4 ms·
It's a good idea but avoiding collisions with genuine passwords could be tricky particularly for sites with millions of accounts. If the honeywords are very lon
by ss64 13y ago
It's a good idea but avoiding collisions with genuine passwords could be tricky particularly for sites with millions of accounts.
If the honeywords are very long and random, then they probably won't collide but they will be obviously different from a typical users password.
If you add a standard prefix or an extended character that is disallowed for real user passwords, that avoids collisions but also makes the honeywords easy to filter out.
If you generate the honeywords by swapping around the characters in a real password then theres a danger that a user could set off a false alarm with a simple typo in their password.
- takluyver 13y agoThe generator shown will produce random variants on passwords it's fed, so it shouldn't be easy to filter them out. False alarms should be easy to avoid - stick 100 honeypot passwords in the database, and set off the alarm if say, 10 of them are tried within a week. Obviously those numbers can be tweaked according to password strength, number of users, etc. Edit: It's actually talking about a specific set of honeywords for each user. So when the password is chosen, you generate a set of honeywords that are quite different from that password, and can't be reached by mistake.
- anywhichway 13y agoThe way the system is proposed is that each user would have an exclusive list of honey words for just them. Each user would have, say 10 possible passwords. The password system would recognize all of them as correct for that user, but only 1 of the 10 wouldn't also trip an alarm in a secondary system. The honey word generating system avoid collisions with that specific user's password for generating that user's honey words, which is all that is needed.
- anywhichway 13y agoThe way the system is proposed is that each user would have an exclusive list of honey words for just them. Each user would have, say 10 possible passwords. The password system would recognize all of them as correct for that user, but only 1 of the 10 wouldn't also trip an alarm in a secondary system. The honey word generating system avoid collisions with that specific user's password for generating that user's honey words, which is all that is needed.
- anywhichway 13y agoThe way the system is proposed is that each user would have an exclusive list of honey words for just them. Each user would have, say 10 possible passwords. The password system would recognize all of them as correct for that user, but only 1 of the 10 wouldn't also trip an alarm in a secondary system. The honey word generating system avoid collisions with that specific user's password for generating that user's honey words, which is all that is needed.
- anywhichway 13y agoThe way the system is proposed is that each user would have an exclusive list of honey words for just them. Each user would have, say 10 possible passwords. The password system would recognize all of them as correct for that user, but only 1 of the 10 wouldn't also trip an alarm in a secondary system. The honey word generating system avoid collisions with that specific user's password for generating that user's honey words, which is all that is needed.