课程: ISC2 Certified Information Systems Security Professional (CISSP) (2024) Cert Prep

免费学习该课程!

今天就开通帐号,24,600 门业界名师课程任您挑!

Password authentication protocols

Password authentication protocols

- [Instructor] Many access control systems rely upon password-based mechanisms to implement something you know, security. One of the most common applications of password security is to secure virtual private networks and other remote access technologies. Let's take a look at the protocols used to implement remote access password security. The Password Authentication Protocol, or PAP, is the earliest of these protocols. In this protocol, the client wishes to authenticate to a server, and both the client and the server know the user's password. The client simply transmits the username and password to the server, and the server validates the password. That's about as simple as it gets and successfully implements password authentication. But there's a major flaw to this approach. PAP does not use any encryption to protect the communication. Anyone able to eavesdrop on the connection can read the username and password from the network. For this reason, PAP should never be used, except…

内容