As best I can tell, it doesn't protect from MITM attacks. If so, I'm confused about what the point is.
As best I can tell, it doesn't protect from MITM attacks. If so, I'm confused about what the point is.
https://en.wikipedia.org/wiki/Ident_protocol
It is a way for the server to verify which username initiated a connection from the client by connecting back to the client on a privileged port and ask, referencing the local and remote port of the target connection.
> it eliminates mail and news forgery above TCP
I have some trouble guessing offhand what flavor of security confusion was fresh in mind from the preceding 3 to 10 years (and I was yet to be born), but after glancing at RFC 931, I'm going to guess that before this, user-hostname identifiers were handled in varied ad-hoc ways allowing spoofing of sender, or connecting user. I'm careful not to say "authenticating" user.
https://datatracker.ietf.org/doc/html/rfc931
It's actually an evergreen problem, happened on a new social site, last week.
A message from your good friend, Amazon S3:
https://pbs.twimg.com/media/FvW7NJtWAAAocCe?format=jpg&name=...