[7969] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Kerberos 5 and S/Key

daemon@ATHENA.MIT.EDU (Joe Kovara)
Sun Sep 15 17:40:54 1996

To: kerberos@MIT.EDU
Date: Sun, 15 Sep 1996 19:02:43 GMT
From: joek@CyberSafe.com (Joe Kovara)

mas@ucla.edu (Michael Stein) in comp.protocols.kerberos wrote:
> What's the point?  My understanding of Kerberos is that anyone can
> request  a  TGT from the kerberos security server, but the reply is
> going to be encrypted in the users secret key (his password).   

Reusable passwords are less secure than single-use/one-time passwords because
reusable passwords are subject to many relatively simple attacks.  The password
itself is the object of the attack--which obviously results in compromising
whatever the password is protecting--a seemingly academic, but important,
distinction.

To put it another way: static targets are easier to hit than moving ones.

Regards,
Joe Kovara / CyberSafe Corp. / joek@cybersafe.com


home help back first fref pref prev next nref lref last post