LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 01-25-2008, 03:39 PM   #1
MindOfMercury
LQ Newbie
 
Registered: Dec 2007
Distribution: Debian 4.0r2 x86_64
Posts: 22

Rep: Reputation: 15
One-Time Passwords


I know how to configure and use OPIE for one-time password authentication. I just can't seem to find a usable OTP password generator for other devices, such as mobiles and BlackBerrys. Does anyone have any advice for me? Specifically, for a BlackBerry 8320.
 
Old 01-27-2008, 01:08 AM   #2
jantman
Member
 
Registered: Nov 2005
Location: New Jersey, USA
Distribution: SuSE
Posts: 492

Rep: Reputation: 31
I know there *are* generator apps for mobile devices (I know there's one for Palm) but I always got the impression that Blackberry software was rather limited. If the OPIE homepage doesn't have anything, you might be out of luck. Have you tried their mailing list?

I remember looking into OPIE a while back and feeling that it was quite limited in terms of support for other devices.

I don't know what developing for the BB is like, but you may have to consider porting something.

**Note: one other option is if you have some way of encrypting memos or text files on the BB, or you don't mind putting plaintext passwords on it, you could use the OPIE password generator program to generate a hundred or so passwords, then sync them to your BB as a memo. Of course, this ends up placing the password list on your device *and* the computer you sync it to, so you'll probably actually *lose* security.
 
Old 01-27-2008, 01:13 AM   #3
jantman
Member
 
Registered: Nov 2005
Location: New Jersey, USA
Distribution: SuSE
Posts: 492

Rep: Reputation: 31
As a PS - this reminds me of a thread on password schemes on the SAGE (www.sage.org) mailing list a while back. Rather than use OTPs, a number of people said that they use a password scheme - a root portion, a host-specific portion, and a changing portion. I.e. all passwords for a person might start with a random 4-character string, then have the first 4 letters of the hostname with some sort of translation (rotation through the alphabet, keys next to them on the keyboard, etc.) and then have a string of 4 characters or so that changes every (week|month|etc.).

Not the absolute strength of OTPs, but does a lot to prevent brute-force passwords, guesses, etc.
 
Old 01-27-2008, 01:29 AM   #4
MindOfMercury
LQ Newbie
 
Registered: Dec 2007
Distribution: Debian 4.0r2 x86_64
Posts: 22

Original Poster
Rep: Reputation: 15
Well, if OPIE isn't known for its support for other devices, what is? What ARE some good OTP implementations, anyway?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
updating samba passwords with system passwords paranoid times Linux - Software 3 10-03-2006 09:04 PM
Sync MySQL passwords with local account passwords? turbine216 Linux - Software 2 02-18-2005 03:15 AM
Completely uninstalling MySQL and its passwords passwords...how? I locked myself out! Baix Linux - Newbie 2 01-30-2005 04:10 PM
Is there a way to sync Samba passwords with linux user passwords MarleyGPN Linux - Networking 2 09-09-2003 10:59 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 06:09 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration