2 ms·
See my response below. I think they're trying to protect against potential weaknesses in the HMAC by requiring both sides to prove they know part of the PIN bef
by jacquesgt 15y ago
See my response below. I think they're trying to protect against potential weaknesses in the HMAC by requiring both sides to prove they know part of the PIN before sending information derived from the second part of the PIN. If a weakness is discovered in the HMAC, this scheme is supposed to allow either side to bail without leaking the whole PIN. This (supposedly) protects against someone spoofing the AP and selecting nonces that allow the PIN to be recovered.
- jaylevitt 15y agoI'm no crypto guy.. is there any conceivable situation in which their idea works? I mean, when is it actually more secure to say 'I'll let you know if you got the first half of the password right before you enter the second'?