RE: Comments on CRACK (shared secrets)

No, you're right. I missed that somehow.

So actually there's no barrier against using this legacy authentication
scheme if you don't mind using AM, but if you want identity protection then
the only limitation is the SKEYID_e derivation algorithm.

On Thu, 28 Oct 1999, Andrew Krywaniuk wrote: 
> Here we have a completely secure example of a legacy authentication system

> which is secured using shared secrets. Of course the question arises 
> regarding how one should handle dynamic IP assignment. As I discussed
> both AM and MM don't really support using id types other than IPs with 
> shared secrets. 
Why do you say that? In AM, the ID is sent before any encryption happens,
so I can pick a shared secret based on the ID contents, be they ID_FQDN, 
ID_USER_FDQN, ID_IPV4, whatever... 
Wondering if I'm missing something, 
