Tokens for Admin accounts

From: John (sregney@gedas.es)
Date: 08/23/01


Date: 23 Aug 2001 13:48:52 -0000
Message-ID: <20010823134852.15808.qmail@securityfocus.com>
From: John <sregney@gedas.es>
To: security-basics@securityfocus.com
Subject: Tokens for Admin accounts

Hello Everyone,

It seems like the goal of most hacking attempts are in
some way designed to get access to Admin.
privileges. We often hear talk of good passwords
using 8 characters, non-dictionary words,
mnemonics, blah, blah, blah. Our network is fairly
large and consists of UNIX, NT, and 2000 and uses
an ACE Server and SecureID for external users.

My question:

Why not require token authentication on all
Administrator accounts?

 Sure, the Adms. would have to now use a token for
both remote and local access, but wouldn’t this
eliminate most password problems like: bad; shared;
compromised passwords, etc? Am I missing
anything here?

Thanks All,
John



Relevant Pages

  • Re: Password alternatives
    ... their algorithm remaining secret, which in terms of cryptography is bad ... I'm not an expert on tokens. ... Unlike passwords, biometrics do have the problem of False Accept Rate ... passphrases as a string of characters, ...
    (Security-Basics)
  • RE: [Full-disclosure] Re: RSA SecurID SID800 Token vulnerable by design
    ... authentication is only as good as the password - malware can probe the ... In the event of an unconnected OTP token, a variety of MITM attacks still ... well as he network) OTP is better than passwords alone. ... Does the risk justify the costs involved (tokens, ...
    (Full-Disclosure)
  • RE: [Full-disclosure] Re: RSA SecurID SID800 Token vulnerable by design
    ... authentication is only as good as the password - malware can probe the ... In the event of an unconnected OTP token, a variety of MITM attacks still ... well as he network) OTP is better than passwords alone. ... Does the risk justify the costs involved (tokens, ...
    (Bugtraq)
  • Re: Password alternatives
    ... Unlike passwords, biometrics do have the problem of False Accept Rate ... As for tokens, AFAIK they rely on ... passphrases as a string of characters, ...
    (Security-Basics)
  • Re: How do OTP tokens work?
    ... security domain) as they currently require (shared-secret) passwords ... (large scores of such tokens). ... secret guidelines (like unique shared secret for different, ... remember passwords or tokens that have to be carried, ...
    (comp.security.unix)