Re: Cryptography problem

From: Gerard Bok (bok118_at_zonnet.nl)
Date: 06/24/04

  • Next message: Rob Slade, doting grandpa of Ryan and Trevor: "REVIEW: "Security Warrior", Cyrus Peikari/Anton Chuvakin"
    Date: Thu, 24 Jun 2004 11:31:44 GMT
    
    

    On Wed, 23 Jun 2004 16:24:44 GMT, Dean Hallman <deanh@sc.rr.com>
    wrote:
     
    >> Maybe tickets solve your problem ?
    >>
    >> You ship each of your rich clients with a unique ticket.
    >> Each request validates the ticket, supplies an answer, and a new
    >> ticket, to be used for the clients next request.
    >
    >Yes, I had considered something similar to this. But, connect the current
    >search with the next search in this way could lead to "out of sync"
    >problems. What if the client is uninstalled and reinstalled, for example.
    >The ticket for use on the next search could be lost.

     'out of sync' need not pose any problems, as you can define a
    window to accomodate that situation.

    How would your server distinguish between a client being
    reinstalled on the same machine from that client being installed
    on 10.000 hacked machines (as was your original problem, wasn't
    it) ?

    Re-authorizing after reinstall seems a modest requirement.
    You either implement a secure identification system or you don't
    :-)

    -- 
    Kind regards,
    Gerard Bok
    

  • Next message: Rob Slade, doting grandpa of Ryan and Trevor: "REVIEW: "Security Warrior", Cyrus Peikari/Anton Chuvakin"

    Relevant Pages

    • Re: Cryptography problem
      ... >> You ship each of your rich clients with a unique ticket. ... >> Each request validates the ticket, supplies an answer, and a new ... What if the client is uninstalled and reinstalled, ... Re-authorizing after reinstall seems a modest requirement. ...
      (alt.computer.security)
    • Re: Kerberised NFS
      ... Kerberised NFS presumably requires authentication and encryption between client and server, so presumably the client needs to get a ticket prior to contacting the server. ... server with kerberos security options, and successfully automounting user's home directories on client machines when they log in. ...
      (comp.protocols.kerberos)
    • Service Ticket Request Failure Audit
      ... Service Ticket Request: ... Please make sure that the time between the client and the server ...
      (microsoft.public.windows.server.sbs)
    • Re: Kerberised NFS
      ... the client needs to get his ticket initially somehow. ... the result is that client gets kerberos ticket during GDM logon - ... Is there a ticket beween client and server that expires? ...
      (comp.protocols.kerberos)
    • Help needed regarding Office Sharepoint Integration.
      ... I have no luck with Sharepoint Office Integration since WSS ... Service Ticket Granted: ... Client Address: 192.168.0.10 ... Successful Logon: ...
      (microsoft.public.sharepoint.windowsservices)