings)

Michael Sierchio (kudzu@dnai.com) wrote:
: Steve Lodin wrote:
: > 
: > There is information available on the Kerberos vulnerability incident at:

: I am not sure, but I believe that this is nothing new.  Steve Bellovin at
: AT&T had a paper a number of years ago on weaknesses in the Kerberos
: Authentication Suite.

I learned about this over a year ago when I saw the fix for it included 
in my kerberosIV distribution.  Also there was an rfc published about 
this (rfc1750).  Perhaps I am showing my ignorance,  but considering that 
the vulnerability was fairly well known (there were comments in the new 
random key generator to the effect that the old one was insecure),  and 
the fix was already available,  why was the release of the patch 
information delayed?  I can see delaying the release of an exploit script 
as others do, but what was the logic behind delaying the patch?

Josh
