[7969] in Kerberos
Re: Kerberos 5 and S/Key
daemon@ATHENA.MIT.EDU (Joe Kovara)
Sun Sep 15 17:40:54 1996
To: kerberos@MIT.EDU
Date: Sun, 15 Sep 1996 19:02:43 GMT
From: joek@CyberSafe.com (Joe Kovara)
mas@ucla.edu (Michael Stein) in comp.protocols.kerberos wrote:
> What's the point? My understanding of Kerberos is that anyone can
> request a TGT from the kerberos security server, but the reply is
> going to be encrypted in the users secret key (his password).
Reusable passwords are less secure than single-use/one-time passwords because
reusable passwords are subject to many relatively simple attacks. The password
itself is the object of the attack--which obviously results in compromising
whatever the password is protecting--a seemingly academic, but important,
distinction.
To put it another way: static targets are easier to hit than moving ones.
Regards,
Joe Kovara / CyberSafe Corp. / joek@cybersafe.com