[lug] onetime login / rotating passwords - avoiding keyboard sniffers

John Hernandez John.Hernandez at noaa.gov
Wed Apr 23 17:28:51 MDT 2003


On Wednesday 23 April 2003 05:17 pm, Eric Peers wrote:
> Is s-key the login method I'm looking for?

Yes, S/Key or OPIE would work for OTP schemes.  In your case, you should not 
generate new passwords on the untrusted (potentially keystroke-monitored) 
machine -- you'll need to carry a password list for it to be secure.

-- 

 |  John Hernandez - NOAA Boulder NOC - 303-497-6392
 |  Mailstop R/OM62. 325 Broadway, Boulder, CO 80305
 |  PGP Public Key ID: 586A7E23



More information about the LUG mailing list