Re: Registry lock - two-factor or intervention
Jarle Greipsland <[email protected]> Thu, 19 Sep 2013 08:36:57 +0200 (CEST)
| Newsgroups | gmane.ietf.provreg |
|---|---|
| Message-ID | <[email protected]> |
Jay Daley <[email protected]> writes: [ ... ] > How exactly do you think a registrar can mistakenly authorise a change via an OOB mechanism? > > In my view, the threats and realistic likelihood of those threats, are: > > 1. The registrar is hacked and the miscreant sends a change request using the registrar credentials. [Likelihood = Possible] > > 2. The registrar mistakenly requests a change. [Likelihood = Unlikely] > > 3. The registrar mistakenly requests a change and then also mistakenly authorises the OOB challenge. [Likelihood = Very Rare] 3b. The registrar deliberately, as a result of e.g. social engineering or blackmail, requests a change and then also deliberately authorises the OOB challenge. [Likelihood = ??] -jarle _______________________________________________ provreg mailing list [email protected] https://www.ietf.org/mailman/listinfo/provreg