"Ivan Grover" writes:
There is no way to deduce the next challenge from the current one. This
is documented in the opie(4) man page.
Here's the only advisory I could find for OPIE:
http://security.freebsd.org/advisories/FreeBSD-SA-06:12.opie.asc
> I ask this because usually the challenge/response implementations
OPIE cannot use random challenges, because one of the requirements is
that it should be possible to print a list of pre-generated responses.
The advantage of OPIE over traditional passwords is that OPIE is not
vulnerable to replay attacks, but this is not as relevant these days as
it was back when S/Key (on which OPIE is based) was designed. Replay
attacks aren't very effective against encrypted protocols such as SSH.
> My problem is to determine the best challenge/response implementation
Systems like OPIE, where the challenge is actually issued to the user
and not just to the user's software, require the user to have access to
a response calculator, or to carry a sheet of precalculated responses.
The former is difficult unless the users always log in from their own
desktop or laptop computer, and the latter is usually a bad idea since
someone might steel the sheet. On the bright side, it should be fairly
easy to write an OTP calculator that run on a cell phone, such as an
S60-based Nokia phones or an iPhone.
I'd say that the only advantage of OPIE today is that it's free.
DES
--
Dag-Erling Smørgrav - des@des.no
_______________________________________________
freebsd-security@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
| David Miller | Re: Slow DOWN, please!!! |
| debian developer | Re: Dual-Licensing Linux Kernel with GPL V2 and GPL V3 |
| Roland Dreier | Re: Integration of SCST in the mainstream Linux kernel |
| Ingo Molnar | Re: containers (was Re: -mm merge plans for 2.6.23) |
git: | |
| Jarek Poplawski | [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock(). |
| Josip Rodin | bnx2_poll panicking kernel |
| David Miller | [GIT]: Networking |
| Gerrit Renker | [PATCH 13/37] dccp: Deprecate Ack Ratio sysctl |
