Great Circle Associates Firewalls
(November 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: re: SDI's Time-Synched SecurIDs
From: Bob Bosen <bbosen @ netcom . com>
Date: Thu, 30 Nov 1995 11:43:33 -0800 (PST)
To: firewalls @ greatcircle . com
In-reply-to: <951129121513 . 20214703 @ hobbes . orl . mmc . com>




On Wed, 29 Nov 1995, A. Padgett Peterson, P.E. Information Security wrote:

> 
> Before such things, numbers of keystrokes that must be entered may have 
> been a factor, though far less than stated (I use both. With the C/R, I
                 ^^^^^^^^^^^^^^^^^^^^^^^^^^^
> read digits from the screen, press on/off, enter PIN+digits (seven total) 
> into the card, & press "E". Read seven digits off the card, type into 
> keyboard. Press enter. 17 keystrokes.
> 
> With TS I read six digits off the card & type 12 digits into the screen
> (6 ID & 6 response). Press enter. 13 keystrokes. Delta four whole 
> keystrokes. If this makes a difference to anyone, they are not really 
> doing anything (opinion).
> 
> Other difference is that fixed id is sent in clear with TS, PIN is 
> kept secret with C/R.
> 
> (Not counting the username/password I enter in both cases). Do not think
> keystrokes is really a factor. Is not at all with soft tokens since 
> authentication requirements are similar for either.
> 
> 
> ps know the date 36 months from issue one of my TS cards will stop working,
>    the C/R one I have had since 1990 just keeps on ticking. Of course it
>    only needs to be on for 20 seconds a day.
> 

Dear Padgett: Bless you for helping clarify the oft-overblown hyperbole
about how hard it is to enter a challenge! I hope that 1990 card is one of
ours....





Bob Bosen
Enigma Logic Inc.
2151 Salvio St. #301
Concord, CA   94520
USA

Tel: +1 510 827-5707
Internet: bbosen @
 netcom .
 com
http://www.safeword.com
ftp://ftp.safeword.com/download/
**************************************************************************
* "It wasn't me!!! Somebody must have captured my username/password!!!"  *
**************************************************************************



References:
Indexed By Date Previous: Re: V-One Firewall
From: cjolley @ iac . net
Next: tn3270 proxy
From: bncqraq @ is000913 . BELL-ATL . COM (Morris)
Indexed By Thread Previous: re: SDI's Time-Synched SecurIDs
From: "A. Padgett Peterson, P.E. Information Security" <PADGETT @ hobbes . orl . mmc . com>
Next: is a second filter router worthwhile?
From: Eric Vanuska <vanuskae @ halsp . hitachi . com>

Google
 
Search Internet Search www.greatcircle.com