Re: KDC model and atomicity
"Henry B. Hotz" <[email protected]> Wed, 13 Jun 2012 17:31:40 -0700
| Newsgroups | gmane.ietf.krb-wg |
|---|---|
| Message-ID | <[email protected]> |
On Jun 13, 2012, at 4:55 PM, Nico Williams wrote: > But also, none of this really says anything at all about password > guessing attacks. > > A smart attacker will try a safe number of passwords < N for each > principal in whatever period of time the attacker can expect the users > to successfully authenticate. This way the attacker can mount a slow > attack, but if there's lots of users the attacker can still make > progress fairly quickly. Which really goes to my second objection: I > object to N-strikes-you're-locked. It's not a good feature; it's a > _DoS_ attack vector where none need exist; it's hard to implement > correctly; it doesn't actually protect against password guessing > attacks, and it protects less well as the number of users in a realm > goes up. > > I'd be much happier just ripping this out. If it must stay in I want > all of it to be optional, and I want the security considerations > section to discuss the DoS issue and the low effectiveness of this > feature in stopping password guessing attacks. The Kerberos admin may not get a choice. There are lots of N-strikes--- requirements out there. If you can't support the requirement maybe you have to use a different technology. In other words, maybe slow-down is the right solution, but maybe N-strikes--- is the required solution. At least the data model, if not all implementations, should support both solutions, and hopefully others as well. There appears to be consensus for defining some generic statistics the model could expose, and leaving the actual interpretation and resulting actions to the specific implementations? (Except that an unlock action is clearly needed. I'd generalize that to something that can clear an intentional slow-down as well.) ------------------------------------------------------ The opinions expressed in this message are mine, not those of Caltech, JPL, NASA, or the US Government. [email protected], or [email protected] _______________________________________________ ietf-krb-wg mailing list [email protected] https://lists.anl.gov/mailman/listinfo/ietf-krb-wg