Boston Linux & Unix (BLU) Home | Calendar | Mail Lists | List Archives | Desktop SIG | Hardware Hacking SIG
Wiki | Flickr | PicasaWeb | Video | Maps & Directions | Installfests | Keysignings
Linux Cafe | Meeting Notes | Blog | Linux Links | Bling | About BLU

BLU Discuss list archive


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Discuss] KeePassX



Bill Horne wrote:
> Schneier once put a picture of a SecureID token on his website: it was
> on a live-camera feed from an undisclosed location. He said that the
> funny thing was that, as long as the device's serial number wasn't
> disclosed, the thing was still secure.

Well, yeah. The codes the token displays aren't the key to the lock. The 
token's serial number is the key. It's also the seed to the PRNG that 
generates the codes.

Software tokens like the Google Authenticator app and the Blizzard 
Authenticator app work the same way.

-- 
Rich P.



BLU is a member of BostonUserGroups
BLU is a member of BostonUserGroups
We also thank MIT for the use of their facilities.

Valid HTML 4.01! Valid CSS!



Boston Linux & Unix / webmaster@blu.org