Re: Cryptanalysis of SecurID (ACE/Server)

New Message Reply About this list Date view Thread view Subject view Author view

Perry E. Metzger (perry@piermont.com)
Thu, 01 Oct 1998 18:23:06 -0400


"John Moore" writes:
> > From: Perry E. Metzger [mailto:perry@piermont.com]
> > You honestly think that dial-in can't be interfered with?
>
> All security is a tradeoff. Do you honestly think that crypto systems can't
> be attacked by techniques other than technical (dumpster diving, bribery,
> breakins, etc)?

Since the cost of a secure ID system is no lower than that of fully
encrypting the link, and in fact (given the fact that the cards self
destruct and have to be replaced at high cost) often cost
significantly more, why bother with half measures? Sure, there are
ways to break a crypto system, but if you are bothering with any
security why not do something both cheaper and better?

Perry


New Message Reply About this list Date view Thread view Subject view Author view

 
All trademarks and copyrights are the property of their respective owners.

Other Directory Sites: SeekWonder | Directory Owners Forum

The following archive was created by hippie-mail 7.98617-22 on Sat Apr 10 1999 - 01:15:19