Received: from SOUTH-STATION-ANNEX.MIT.EDU by po7.MIT.EDU (5.61/4.7) id AA17470; Sat, 24 Feb 96 20:28:25 EST
Received: by MIT.EDU 
	id AA20898; Sat, 24 Feb 96 20:27:34 EST
Date: Sat, 24 Feb 96 20:27:34 EST
From: MAILER-DAEMON@MIT.EDU (Mail Delivery Subsystem)
Subject: Returned mail: Deferred: Address family not supported by protocol family
Message-Id: <9602250127.AA20898@MIT.EDU>
To: <owner-kerberos@MIT.EDU>

   ----- Transcript of session follows -----
421 foobar.com.tcp... Deferred: Connection timed out during user open with kiwi.foobar.com
421 draper.com.tcp... Deferred: Connection timed out during user open with ns.draper.com
550 jhlee@minkowski.etri.re.kr... Host unknown
451 hangman@pyro.rh.imsa.edu... reply: read error
hangman@pyro.rh.imsa.edu... reply: read error
421 ccmpo-c.draper.com.tcp... Deferred: Connection timed out during user open with ns.draper.com
421 sci.uma.es.tcp... Deferred: Address family not supported by protocol family

   ----- Unsent message follows -----
Received: from pad-thai.cam.ov.com by MIT.EDU with SMTP
	id AA20660; Sat, 24 Feb 96 19:08:12 EST
Received:  by pad-thai.cam.ov.com (8.6.12/)
	id <TAA26306@pad-thai.cam.ov.com>; Sat, 24 Feb 1996 19:12:24 -0500
Received: from GATEWAY by pad-thai.cam.ov.com with netnews
	for kerberos-wrapper@cam.ov.com (kerberos@mit.edu)
To: kerberos@MIT.EDU
Date: 24 Feb 1996 18:39:47 -0500
From: eichin@cygnus.com (Mark Eichin)
Message-Id: <xe1ohqomgxo.fsf@scuba.cygnus.com>
Organization: Cygnus Support -- Compilers & Kerberos
Sender: usenet@cam.ov.com
References: <4g5jdd$iv4@umbc7.umbc.edu>, <4g5k5e$21c@narnia.cs.purdue.edu>
Subject: Re: Kerberos Weakness (COAST Findings)

>> With des_random_key available and no access to the MIT code, why use the
>> old, broken (as it turned out) ranom_key function?

Point of information: in the MIT code, "des_random_key" *is* the
broken one; "random_key" is a backwards-compatibility define (for
kerberos 3, maybe? :-) along with a few other non-prefixed names. The
correct generator *for the MIT libraries* is called des_new_random_key.

This naming, of course, isn't to relevant, since eBones had neither
the calls to the random generator *nor* any of the generators...
leaving plenty of opportunities to be more or less creative with the
information.
			_Mark_ <eichin@cygnus.com>
			Cygnus Support
			Cygnus Network Security <network-security@cygnus.com>
			http://www.cygnus.com/data/cns/
