How to hide passwords
- From: "Woody Brison" <woody_brison@xxxxxxxxx>
- Date: 27 Feb 2006 11:46:55 -0800
There are men who must remember many passwords, and as age
advances, it becomes increasingly difficult and risky to try
to remember from five to maybe several dozen passwords. Now,
people can more easily remember geometrical patterns. Suppose
a pattern of characters is placed on a website somewhere or
printed out and tacked up on the wall, or stored on a PDA or
an ipod, so it can be read anytime (by the attacker, too,
doubtless)... and this pattern consists of an arrangement of
characters like, say
| ewia cdxd swza jvhf |
| yn8j q$wp oilk oipo |
| hxls junq 1wer jh4$ |
| 8tjd oick |
| gm3k ovg0 thvd hkdi |
| jhgf d@sa zuka sve7 #zo3 er@w |
| g*zx eiph swed rfcx cvb5 n1o2 |
| 6^df gtrf gev6 bvmq |
| poxe icos |
| wwia b!nv gygh ewia |
| nn8j j^4n 7wdu yn8j |
| xxls uiw8 kopl hxls |
| |
| @oqw ewia 7izb >h pvej |
| yn8j y4$u io%p d9fg hxls |
| keif jvhf |
| @oqw pmkl oipo qwer |
| ty4j f89c jh4$ i9o3 |
Suppose the person needing to chose a password takes for
instance the six corner characters going clockwise and then
the next four inward, yielding "efs3tynpeo". He could also
have other passwords hidden in this same pattern, such as at
the bottom right, "i9o3rewq", and there could be any number
of others in use at the same time. When it's required to
choose a new password, he simply picks out a new pattern
hopping around the array somehow.
How secure would this be?
Assume the attacker can read this array, and knows the
general method being used, too. He does not know what
geometrical patterns have been picked.
It seems to me that if he takes a brute force approach then
he's basically searching the whole alphanumeric space.
Perhaps there's a weakness in that the human mind would tend
toward certain symmetries or something? Still, the search
space would have to be huge, right?
Wood
.
- Follow-Ups:
- Re: How to hide passwords
- From: Mikhael Felker
- Re: How to hide passwords
- From: Woody Brison
- Re: How to hide passwords
- Prev by Date: Re: FlexiProvider: an open source cryptography provider for the JCA/JCE
- Next by Date: Re: libtomcrypt.org dns hijack
- Previous by thread: When do HMAC use less CPU power than Hash function in a MAC
- Next by thread: Re: How to hide passwords
- Index(es):
Relevant Pages
|
|