On Friday, February 02, 2007 10:05:09 AM -0500 Jim Rees <[EMAIL PROTECTED]> wrote:
> So would it be fair say this is sort of like using a smartcard in that you > need both possession of the token and knowledge of a PIN? And that the > KDC guards the PIN against brute force guessing, because each guess > requires a transaction against the KDC? So stealing the token gets the > attacker nothing? No. Smart cards are not (generally) simple storage devices. What guards a smartcard PIN against brute force guessing is that you only get a limited number of tries before the card locks itself and becomes useless. And what protects the private key is the fact that only the card knows the key, so if the card is not physically present (or has been locked out due to too many wrong PIN's), it is impossible to perform crypto operations with the private key. What we're talking about here is something completely different. Yes, you need both posession of a physical object and a password. But the similarity ends there. -- Jeff ________________________________________________ Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos