OPIE considered insecure

Chris Palmer chris at noncombatant.org
Sun Mar 1 18:32:54 PST 2009

Rich Healey writes:

> I'm thinking about implementing OPIE, but after reading this I'm not so
> sure. What's consensus on the best approach to one time logins?

Why are people logging into their remote servers from assumed-untrustworthy
clients at all?

