ssh and security
Posted Dec 4, 2003 16:25 UTC (Thu) by
scripter (subscriber, #2654)
Parent article:
ssh and security
Thank you! I thought your letter was informative, and it makes people aware of the limitations of SSH.
You mention that a challenge response system is a solution to the shortcomings of SSH. Unfortunately, as far as I know, a hardware based challenge-response system is prohibitively expensive, especially in the OSS development model. And it is difficult to distribute the hardware (or a paper with one-time passwords). The hardware costs money. Postage costs money. Administration costs time and/or money. The person issuing the challenge-response system to users has to be able to verify if they want to trust each individual user.
Is there a way to "revoke" a smart card or equivellent system?
Is there a software-only solution that avoids the high distribution costs?
Thoughts?
(
Log in to post comments)