Lecture 6 - Authentication Flashcards

1
Q

What is Authentication

A

They are who they say they are & they are permitted to access

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

TOCTTOU

A

Time of check to time of use.
Repeated authentication.
At start, during a session.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is Passwords

A

Digital keys,

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Problems with passwords

A
People forget them
Can be guessed
Spoofing and Phishing
Keylogging
Compromised password files
Weak Passwords
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Password Policies

A

Certain length and type of char
no dictionary words
regularly change
no previously used passwords

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Storing Passwords

A

One-way hash functions
Cant be looked up by admin
Stored in shadow file, read protected.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Types of password attacks

A

Online - on login terminals (phishing)
Offline - When password hash is obtained (brute force)
Dictionary Attacks - uses of common words.
Pretexting - obtaining private details by offering some pretext as a reason for needing them.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Password Salting

A

Adding a random “salt” before hashing.
Assign random salt for each user
Prevent massive leaks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

2-Factor Authentication

A

Text codes to mobile
Google authenticator
USB Device
TOCTTOU

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Password Alternatives

A

Biometrics - trade off between false +/-. accuracy is improtant
Location - not reliable on its own.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly