One Time Identification, a request for comments/testing.

Jeffrey Hutzelman jhutz at
Fri Feb 2 10:25:36 EST 2007

On Friday, February 02, 2007 10:05:09 AM -0500 Jim Rees <rees at> 

> So would it be fair say this is sort of like using a smartcard in that you
> need both possession of the token and knowledge of a PIN?  And that the
> KDC guards the PIN against brute force guessing, because each guess
> requires a transaction against the KDC?  So stealing the token gets the
> attacker nothing?

No.  Smart cards are not (generally) simple storage devices.  What guards a 
smartcard PIN against brute force guessing is that you only get a limited 
number of tries before the card locks itself and becomes useless.  And what 
protects the private key is the fact that only the card knows the key, so 
if the card is not physically present (or has been locked out due to too 
many wrong PIN's), it is impossible to perform crypto operations with the 
private key.

What we're talking about here is something completely different.  Yes, you 
need both posession of a physical object and a password.  But the 
similarity ends there.

-- Jeff

More information about the krbdev mailing list