[7965] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Kerberos 5 and S/Key

daemon@ATHENA.MIT.EDU (Jacques Vidrine)
Sun Sep 15 14:21:06 1996

Date: Sun, 15 Sep 1996 12:35:07 -0500 (CDT)
From: Jacques Vidrine <nectar@communique.net>
To: Sam Hartman <hartmans@MIT.EDU>
Cc: Michael Stein <mas@ucla.edu>, kerberos@MIT.EDU
In-Reply-To: <tslk9tvspkc.fsf@tertius.mit.edu>


On 15 Sep 1996, Sam Hartman wrote:

> 	While there are valid uses for this setup, and I have wished
> for its existance from time to time, it tends not to be as strong as
> full Kerberos security.  In particular, many Kerberos sites expect
> their admins to have fully encrypted sessions when doing server
> maintainance Also, you are vulnerable to all the standard OTP attacks.
>
> 	Again, the technology is useful--I just get nervous when
> people start throwing around terms like "not expose your password," or
> "secure".
> 
> --Sam

Thanks for the comments, Sam.  I am in agreement with you.  In my 
particular case, I am an ISP.  I currently do not allow any connectivity 
to my systems from outside of my network.  However, I've a lot of demand 
for this, for checking email remotely for example.

But as you may well guess, 99.9% of my customers think nothing about 
security.  Not only do they manage to choose bad passwords, but they 
think nothing about using them over the Internet-at-large.  Thus I desire 
to FORCE users connecting from the Internet-at-large to authenticate via 
S/Key.

Long term, I hope that there will be a wide variety of TELNET and email 
clients that are Kerberos aware, so that these customers can simply 
authenticate via Kerberos and use an encrypted session.  But for today, 
OTPs seem like my only option. 

i.e. OTPs are better than the current options (cleartext passwords) :-)
 
Jacques Vidrine <nectar@communique.net>               Communique, Inc.


home help back first fref pref prev next nref lref last post