Re: Bug#170069: ITP: grunt -- Secure remote execution via UUCP or e-mail using GPG
On Fri, Nov 22, 2002 at 10:32:22AM +0100, Josselin Mouette wrote:
> That's why I suggest using either a challenge/response authentification
> (if the mail is lost, you have to ask for a new challenge and the
> previous mail won't be accepted if it is delayed), or one-time passwords
> (every time you use a OTP, all previous passwords are revoked).
Presumably you would have to send 1 E-Mail (challange), wait for
the response, and then send the next E-Mail.
The could remarkably slow the process down for slow batched based
E-Mail systems.
(it would appear to be a tradeoff of functionality/efficiency vs
security).
--
Brian May <bam@debian.org>
Reply to: