Re: Randomly-generated challenge method ?

From: O.L. (nowhere_at_invalid.net)
Date: 10/20/05

  • Next message: tomstdenis_at_gmail.com: "Re: Cryptoanalysis challenge"
    Date: Thu, 20 Oct 2005 11:40:09 +0200
    
    

    Le 19/10/2005, Gregory G Rose a supposé :
    > I guess I'm misunderstanding what you're trying to
    > do here. See comments below.
    >
    > In article <mn.9b967d5a54f8c207.18740@invalid.net>,
    > O.L. <nowhere@invalid.net> wrote:
    >> I thought about a secure method of authentication based on a simple
    >> password (memorizable by a human).
    >> This method uses hazard to increase the authentication process
    >> duration, and so to prevent attackers from quickly break the encryption
    >> by brute force. The computation duration can be easily set by
    >> increasing or decreasing the challenge string length.
    >>
    >> 1) The user sends his password (ie: "azerty") to the server
    >
    > Isn't this the real problem? The user just sent
    > his cleartext password... any eavesdropper now
    > knows it.

    Oops ! I made a mistake ... when I wrote this message !
    The user sends his USERNAME, not his password.
    Then the server get this USERNAME, look in his DB to find the
    associated password ...

    -- 
    Olivier Ligny
    Créateur web free-lance / www.cyber-tamtam.net
    

  • Next message: tomstdenis_at_gmail.com: "Re: Cryptoanalysis challenge"

    Relevant Pages

    • Re: network access issue.
      ... server with the same username and password they use to log onto their ... Or you could use the less secure method of adding the guest account access ... Server. ... Is there a way that I can configure this so that it will not prompt for a ...
      (microsoft.public.windows.server.general)
    • Re: Verify NT password
      ... This should *never* need to be done outside the normal Windows ... authentication process. ... they enter the username used to log on to the domain. ... entered is correct (the SID for the user and the current SID are the same), ...
      (microsoft.public.vb.winapi)
    • Capture M$ username during NT Authentication
      ... and hope there may be someone out there that could aid with this. ... access to my pages and database access is working great but I would ... like to "capture" only the username during this authentication process ...
      (alt.php)
    • Re: network access issue.
      ... server with the same username and password they use to log onto their ... Or you could use the less secure method of adding the guest account access ... Server. ... Is there a way that I can configure this so that it will not prompt for a ...
      (microsoft.public.windows.server.general)