Re: forging a new pppext charter

Barney Wolff <[email protected]>
Newsgroups gmane.ietf.pppext
Message-ID <[email protected]>
On Tue, Feb 17, 2004 at 01:24:20PM -0500, James Carlson wrote:
> 
> The real issue (if there is one at all) is that PAP is still
> operationally important, and is likely to be so for the indefinite
> future.  In security terms, it's exactly equivalent to the traditional
> "login:/Password:" interface and carries no more or less risk than
> that does.  In particular, it allows access to existing user
> authentication schemes (e.g., PAM) that don't require that the
> password be stored in the clear, as is the case with CHAP.

PAP works for token cards, although I suppose EAP is a better choice.
But the PAP/CHAP decision is entangled with the unfortunate design of
RADIUS that the PAP password is encrypted but the CHAP challenge and
response are not, thus exposing the CHAP secret to offline dictionary
attack.

I also volunteer to participate in writing/editing updated RFCs, and
add my thanks to Karl.

Regards,
Barney

-- 
Barney Wolff         http://www.databus.com/bwresume.pdf
I'm available by contract or FT, in the NYC metro area or via the 'Net.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.