Outline for November 27, 2006
Reading
: §12.1–12.2.2
Greetings and felicitations!
Puzzle of the day
Office hours changed today to 4–5 PM
Basis: what you know/have/are, where you are
Passwords
Problem: common passwords
May be pass phrases: goal is to make search space as large as possible, distribution as uniform as possible
Other ways to force good password selection: random, pronounceable, computer-aided selection
Password Storage
In the clear; Multics story
Enciphered; key must be kept available
Hashed; show UNIX versions, including salt
Attacks
Exhaustive search: password is 1 to 8 chars, say 96 possibles; it's about 7×10
16
Inspired guessing: think of what people would like (see above)
Random guessing: can't defend against it; bad login messages aid it
Scavenging: passwords often typed where they might be recorded as login name, in other contexts, etc.
Ask the user: very common with some public access services
You can also obtain a PDF version of this.
Version of November 28, 2006 at 11:34 AM