24 ms·
This looks very interesting on a technical level, but I'm not sure it really solves the problem of people using bad passwords, and it has some serious usability
by samdk 15y ago
This looks very interesting on a technical level, but I'm not sure it really solves the problem of people using bad passwords, and it has some serious usability problems.
As far as I can see, this method is likely good enough to help in cases where people choose short but otherwise good passwords, but not in cases where people just plain choose bad passwords. Computers are getting increasingly good at solving captchas, and you can get human-solved captchas done very cheaply [1]. When the most common passwords are in use by more than 1% of your users [2], just trying those and using a combination of heuristics and cheap human labor still gets you a pretty large number of compromised accounts.
Even in the cases where it works, though, it comes at the cost of a really awful usability problem: users need to read and retype a long random string from the captcha every time they log in, and people hate catpchas. That alone is likely to prevent this being used in any application that depends on getting traction with a large number of users. Slow hashing algorithms like bcrypt or scrypt do a good enough job of protecting short-but-good passwords for most purposes.
The only cases where I can see this being actually used are in applications with very high security requirements, where people have no choice about whether to use the application, and where there are mechanisms in place preventing very bad passwords from being used. However, high-security applications are likely to have much lower traffic, which means that setting a very high bcrypt or scrypt work factor will accomplish much the same thing. That might take a bit more computational power for the application server, but if the traffic isn't very high, that cost isn't likely to be an insurmountable obstacle, and then you get to avoid all of the usability headaches that complicated captchas come with.
[1] http://motherjones.com/kevin-drum/2010/08/price-captcha http://motherjones.com/kevin-drum/2010/08/price-captcha
[2] http://blogs.wsj.com/digits/2010/12/13/the-top-50-gawker-media-passwords/ http://blogs.wsj.com/digits/2010/12/13/the-top-50-gawker-med...