[7965] in Kerberos
Re: Kerberos 5 and S/Key
daemon@ATHENA.MIT.EDU (Jacques Vidrine)
Sun Sep 15 14:21:06 1996
Date: Sun, 15 Sep 1996 12:35:07 -0500 (CDT)
From: Jacques Vidrine <nectar@communique.net>
To: Sam Hartman <hartmans@MIT.EDU>
Cc: Michael Stein <mas@ucla.edu>, kerberos@MIT.EDU
In-Reply-To: <tslk9tvspkc.fsf@tertius.mit.edu>
On 15 Sep 1996, Sam Hartman wrote:
> While there are valid uses for this setup, and I have wished
> for its existance from time to time, it tends not to be as strong as
> full Kerberos security. In particular, many Kerberos sites expect
> their admins to have fully encrypted sessions when doing server
> maintainance Also, you are vulnerable to all the standard OTP attacks.
>
> Again, the technology is useful--I just get nervous when
> people start throwing around terms like "not expose your password," or
> "secure".
>
> --Sam
Thanks for the comments, Sam. I am in agreement with you. In my
particular case, I am an ISP. I currently do not allow any connectivity
to my systems from outside of my network. However, I've a lot of demand
for this, for checking email remotely for example.
But as you may well guess, 99.9% of my customers think nothing about
security. Not only do they manage to choose bad passwords, but they
think nothing about using them over the Internet-at-large. Thus I desire
to FORCE users connecting from the Internet-at-large to authenticate via
S/Key.
Long term, I hope that there will be a wide variety of TELNET and email
clients that are Kerberos aware, so that these customers can simply
authenticate via Kerberos and use an encrypted session. But for today,
OTPs seem like my only option.
i.e. OTPs are better than the current options (cleartext passwords) :-)
Jacques Vidrine <nectar@communique.net> Communique, Inc.