directory-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Jeffrey Hutzelman <>
Subject Re: One Time Identification, a request for comments/testing.
Date Fri, 02 Feb 2007 15:25:36 GMT

On Friday, February 02, 2007 10:05:09 AM -0500 Jim Rees <> 

> So would it be fair say this is sort of like using a smartcard in that you
> need both possession of the token and knowledge of a PIN?  And that the
> KDC guards the PIN against brute force guessing, because each guess
> requires a transaction against the KDC?  So stealing the token gets the
> attacker nothing?

No.  Smart cards are not (generally) simple storage devices.  What guards a 
smartcard PIN against brute force guessing is that you only get a limited 
number of tries before the card locks itself and becomes useless.  And what 
protects the private key is the fact that only the card knows the key, so 
if the card is not physically present (or has been locked out due to too 
many wrong PIN's), it is impossible to perform crypto operations with the 
private key.

What we're talking about here is something completely different.  Yes, you 
need both posession of a physical object and a password.  But the 
similarity ends there.

-- Jeff

View raw message