[2157] in Kerberos
Re: New User Accounts
daemon@ATHENA.MIT.EDU (Ravi Ganesan (301) 595-8439)
Thu Sep 3 10:35:43 1992
From: bagate!socrates!bf4grjc (Ravi Ganesan (301) 595-8439)
To: 0003858921@mcimail.com (Robert G. Moskowitz)
Date: Thu, 3 Sep 92 10:09:06 EDT
Cc: kerberos@Athena.MIT.EDU
In-Reply-To: <53920903103935/0003858921NA3EM@mcimail.com>; from "Robert G. Moskowitz" at Sep 3, 92 10:39 am
Reply-To: socrates!socrates.bell-atl.com!ravi
>
> Ganesan writes:
>
> >What problem does it NOT solve?
> >Type 2. Password weakness problems:
> > - password guessing
> > - dictionary attacks
>
> >From the Kerberos class that I took at spring INTEROP, it would seem that the
> dictionary in v5 will pretty much stop these two.
>
Observe that there is a trade off situation in using difficult passwords,
especiailly when they change often due to password aging, and when a user
has accounts on several systems which as yet cannot share authentication.
i.e. the harder the password, the more likely the user is to write it down.
Dictionary attacks can eb stopped using the protocls developed by li Gong et
al, and by Bellovin & Merrit. Note that the latter necessitates the use
of public-key, and both have (probably acceptable) an overhead.
>
> Nothing will stop intentional password sharing. Even with a SecureID. It is
> just more limited with SecureID.
>
With a token authenticator, a physical device needs to change hands for
password sharing can take place, which in general would require the complicity
of the person doing the sharing, which can be audited.
While I'm sure sharing can/will still occur, it is FAR MORE limited. Nothing
works like the detterrent of being resonsible for your actions!
Ravi
--
*******************************************************************************
Ravi Ganesan e-mail: ravi@socrates.bell-atl.com
IS SAS Corporate Network Planning v-mail: (301) 595-8439
Bell Atlantic Fax: (301) 595-1341
Note: If your e-mail reply to me bounces, try sending it explicitly to
ravi@socrates.bell-atl.com instead of using the 'reply' feature.
******************************************************************************