3 ms·
This is such a simple, yet powerful idea. What an elegant way to add another layer of security to a system. It's very easy to generate long random passwords t
by yeison 13y ago
This is such a simple, yet powerful idea. What an elegant way to add another layer of security to a system. It's very easy to generate long random passwords that no user would create on their own. Then to populate the database with a large number of these phony passwords. There would be a small hit based on the amount of space the honeyword passwords occupy. However, the amount is manageable, and the benefits are well worth it.
- jrabone 13y agolong random passwords that no user would create on their own Really? You see the ones my IronKey comes up with... I have about 140 of them. IMO anyone using a password manager is pretty likely to be generating long, random passwords, or they're Not Doing It Right.
- deckar01 13y agoI am working on a replacement for password managers. Type a password, then [Ctrl] + double click the field to hash it. Even if the database is compromised, an attacker is unlikely to assume your plaintext password is a base64 hash. http://deckar01.github.io/SHA512JS/ http://deckar01.github.io/SHA512JS/
- deleted 13y ago[deleted]
- nickzoic 13y agoPersonally, I suspect the Right Way to do this is for W3C to standardize a special input field something like: <input type="passhash"/> which looks like a normal password entry field but automatically does some clever hashing on the client to create a per-site password. Of course, you can still get keylogged if you use a public computer or whatever.
- yeison 13y agoWell, the issue I'm alluding to here is the issue of avoiding collisions. Even the password generator will not create the same long random passwords precisely because they're random and long... So even with a password generator these are still long random passwords that no user would create on their own and therefore do not collide with the honeyword passwords. Also, the combination of password generator and honeyword is actually even more secure than either one; in a "Greater than the sum of its parts" kind of way.
- deleted 13y ago[deleted]
- wnissen 13y agoIn section 5 they talk about generating the passwords, but I think taking them from existing known password databases (excluding those that are within a typo of the real password) would make them more likely to get hits. It would also make them almost impossible to distinguish from the real user passwords, since they would in fact be real user passwords.