From owner-freebsd-security@FreeBSD.ORG Tue Mar 15 10:35:11 2011 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id F34DB1065679 for ; Tue, 15 Mar 2011 10:35:11 +0000 (UTC) (envelope-from des@des.no) Received: from smtp.des.no (smtp.des.no [194.63.250.102]) by mx1.freebsd.org (Postfix) with ESMTP id E602A8FC16 for ; Tue, 15 Mar 2011 10:35:07 +0000 (UTC) Received: from ds4.des.no (des.no [84.49.246.2]) by smtp.des.no (Postfix) with ESMTP id CD30F1FFC34; Tue, 15 Mar 2011 10:35:06 +0000 (UTC) Received: by ds4.des.no (Postfix, from userid 1001) id A561E844B0; Tue, 15 Mar 2011 11:35:06 +0100 (CET) From: =?utf-8?Q?Dag-Erling_Sm=C3=B8rgrav?= To: RW References: <1299682310.17149.24.camel@w500.local> <1299769253.20266.23.camel@w500.local> <2E5C0CE8-4F70-4A4D-A91D-3274FD394C80@elvandar.org> <1299784361.18199.4.camel@w500.local> <20110310202653.GG9421@shame.svkt.org> <1299798547.20831.59.camel@w500.local> <20110313204054.GA5392@server.vk2pj.dyndns.org> <1300050377.5900.12.camel@w500.local> <20110313220552.5b79de13@gumby.homeunix.com> Date: Tue, 15 Mar 2011 11:35:06 +0100 In-Reply-To: <20110313220552.5b79de13@gumby.homeunix.com> (RW's message of "Sun, 13 Mar 2011 22:05:52 +0000") Message-ID: <86ipvky8md.fsf@ds4.des.no> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/23.2 (berkeley-unix) MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Cc: freebsd-security@freebsd.org Subject: Re: It's not possible to allow non-OPIE logins only from trusted networks X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 15 Mar 2011 10:35:12 -0000 RW writes: > IIRC there is/was a weakness in FreeBSD's OPIE implementation in that > it's susceptible to rainbow table attacks - I think part of the hash > is discarded. Can you provide more details? AFAIK, OPIE was written to be 100% compatible with S/Key, so any weakness in OPIE is a design flaw in S/Key which cannot be corrected. DES --=20 Dag-Erling Sm=C3=B8rgrav - des@des.no