[2158] in Kerberos
Re: New User Accounts
daemon@ATHENA.MIT.EDU (smb@ulysses.att.com)
Thu Sep 3 13:03:16 1992
From: smb@ulysses.att.com
To: socrates!socrates.bell-atl.com!ravi
Cc: kerberos@Athena.MIT.EDU
Date: Thu, 03 Sep 92 11:16:09 EDT
Dictionary attacks can eb stopped using the protocls developed
by li Gong et al, and by Bellovin & Merrit. Note that the
latter necessitates the use of public-key, and both have
(probably acceptable) an overhead.
Both protocols require public key cryptosystems. One significant difference
is that the Lomas/Gong/Needham/Saltzer protocol requires a known public
key for the server, and the Bellovin/Merritt one does not. Both require
high-quality random numbers. Bellovin/Merritt imposes some possibly-tricky
constraints on what a public key can look like.
--Steve Bellovin