4 ms·
With such a large user database, why isn't tar pitting db requests the norm?... or at the very least, instituting something as simple as a flag on dummy record
by throwwit 12y ago
With such a large user database, why isn't tar pitting db requests the norm?... or at the very least, instituting something as simple as a flag on dummy record requests?
- thrownaway2424 12y agoA flag on dummy record requests? You mean have records that don't correspond to real accounts, and audit access to them? How would you censor them from legitimate full traversals of the user database? How would you tar-pit attackers without throttling such legitimate processes?
- dchest 12y agoThere's an interesting project called "Honeywords" (one of the authors is Ron Rivest) http://people.csail.mit.edu/rivest/honeywords/ http://people.csail.mit.edu/rivest/honeywords/ Link to paper: http://people.csail.mit.edu/rivest/honeywords/paper.pdf http://people.csail.mit.edu/rivest/honeywords/paper.pdf (see also recent paper "Some Remarks on Honeyword Based Password-Cracking Detection" https://eprint.iacr.org/2014/323.pdf https://eprint.iacr.org/2014/323.pdf)