HP Dc5700 HP ProtectTools Security Manager Guide - Page 16

Dictionary Attack Behavior with Power-On Authentication, Dictionary Attack Defense, Welcome

Page 16 highlights

Dictionary Attack Behavior with Power-On Authentication A dictionary attack is a method used to break into security systems by systematically testing all possible passwords to break a security system. A dictionary attack against Embedded Security could try to detect the Owner password, the Basic User password, or password-protected keys. Embedded Security offers an enhanced Dictionary Attack Defense. Dictionary Attack Defense Embedded Security's defense against dictionary password attack is to detect failed authentication attempts and temporarily disable the TPM when a certain failure threshold is reached. Once the failure threshold is reached, not only is the TPM disabled and a reboot required, but ever increasing lockout timeouts are enforced. During the timeout, entering the correct password will be ignored. Entering the wrong password will double the last timeout. Additional documentation on this process is located in the Embedded Security Help. Click Welcome to the HP Embedded Security for ProtectTools Solution > Advanced Embedded Security Operation > Dictionary Attack Defense. NOTE Normally, a user receives warnings that their password is incorrect. The warnings state how many more attempts the user gets prior to the TPM disabling itself. The Power-On Authentication process takes place in the ROM before the OS is loaded. Dictionary Attack Defense is operational, but the only warning the user will get is the X key symbol. 10 Chapter 1 Introduction ENWW

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48

Dictionary Attack Behavior with Power-On Authentication
A dictionary attack is a method used to break into security systems by systematically testing all possible
passwords to break a security system. A dictionary attack against Embedded Security could try to detect
the Owner password, the Basic User password, or password-protected keys. Embedded Security offers
an enhanced Dictionary Attack Defense.
Dictionary Attack Defense
Embedded Security’s defense against dictionary password attack is to detect failed authentication
attempts and temporarily disable the TPM when a certain failure threshold is reached. Once the failure
threshold is reached, not only is the TPM disabled and a reboot required, but ever increasing lockout
timeouts are enforced. During the timeout, entering the correct password will be ignored. Entering the
wrong password will double the last timeout.
Additional documentation on this process is located in the Embedded Security Help. Click
Welcome to
the HP Embedded Security for ProtectTools Solution
>
Advanced Embedded Security
Operation
>
Dictionary Attack Defense
.
NOTE
Normally, a user receives warnings that their password is incorrect. The warnings state
how many more attempts the user gets prior to the TPM disabling itself.
The Power-On Authentication process takes place in the ROM before the OS is loaded. Dictionary
Attack Defense is operational, but the only warning the user will get is the X key symbol.
10
Chapter 1
Introduction
ENWW