Home page Services provided Software available Site licenses Systems status Local Documentation Windows 2000 Reporting problems Links Contact information





Next Previous Contents

3. Why should I use SSH?

SSH or Secure Shell, encrypts the entire data stream between two hosts. When you use "normal" UNIX communication programs like: telnet, ftp, rsh, rlogin and rcp, the data stream is not encrypted. Even though your password is hashed in the password file, it goes over the network just as you typed it at the keyboard; as clear text. If someone is running a packet sniffer, they will be able to get your username and password if you use one of the clear text communication methods. In many cases, the packet sniffer isn't even running on your computer. It may be running on your segment of the network, and depending on the network configuration, the sniffer may still be able to obtain your clear text password. They will then be able to log in as "you" once they have your clear text password. This is one of the most common methods used to "crack" into computers around campus.

One commonly used analogy is: would you prefer to return your IRS tax returns in a clear or solid envelope?


Next Previous Contents




Certifying authority: Paul Gluhosky
Manager, AM&T Workstation Support Services
URL: http://wss.yale.edu/doco/SSH
Last update: 08.18.04
AMT home pageITS home pageYale Front DoorContact usSearchWorkstation Support Services home page