4 ms·
Another alternative is a PAKE. You'll never have a password sent over the wire. For some reason PAKE schemes aren't that commonly used despite having a solid g
by DarthGhandi 6y ago
Another alternative is a PAKE. You'll never have a password sent over the wire.
For some reason PAKE schemes aren't that commonly used despite having a solid grounding. Matthew Green has a few good articles on them.
- thaumasiotes 6y ago> You'll never have a password sent over the wire. As far as I can see, you do need to send the full password over the wire once when you set its value. But the server doesn't need to remember it. > For some reason PAKE schemes aren't that commonly used despite having a solid grounding. It doesn't look like something you can implement unilaterally. How's browser support? (Interestingly, I guess you could implement it unilaterally between your server and client-side javascript...)
- DarthGhandi 6y agoI'm not sure if this is coming down to semantics here but the password is essentially encrypted to everyone except the client, I wouldn't call that sending a password over the wire, you may disagree. This is a unique value for every login attempt. Probably the most common scheme is SRP. https://en.wikipedia.org/wiki/Secure_Remote_Password_protocol https://en.wikipedia.org/wiki/Secure_Remote_Password_protoco...
- deleted 6y ago[deleted]
- thaumasiotes 6y agoNo, you're right; I wasn't talking about login attempts. I was thinking that PAKE is a way to establish that two parties have common knowledge of a shared secret, and so the password needs to be shared once in order to become a shared secret. But the protocol you link doesn't transfer the password even when setting it. (Weirdly, the article explicitly notes that s, the salt Carol applies to her own password, is shared with the server and sent over the wire during login. But the salt never appears to be used by the server in any capacity. And the instruction "Carol must not share x with anybody, and must safely erase it at this step, because it is equivalent to the plaintext password p" doesn't make a lot of sense; presumably Carol isn't going to erase her knowledge of her password -- what does erasing x add? [The only thing making the password equivalent to x is that the server transmits the value s during the login attempt. If it didn't do that, x would still be useful, but the "password" would be worthless, unless of course s was stored alongside the password...])