Re: Registry lock - two-factor or intervention

Jarle Greipsland <[email protected]> Thu, 19 Sep 2013 08:36:57 +0200 (CEST)
Newsgroups gmane.ietf.provreg
Message-ID <[email protected]>
Jay Daley <[email protected]> writes:
[ ... ]
> How exactly do you think a registrar can mistakenly authorise a change via an OOB mechanism?  
> 
> In my view, the threats and  realistic likelihood of those threats, are:
> 
> 1.  The registrar is hacked and the miscreant sends a change request using the registrar credentials. [Likelihood = Possible]
> 
> 2.  The registrar mistakenly requests a change. [Likelihood = Unlikely]
> 
> 3.  The registrar mistakenly requests a change and then also mistakenly authorises the OOB challenge.  [Likelihood = Very Rare]
3b. The registrar deliberately, as a result of e.g. social
   engineering or blackmail, requests a change and then also
   deliberately authorises the OOB challenge.  [Likelihood = ??]

					-jarle
_______________________________________________
provreg mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/provreg