[2152] in Kerberos

home help back first fref pref prev next nref lref last post

Re: New User Accounts

daemon@ATHENA.MIT.EDU (Ganesan)
Wed Sep 2 18:06:58 1992

From: bagate!socrates!bf4grjc (Ganesan)
To: warlord@MIT.EDU (Derek Atkins)
Date: Wed, 2 Sep 92 17:42:08 EDT
Cc: kerberos@Athena.MIT.EDU
In-Reply-To: <9209021949.AA17532@deathtongue.MIT.EDU>; from "Derek Atkins" at Sep 2, 92 3:49 pm

ravi@socrates.bell-atl.com
X-Mailer: ELM [version 2.3 PL8]

> 
> The solution here is not a simple one, so suggestions are open!
> 
Here at Bell Atlantic we have a major V.5 deployemnet planned, 
concurrent with a major token authenticator deployement. And in 
looking at this problem agree that it is hardly simple.

> (The real solution is to throw away SecurID as a method of
> login-password-authentication and extend kerberos all the way across
> the modem to the terminal.)
> 
However, throwing away SecureID is NOT any solution at all. 
Lets assume, that by some majic Kerberos gets deployed on every 
terminal in every location (e.g. its already availble for PCs to 
some extent, X-Terminals have it, so this is not very far fetched..).

What problem do you solve? 
Type 1. Cleartext passwords over supposedly insecure channels.

What problem does it NOT solve? 
Type 2. Password weakness problems:
 - password guessing 
 - dictionary attacks
 - intentional password sharing
 - unintentional password sharing /* That little Post-It note.... */
 - enforcing accountability /* i.e. you can never prove intentional password 
   sharing; a guilty user can always claim someone guessed his password */

Analysis of security break-ins across many corporations (and I bet its 
the same for the University world) shows that the major source of threats 
are Type 2 problems. 

Most academic work on cryptographic protocol security has focussed on 
Type 1 problems. Probably because it is the more interesting and tractable 
problem. Kerberos is a good example of the tremendous steps taken towards 
solving Type 1 problems.

Meanwhile in the real world, where Type 2 problems cost companies millions 
of dollars, solutions such as SecureID, which take strong steps towards 
solving Type 2 problems, ARE EXTREMELY IMPORTANT.

Please note: This is not meant to trivialize the Kerberos work; it is 
also very important, and the smarter your average hacker gets, the more 
important Type-1 problems will get. But it must be realized that methods 
of solving Type-2 problems (e.g. the recent Kerberos work to protect against 
dictionary attacks using public-key, Secure ID type systems, etc.) are
vital to closing the doors most often used by hackers.


-Ravi

*****************************************************************************
Ravi Ganesan				e-mail: ravi.ganesan@bell-atl.com
IS SAS Corporate Network Planning	v-mail: (301) 595-8439
Bell Atlantic				fax:	(301) 595-1341
*****************************************************************************

home help back first fref pref prev next nref lref last post