Great Circle Associates Firewalls
(March 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: ADDENDUM: Brief report on Firewalls BoF from Networld+Interop, Las Vegas
From: dedlow @ voro . lbl . gov (Mark Dedlow)
Date: Thu, 30 Mar 1995 23:04:25 -0800
To: avalon @ coombs . anu . edu . au, joshua @ dee . retix . com
Cc: avolio @ tis . com, firewalls @ greatcircle . com

>>   Whilst one-time keycards are nice, ones such as S/Key are also "dangerous".
>
>>   If you're attending a conference (and have a name tag), or travelling,
>>   you're going to take your s/key list or other with you...whilst the
>>   security seems well and good, it does, however, reduce the skill required
>>   to get `in' to somene who is good at picking pockets...and what do you do
>>   if you `lose' your `card' ?  Can you call back to work, 24 hours a day and
>>   report it missing ?
>
>you could keep your s/key list encrypted on a laptop.
>
>josh
>

Isn't the design intention of S/key that one generates one-time 
passwords (using memorized secret key) on-the-fly?  I thought
that carrying around lists of pre-generated passwords was a compromise 
for when one didn't have a local key generation system (though I know
there are considerations running the key software on X networks, where
one may accidentally run the key generator on a remote host, thus
passing the secret password in clear text via telnet).  But if you've 
got a laptop, why pre-generate keys, and then encrypt them?  Just 
generate them as needed.  S/key is available for DOS and Macs.

Mark


Follow-Ups:
Indexed By Date Previous: Re: Outgoing ftp and filters
From: Brent @ GreatCircle . COM (Brent Chapman)
Next: Re: A "real" security expert
From: patrick @ oes . amdahl . com (Patrick Horgan)
Indexed By Thread Previous: Re: ADDENDUM: Brief report on Firewalls BoF from Networld+Interop, Las Vegas
From: jgt10 @ amdahl . com (John G. Thompson)
Next: Re: ADDENDUM: Brief report on Firewalls BoF from Networld+Interop, Las Vegas
From: Darren Reed <avalon @ coombs . anu . edu . au>

Google
 
Search Internet Search www.greatcircle.com