Taming Kerberos - Computerphile

Taming Kerberos - Computerphile

Computerphile

5 лет назад

337,214 Просмотров

Ссылки и html тэги не поддерживаются


Комментарии:

@karimsalah6270
@karimsalah6270 - 23.02.2021 10:37

Why doesn't 'S' send the ticket granting ticket (first red message) to 't' itself instead of having 'a' send it to 't', similarly why doesn't 't' do that with 'b'?

Ответить
@LimitedWard
@LimitedWard - 01.03.2021 06:42

I had to implement Kerberos SSO support for the software that my company makes. I had no idea what all the settings did, but now it all makes sense.

Ответить
@jacobsteele2929
@jacobsteele2929 - 24.03.2021 18:01

Thank you so much Mike for these videos. I'm taking the security + right now and I would be lost without you. Your video's really help to solidify the text.

Ответить
- 16.04.2021 11:36

damned, you gave me an earworm i could really live without with... at least share it now: 'you're the keeper of the seven keys...' (to be imagined sung in a mans nasal head voice, over-layed by the tortured sounds of a mistreated guitar)

Ответить
@zeroedsalvo1657
@zeroedsalvo1657 - 20.04.2021 02:47

would be very nice if you put all those crypto/network videos into a playlist (sorry if you already did, just couldn't see it)

Ответить
@premkulkarni8012
@premkulkarni8012 - 23.04.2021 22:16

Mike you should be a Professor at MIT or Harvard ! You are the best !

Ответить
@ajbiffl4695
@ajbiffl4695 - 07.05.2021 09:03

would not the ticket-granting-tickets be a vulnerability? couldn't you take the known information encrypted with Kst and reverse-engineer it?

Ответить
@rooneye
@rooneye - 06.06.2021 01:14

I find encryption and cryptography tedious! Always hate it when I click a Computerphile video and it's about this subject 😟 There's a lot of them too.

Ответить
@mail2red
@mail2red - 15.06.2021 01:13

If "ticket server" sends Kbt{Kab, A, L}, and if A knows Kab, A and L-- A can get Kbt... right?

Ответить
@Ethernet480
@Ethernet480 - 20.06.2021 01:11

Mikes face in the thumbnail looks like he was just selected as tribute to fight actual Kerobos

Ответить
@andrewbuckley2627
@andrewbuckley2627 - 26.06.2021 03:24

How does this scheme handle NFS and SMB folder permissions? This looks pretty all or nothing. I expect the answer to be pretty involved.

Ответить
@tigerfish66
@tigerfish66 - 03.07.2021 18:25

brilliantly explained, thank you

Ответить
@skizz_
@skizz_ - 20.10.2021 21:18

Great video, so well put and easy to understand. I imagine this is how Jared would look if he had decided to go down the tech road and not biz dev.

Ответить
@ahmedaj2000
@ahmedaj2000 - 24.10.2021 16:31

Well explained thanks!

Ответить
@TheodoreWard
@TheodoreWard - 17.11.2021 20:25

U of N seems to have all the remaining fanfold paper.

Ответить
@mirceagheoace549
@mirceagheoace549 - 17.02.2022 12:33

Wonderful video!
I don't get how the long term key Kas is shared between the Kerberos server and computer A.

Ответить
@bbblader911
@bbblader911 - 13.04.2022 16:50

Wow

Ответить
@tsmith906
@tsmith906 - 04.05.2022 14:19

Yup.this is it. This is what im battling rn. Im currently waiting on cmos to clear cause i , after 2 weeks of research, have disabled it hiding from filechecker. Im giving my a full day draining of electrons jist in case theres a rootkit hidden somewhere idk about. I then just have to delete the couple of roots put on my win10 usb via ufi shell then repartition all my drives in windows installer and i should be rid of all the rootkits and the end of a 3 fkn week battle.
Wish me luck.
If anyone smarter than me reads this and knows im wrong PLZ respond. Im sick of this thing. I want my pc to myself again...

Ответить
@musteren99
@musteren99 - 24.07.2022 01:12

I just came across this in my reccomendations and i dont even wanna know what they do to computers in this channel.

Ответить
@BorjaTarraso
@BorjaTarraso - 19.08.2022 22:55

Your best video Mike.

Ответить
@YuKonSama
@YuKonSama - 07.09.2022 22:58

I love how every time he says "thats why kerberos is so clever" my security-focused brain says "no, thats why it is so easy to perform lateral movement with kerberos" :D

Ответить
@br3achbr3aker
@br3achbr3aker - 08.09.2022 17:40

A wonderful video on how Kerberos works!

Ответить
@lennonmclean
@lennonmclean - 16.09.2022 05:16

its crazy that all this happens whenever I log onto a computer at school

Ответить
@hyp3rvirus
@hyp3rvirus - 27.09.2022 00:11

you all told about Kerberos tens of years but no one said about Java modules epic fail in Linux/Windows environment that don't support MIT Kerberos cred cache algorithm. The cunning Oracle and Hadoop guru cry with foaming at the mouth to prove thousands of tickets per second are a security feature, not a awful bug. If you can't authenticate Java threads so buy millions of CPU cores. When they are poken to full RFC supported C and python, they cry those languages are trash.

Ответить
@mar7348
@mar7348 - 14.10.2022 23:38

When he started drawing a pentagram I thought he was going to summon kerberos

Ответить
@gplustree
@gplustree - 19.11.2022 00:39

first heard of Kerberos nearly 30 years ago but never used it, this is the first time I've actually gotten a high-level overview that was super easy to understand - thank you!

Ответить
@1mlister
@1mlister - 15.02.2023 21:51

I've always hated Active Directory. I feel I was unfair.

Ответить
@anonymousvevo8697
@anonymousvevo8697 - 14.03.2023 13:56

this guy is just amazing ! great explanation =)

Ответить
@theanhvu105
@theanhvu105 - 29.05.2023 20:45

Hi, I'm a bit confused about A B and T and have 2 questions. From the video, A received a short-term K_at from S in order to talk to T. Later, T send A a key K_ab encrypted in K_bt.

1. The K_bt was said to be long-term. It is supposed to be short-term, right?
2. Similar to K_at being granted from S, K_bt should have been granted from S at an earlier time when B authenticated with S, right? Or is it some other time?

Ответить
@younesrabhi5298
@younesrabhi5298 - 30.06.2023 20:11

wunderbar !!

Ответить
@Lucky8unny
@Lucky8unny - 17.08.2023 23:39

This is HANDS DOWN the BEST description of how Kerberos works. Straight forward, easy to understand. I feel like I truly understand it now, vs just having a general idea of what it does. Thanks so much for this great content!!❤❤❤

Ответить
@F3f33f
@F3f33f - 22.10.2023 12:08

Amazing teacher. Thank you!

Ответить
@wobblynl1742
@wobblynl1742 - 08.11.2023 18:56

why would you not directly get access from S to B? logging?

Ответить
@truthtriumphs5289
@truthtriumphs5289 - 09.11.2023 15:34

I am exception to the comments here. I did not understand after 10 minutes of the presentation.

Ответить
@marusak72
@marusak72 - 10.11.2023 10:27

When I saw him using a tabulation paper with those green lines I subscribed immediately 😊

Ответить
@bharatirajanvss4937
@bharatirajanvss4937 - 06.12.2023 11:21

Hands-down the best explanation I've seen about kerberos auth mechanism on the internet.

Ответить
@mandy1339
@mandy1339 - 09.12.2023 05:32

Excellent4!

Ответить
@DumblyDorr
@DumblyDorr - 06.01.2024 06:00

I once had to do some Service Principal configuration & administration with Kerberos in AD. That was >10 years ago. I still have nightmares.

Ответить
@mickolesmana5899
@mickolesmana5899 - 25.03.2024 17:23

basically, Cerberus is like when you ask your friend friend's number, but your friend's friend ask your friend if it is legit.

Ответить
@pasteyourinjectionstringhere
@pasteyourinjectionstringhere - 10.05.2024 06:32

Can you make a NTLM authentication video please :)

Ответить
@-iIIiiiiiIiiiiIIIiiIi-
@-iIIiiiiiIiiiiIIIiiIi- - 17.09.2024 00:28

Terrible explanation, but thanks for trying!

Ответить
@vivek73
@vivek73 - 20.10.2024 15:38

Outstanding video. I have seen so many videos on Kerberos but could not understand them. This video made it crystal clear to me. Thank you very much.

Ответить
@Karnaf142
@Karnaf142 - 30.12.2024 01:34

But the first time when I'm setting up the password I am using public key cryptography, right?

Ответить
@zeusent
@zeusent - 07.03.2025 20:00

How come B has a long term key with T? What if want to talk to a machine that’s just like me that has no long term key with T? How does it decode the message I pass to it from T? 🤔 Or that’s never the case?

Ответить
@NikitaNair
@NikitaNair - 27.03.2025 20:48

Best explanation of Kerberos on the internet!!

Ответить
@mehd-q1w
@mehd-q1w - 29.03.2025 21:34

how is kerberos going to block u from contacting another computer ??

Ответить
@wanfuse
@wanfuse - 16.05.2025 16:23

Funny thing about Active Directory thr database file isn’t even encrypted by default…not that everyone uses a safe that weighs 20000 kg to store its password in. Also it assumes you can trust anyone which is a flaw, like to see a an open source

OTP-based, quorum-voting, decentralized Kerberos alternative, devils in details though, but then again who says you can trust 2/3 votes, with AI that becomes a realistic attack, think game of diplomacy or similar social engineering on mass scales attacks

Ответить