Great Circle Associates Firewalls
(March 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: ADDENDUM: Brief report on Firewalls BoF from Networld+Interop, Las Vegas
From: Darren Reed <avalon @ coombs . anu . edu . au>
Date: Fri, 31 Mar 1995 11:59:28 +1000 (EST)
To: avolio @ tis . com (Frederick M Avolio)
Cc: firewalls @ greatcircle . com
In-reply-to: <9503301442 . AA19837 @ tis . com> from "Frederick M Avolio" at Mar 30, 95 09:41:54 am

Whilst one-time keycards are nice, ones such as S/Key are also "dangerous".

If you're attending a conference (and have a name tag), or travelling,
you're going to take your s/key list or other with you...whilst the
security seems well and good, it does, however, reduce the skill required
to get `in' to somene who is good at picking pockets...and what do you do
if you `lose' your `card' ?  Can you call back to work, 24 hours a day and
report it missing ?

Some of the pricey cards require PIN numbers which is better, but again,
what sort of backup/procedure do you have for cards that go missing ?

Maybe S/key could be enhanced to require a "secret" password, in addition
to the one-time password to affirm authenticity ?  (NOT the one used to
generate the keys).  The role of it is to make up for not having a PIN
number...

darren

p.s. I'm assuming they get your wallet and/or know who you are anyway...


Follow-Ups:
References:
Indexed By Date Previous: Re: Long messages
From: tws @ wh . bayer . com
Next: Re: A "real" security expert
From: blymn @ awadi . com . AU (Brett Lymn)
Indexed By Thread Previous: ADDENDUM: Brief report on Firewalls BoF from Networld+Interop, Las Vegas
From: Frederick M Avolio <avolio @ tis . com>
Next: Re: ADDENDUM: Brief report on Firewalls BoF from Networld+Interop, Las Vegas
From: joshua geller <joshua @ dee . retix . com>

Google
 
Search Internet Search www.greatcircle.com