assurance - Re: [Assurance] Counting Failed Logins Update
Subject: Assurance
List archive
- From: Benn Oshrin <>
- To:
- Subject: Re: [Assurance] Counting Failed Logins Update
- Date: Wed, 26 Jun 2013 08:12:32 -0600
- Authentication-results: sfpop-ironport04.merit.edu; dkim=permerror (no key for signature)
On 6/21/13 3:01 PM, Joe St Sauver wrote:
#The Counting Failed Logins working group met yesterday and had a fairly
#productive conversation.
I know that implicitly this work is motivated by 800-63-2's requirements
that limit failed authentication attempts to 100 or fewer per 30 day period,
On a technical note, it's motivated by version 1.2 of the InCommon IAPs, which refer to 800-63-1 for calculating entropy. We then refer back to 800-63 1.0.2 to determine how to apply the entropy calculation, since that language was removed from later drafts.
800-63-2 introduced that 100/30 day restriction, which is stricter than we generally need.
My concern, however, is that the details of the specified mechanisms don't
really make sense to me, as defined there.
We're not proposing to use them.
There's also no discussion of how the failed logins could be "reset" --
does this imply that a user could potentially be "done" using his or
her username and password (even with the RIGHT password), for up to a
*month* after hitting a hundred login failures on the 1st of the month?
In the strawman, the failed login count is reset on successful password change. The month window does not apply.
-Benn-
- [Assurance] Counting Failed Logins Update, Benn Oshrin, 06/21/2013
- <Possible follow-up(s)>
- Re: [Assurance] Counting Failed Logins Update, Joe St Sauver, 06/21/2013
- Re: [Assurance] Counting Failed Logins Update, Brendan Bellina, 06/25/2013
- Re: [Assurance] Counting Failed Logins Update, Cantor, Scott, 06/25/2013
- RE: [Assurance] Counting Failed Logins Update, Capehart,Jeffrey D, 06/25/2013
- Re: [Assurance] Counting Failed Logins Update, David Walker, 06/25/2013
- Re: [Assurance] Counting Failed Logins Update, Benn Oshrin, 06/26/2013
- Re: [Assurance] Counting Failed Logins Update, Brendan Bellina, 06/25/2013
- Re: [Assurance] Counting Failed Logins Update, Joe St Sauver, 06/25/2013
- Re: [Assurance] Counting Failed Logins Update, Joe St Sauver, 06/25/2013
- Re: [Assurance] Counting Failed Logins Update, Cantor, Scott, 06/25/2013
Archive powered by MHonArc 2.6.16.