Re: One-Time passwords for regular user accounts?



Carlos Moreno wrote:
John Thompson wrote:

I wonder if there is a way (a standard way, that is) to setup
one-time passwords for logging in to a Linux box (through SSH).

Search google on "opie" (one-time passwords in everything) and
"S/KEY"

Hmmm... The information seems a bit scarce. But still, from one of
the descriptions I read, it seems to be resistant to sniffing attacks,
and not to key loggers. But using SSH -- which I do -- makes me
already impervious to sniffing.

My concern is that I do not trust the keyboard where I'm typing my
password -- that's why I would like the server to have a list of
passwords ready to use, and as soon as one of them is used, it is
immediately removed from that list.

Am I getting it wrong?

Your concern is reasonable. I've used OPIE and its like in the past, for
off-site modem access. It works rather well, although you do need to keep
your printed list of one-time passwords with you.


.



Relevant Pages

  • Re: Secure FTPD (SSL)
    ... > is its great vulnerability to this day. ... If all you're concerned about is username/password sniffing, ... use one-time passwords, eg as implemented by OPIE? ...
    (comp.os.linux.security)
  • one-time passwords + webmail
    ... I am looking for Linux webmail program which supports one-time passwords ... for logging users. ... Or maybe you known PHP/Perl/CGI implementation of one-time passwords ... (i.e. opie)? ...
    (alt.computer.security)
  • webmail with one-time passwords support
    ... I am looking for Linux webmail program which supports one-time passwords ... for logging users. ... Or maybe you known PHP/Perl/CGI implementation of one-time passwords ... (i.e. opie)? ...
    (comp.os.linux.security)