home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.protocols.kerberos
- Path: sparky!uunet!stanford.edu!news
- From: bagate!socrates!bf4grjc (Ravi Ganesan (301) 595-8439)
- Subject: Re: New User Accounts
- Message-ID: <9209031409.AA00547@ramanujam.bell-atl.com>
- Sender: news@shelby.stanford.edu (USENET News System)
- Reply-To: socrates!socrates.bell-atl.com!ravi
- Organization: Internet-USENET Gateway at Stanford University
- References: <53920903103935.0003858921NA3EM@mcimail.com>
- Date: Thu, 3 Sep 1992 14:09:06 GMT
- Lines: 45
-
- >
- > Ganesan writes:
- >
- > >What problem does it NOT solve?
- > >Type 2. Password weakness problems:
- > > - password guessing
- > > - dictionary attacks
- >
- > >From the Kerberos class that I took at spring INTEROP, it would seem that the
- > dictionary in v5 will pretty much stop these two.
- >
- Observe that there is a trade off situation in using difficult passwords,
- especiailly when they change often due to password aging, and when a user
- has accounts on several systems which as yet cannot share authentication.
- i.e. the harder the password, the more likely the user is to write it down.
-
- Dictionary attacks can eb stopped using the protocls developed by li Gong et
- al, and by Bellovin & Merrit. Note that the latter necessitates the use
- of public-key, and both have (probably acceptable) an overhead.
-
- >
- > Nothing will stop intentional password sharing. Even with a SecureID. It is
- > just more limited with SecureID.
- >
-
- With a token authenticator, a physical device needs to change hands for
- password sharing can take place, which in general would require the complicity
- of the person doing the sharing, which can be audited.
-
- While I'm sure sharing can/will still occur, it is FAR MORE limited. Nothing
- works like the detterrent of being resonsible for your actions!
-
- Ravi
- --
-
-
- *******************************************************************************
-
- Ravi Ganesan e-mail: ravi@socrates.bell-atl.com
- IS SAS Corporate Network Planning v-mail: (301) 595-8439
- Bell Atlantic Fax: (301) 595-1341
-
- Note: If your e-mail reply to me bounces, try sending it explicitly to
- ravi@socrates.bell-atl.com instead of using the 'reply' feature.
- ******************************************************************************
-