Title: Is kerberos broken?

My understanding of kerberos, is that you access the central security server (kerberos) by your user name, and it then sends you a ticket encrypted by your password.

Of course with modern computers, any password a human is capable of remembering, or even typing in correctly from a yellow post-it note, can be brute forced on a desktop, so a packet sniffer will rapidly discover the password of each user.

Thus it appears to me that kerberos has been rendered obsolete by Moore's law.

Reply via email to