[OpenAFS] krb4 3des vulnerability

Derek Atkins warlord@MIT.EDU
17 Mar 2003 18:53:43 -0500


Knowing one is sufficient.

I don't know exactly what is considered "long".  I believe the
answer is "8".

-derek

Russ Allbery <rra@stanford.edu> writes:

> Derek Atkins <warlord@MIT.EDU> writes:
> 
> > You are still vulnerable, but only to those people who know the keys to
> > "long" principals.
> 
> Only one, or do they have to know more than one?  (And is there any
> quantifier on "long"?)
> 
> -- 
> Russ Allbery (rra@stanford.edu)             <http://www.eyrie.org/~eagle/>
> _______________________________________________
> OpenAFS-info mailing list
> OpenAFS-info@openafs.org
> https://lists.openafs.org/mailman/listinfo/openafs-info

-- 
       Derek Atkins, SB '93 MIT EE, SM '95 MIT Media Laboratory
       Member, MIT Student Information Processing Board  (SIPB)
       URL: http://web.mit.edu/warlord/    PP-ASEL-IA     N1NWH
       warlord@MIT.EDU                        PGP key available