[7963] in Kerberos
Re: Kerberos 5 and S/Key
daemon@ATHENA.MIT.EDU (Sam Hartman)
Sun Sep 15 12:52:22 1996
To: Jacques Vidrine <nectar@communique.net>
Cc: Michael Stein <mas@ucla.edu>, kerberos@MIT.EDU
From: Sam Hartman <hartmans@MIT.EDU>
Date: 15 Sep 1996 12:36:35 -0400
In-Reply-To: Jacques Vidrine's message of Sat, 14 Sep 1996 16:59:52 -0500 (CDT)
>>>>> "Jacques" == Jacques Vidrine <nectar@communique.net> writes:
Jacques> So that someone may log in to a computer from the
Jacques> Internet without exposing his/her password.
Jacques> Presumably, there could be a key that the S/Key service
Jacques> could use for decrypting the TGT.
While there are valid uses for this setup, and I have wished
for its existance from time to time, it tends not to be as strong as
full Kerberos security. In particular, many Kerberos sites expect
their admins to have fully encrypted sessions when doing server
maintainance Also, you are vulnerable to all the standard OTP attacks.
Again, the technology is useful--I just get nervous when
people start throwing around terms like "not expose your password," or
"secure".
--Sam