Re: [fw-wiz] Username password VS hardware token plus PIN

From: Frank Knobbe (frank_at_knobbe.us)
Date: 02/22/05

  • Next message: Frank Knobbe: "Re: [fw-wiz] Username password VS hardware token plus PIN"
    To: "Marcus J. Ranum" <mjr@ranum.com>
    Date: Tue, 22 Feb 2005 11:33:54 -0600
    
    
    

    On Tue, 2005-02-22 at 11:50 -0500, Marcus J. Ranum wrote:
    > I suppose the closest that'd come would be a social engineering
    > attack along the lines of:
    > "Dear bozo@yourdomain.com -
    > We need to change the batteries in your authentication token,
    > as part of annual maintenance. Please mail it in the included
    > business reply envelope within the next 30 days if you wish to have
    > continued access.

    Your con-man forgot to ask the user to also include his PIN number.

    Most tokens lock out on 3-5 wrong PIN entries. So just stealing the
    token (the thing you have) is not enough. They also need to get the PIN
    (the thing you know) to use the token.

    That's why I was never happy with SecureID tokens since the PIN is
    transmitted during logon and thus subject to interception by an
    attacker. I preferred tokens that require the PIN to unlock the token,
    but never transmit the PIN.

    The token alone should never be enough to let you log in. A physical
    device has the valuable property that it can be stolen easier than
    secured electronic data. ;)

    Cheers,
    Frank

    
    

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards



  • Next message: Frank Knobbe: "Re: [fw-wiz] Username password VS hardware token plus PIN"

    Relevant Pages

    • Re: [fw-wiz] Username password VS hardware token plus PIN
      ... I preferred tokens that require the PIN to unlock the token, ... > but never transmit the PIN. ... has" in order to log in, I disagree that an attacker would ...
      (Firewall-Wizards)
    • RE: [fw-wiz] Username password VS hardware token plus PIN
      ... The RSA key you use, can you force regular PIN changes al la password policy ... > most USB tokens is almost guaranteed to be written down by dumb users ...
      (Firewall-Wizards)
    • Re: [fw-wiz] Username password VS hardware token plus PIN
      ... >That's why I was never happy with SecureID tokens since the PIN is ... I preferred tokens that require the PIN to unlock the token, ... >but never transmit the PIN. ...
      (Firewall-Wizards)
    • RE: [fw-wiz] Username password VS hardware token plus PIN
      ... Granted, at that point, you have my PIN, but you still don't have my token. ... > confident that XX days later, the password will be different to what ... > burned into most USB tokens is almost guaranteed to be written down by ... If you are not the intended recipient please notify the sender ...
      (Firewall-Wizards)
    • Re: RSA SecureID on Solaris
      ... And on your ACE server, a computer hooked up to a network. ... Also consider the "soft tokens." ... RSA doesn't release ... > securid + pin just to make it more secure. ...
      (Focus-SUN)