4 ms·
You are right, and this is a personal failing. Experience suggests I'm unlikely to overcome it. For the record, I don't think any of you are embarassing retards
by thomasptacek 19y ago
You are right, and this is a personal failing. Experience suggests I'm unlikely to overcome it. For the record, I don't think any of you are embarassing retards. But after reading comments here and elsewhere --- "that's OK, I'm making my salt 256 bits!" --- I fear that some of the password systems you will devise will be embarassingly retarded.
As for the parent comment: I just really like that picture.
Regarding challenge-response alternatives to SRP: I don't think these work well on the web.
Reason 1: on almost anything unencumbered by the Thomas Wu patent, you're going to have to store cleartext passwords on the server, which is probably worse than forcing clients to send passwords over the wire.
Reason 2: challenge-response only works if you feed the login page and Javascript dependencies over SSL (otherwise, the same attacker who can sniff passwords can hijack and man-in-the-middle logins). But if you trust SSL to feed the login page, why not trust it with the actual passwords?