An update on the Fedora August 2008 intrusion
An update on the Fedora August 2008 intrusion
Posted Mar 31, 2009 12:33 UTC (Tue) by tialaramex (subscriber, #21167)In reply to: An update on the Fedora August 2008 intrusion by gdt
Parent article: An update on the Fedora August 2008 intrusion
Challenge response doesn't help you. The same user who elects not to set a passphrase on his private key, will leave the challenge response device on his desk or even on the bus. He'll write the mandatory 15 character password on a PostIt. Enforcing this stuff remotely is very difficult when you don't trust your authorised personnel to obey policy. In fact I think it's impossible and your examples haven't changed my mind.
If this Fedora contributor ran Fedora, they had the option to enter their SSH passphrase as infrequently as once per (desktop) login. Is that too much?
