[2157] in Kerberos

home help back first fref pref prev next nref lref last post

Re: New User Accounts

daemon@ATHENA.MIT.EDU (Ravi Ganesan (301) 595-8439)
Thu Sep 3 10:35:43 1992

From: bagate!socrates!bf4grjc (Ravi Ganesan (301) 595-8439)
To: 0003858921@mcimail.com (Robert G. Moskowitz)
Date: Thu, 3 Sep 92 10:09:06 EDT
Cc: kerberos@Athena.MIT.EDU
In-Reply-To: <53920903103935/0003858921NA3EM@mcimail.com>; from "Robert G. Moskowitz" at Sep 3, 92 10:39 am
Reply-To: socrates!socrates.bell-atl.com!ravi

> 
> Ganesan writes:
> 
> >What problem does it NOT solve? 
> >Type 2. Password weakness problems:
> > - password guessing 
> > - dictionary attacks
> 
> >From the Kerberos class that I took at spring INTEROP, it would seem that the
> dictionary in v5 will pretty much stop these two.
>
Observe that there is a trade off situation in using difficult passwords, 
especiailly when they change often due to password aging, and when a user 
has accounts on several systems which as yet cannot share authentication. 
i.e. the harder the password, the more likely the user is to write it down.

Dictionary attacks can eb stopped using the protocls developed by li Gong et 
al, and by Bellovin & Merrit. Note that the latter necessitates the use 
of public-key, and both have (probably acceptable) an overhead.

> 
> Nothing will stop intentional password sharing.  Even with a SecureID.  It is
> just more limited with SecureID.
> 

With a token authenticator, a physical device needs to change hands for 
password sharing can take place, which in general would require the complicity
of the person doing the sharing, which can be audited. 

While I'm sure sharing can/will still occur, it is FAR MORE limited. Nothing 
works like the detterrent of being resonsible for your actions! 

Ravi
-- 


*******************************************************************************

Ravi Ganesan                            e-mail: ravi@socrates.bell-atl.com
IS SAS Corporate Network Planning       v-mail: (301) 595-8439
Bell Atlantic                           Fax:    (301) 595-1341

Note: If your e-mail reply to me bounces, try sending it explicitly to 
ravi@socrates.bell-atl.com instead of using the 'reply' feature.
******************************************************************************

home help back first fref pref prev next nref lref last post