An update on the Fedora August 2008 intrusion
Posted Mar 30, 2009 23:35 UTC (Mon) by
gdt (subscriber, #6284)
In reply to:
An update on the Fedora August 2008 intrusion by tialaramex
Parent article:
An update on the Fedora August 2008 intrusion
There's a wide variety of choices. Challenge-response cards being one obvious alternative. Or patching sshd so that authentication can be stacked (eg: key followed by password).
The blocking issue is a lack of federated single sign on. You can make authentication more complex but people aren't willing to go through multi factor rigmarole for every resource accessed [as this episode nicely demonstrates]. SSO limits the number of times authentication is requested to a few times a day.
(
Log in to post comments)