Re: OPIE Challenge sequence

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: <freebsd-security@...>
Date: Tuesday, July 8, 2008 - 3:27 pm

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

> On the bright side, it should be fairly easy to write an OTP calculator

These already exist for J2ME-enabled mobiles (which is most of them?):

http://tanso.net/j2me-otp/
http://otp-j2me.sourceforge.net/

> Systems like OPIE, where the challenge is actually issued to the user

There exist apps (i.e., browsers, FTP clients, mailers, etc) that
integrate OPIE and can transparently respond to challenges. The user just
puts in his password, and he doesn't worry about plaintext or OPIE or
whatever; the app just does the right thing. Fetch, an FTP client for the
Mac, is one such app.

One could argue that this encourages users to just punch in their password
and not understand if it's going to go over the wire in the clear or be
used to answer a challenge, but it's very useful when you have users who
are incapable of making such distinction in the first place and you just
need to make sure their password is secure for _your_ service.

-Jason

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (FreeBSD)
Comment: See https://private.idealab.com/public/jason/jason.gpg

iD8DBQFIc7+YswXMWWtptckRAoaAAJkBnis9pNHnwuXCc6zjqESrDh8zGwCfTYWC
41JZRoD12LhIpG3QK7cfhMU=
=w11K
-----END PGP SIGNATURE-----
_______________________________________________
freebsd-security@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
ports/128698: [vuxml] new entry for Dovecot 1.1.4-1.1.5, Eygene Ryabinkin, (Sat Nov 8, 10:03 am)
RE: CVE-2008-4609, olli hauer, (Tue Sep 8, 4:58 pm)
OCF, Raja FreeBSD, (Thu Sep 20, 5:49 am)
Re: OPIE Challenge sequence, Ivan Grover, (Tue Jul 8, 9:41 am)
Re: IPSEC help, john decot, (Sat Nov 17, 5:06 am)
Re: OPIE Challenge sequence, Dag-Erling Smørgrav, (Tue Jul 8, 11:37 am)
Re: OPIE Challenge sequence, Ivan Grover, (Wed Jul 9, 2:55 am)
Re: OPIE Challenge sequence, Dag-Erling Smørgrav, (Wed Jul 9, 4:29 am)
Re: OPIE Challenge sequence, Jason Stone, (Tue Jul 8, 3:27 pm)
Re: OPIE Challenge sequence, Ivan Grover, (Wed Jul 9, 4:18 am)
Re: IPSEC help, Shoichi Sakane, (Thu Nov 29, 9:56 pm)
Re: IPSEC help, VANHULLEBUS Yvan, (Mon Nov 19, 5:38 am)
Re: IPSEC help, john decot, (Tue Nov 20, 6:57 am)
Re: IPSEC help, VANHULLEBUS Yvan, (Tue Nov 20, 8:34 am)
Re: IPSEC help, john decot, (Tue Nov 20, 12:46 pm)
Re: IPSEC help, VANHULLEBUS Yvan, (Tue Nov 20, 12:56 pm)
Re: IPSEC help, john decot, (Thu Nov 22, 11:08 am)
Re: IPSEC help, Bjoern Engels, (Tue Nov 20, 7:08 am)
Re: OCF, Mohacsi Janos, (Fri Sep 21, 5:30 am)
Re: OCF, Eygene Ryabinkin, (Fri Sep 21, 11:58 am)