3 ms·
Re single positions, my bank requires a password (which one hopes is appropriately hashed and so forth) plus a challenge to supply requested offsets into a sec
by rrrpfb11 3y ago
Re single positions, my bank requires a password (which one hopes is appropriately hashed and so forth) plus a challenge to supply requested offsets into a secret phrase. That mitigates I suppose against over the shoulder attack. And they have fewer requirements of the phrase so maybe it’s less likely to be written down?
I’m curious whether there’s a technical means to allow the challenge by offset without storing the phrase plain text. I’m challenged for four positions - in theory it could store hashes of all possible four offsets, but is there a better way?
- GoblinSlayer 3y agoSplit the secret into characters then compute verifier bytes for each character: verifier[i]=hash(pepper,salt,i,secret[i])[0]