Re: confusion in ank.



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Mon 2007-04-23 11:52:36 -0400, Nicolas Williams wrote:

Password quality policies certainly shouldn't apply to randomly-
generated keys, but that does not mean that there cannot be a key
expiration policy.

i agree that it's worthwhile to support expiration policy for
randomly-generated keys. One could even argue for iteratively
applying password-quality policies to randomy-generated keys from a
pragmatic approach:

In the unlikely event the randomly-generated key happens to be
guessable by common tools (dictionary attacks, limited character
classes, etc), it's probably worth generating a new random key. While
this reduces the overall space of possible random keys, it does keep
the random keys out of the (admittedly tiny) space regularly probed by
the most common brute force attackers.

--dkg
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Processed by Mailcrypt 3.5.8+ <http://mailcrypt.sourceforge.net/>

iD8DBQFGLOe3iXTlFKVLY2URAmTRAJ9eiJ2qnt5N22NhhMLE+8jQeD9U+QCffrXU
FuRYHsQwMjmsxx+7nDs3PxU=
=MNUn
-----END PGP SIGNATURE-----
________________________________________________
Kerberos mailing list Kerberos@xxxxxxx
https://mailman.mit.edu/mailman/listinfo/kerberos

.



Relevant Pages

  • Re: Bad news for Block Ciphers?
    ... > random keys and one on the fixed key given as example in Filiol's paper. ... The bias on bit 19 is well ... below the standard deviation, and the bias on bit 71 is not far above ... Ongoing simulations on other keys yield similar results. ...
    (sci.crypt)
  • Re: Bad news for Block Ciphers?
    ... >> random keys and one on the fixed key given as example in Filiol's paper. ... > below the standard deviation, and the bias on bit 71 is not far above ...
    (sci.crypt)
  • Re: [YANI] random keys that dont suck
    ... in order to open a door with a key, you had to go through your ... collection of keys trying each in turn until you found the "right" ... "The door opens with the Xth key" where X is some number from 1 ... of some subset of random keys, how broadly applicable are lockpicks, ...
    (rec.games.roguelike.development)
  • Re: A wish and a dream...
    ... >> for random keys and such... ... but myabe I'm missing this fetaure. ... > Versus $10 for an iButton reader and $2 for an iButton? ... > code to extract the keys from the iButton, ...
    (FreeBSD-Security)