• Encryption is not needed, but attacker can flood
  • Double encryption is redundant (eliminated in Kerberos 5)
  • Relies on synchronised and un-compromised clocks. If the host is compromised, clock can be manipulated for replay attacks.