Re: Split passwords

From: Ingbert Grimpe (ingbert_at_sendnospam.to.me)
Date: 06/29/05


Date: Wed, 29 Jun 2005 19:16:44 +0200

aruck wrote:
> An idea that I've been batting around...

You have a (probably) weak user password and a larger 'secret' random
password. Since the random part needs to be protected anyway, why not
simply generate the complete key at random and let the user simply
assign a name/title to it? The only reason for user passwords is the
possibility of hiding the complete password in the user's brain. Does
not really make sense to add some 'written down' secret to it (IMHO).