[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: ArcotSign (was Re: Does security depend on hardware?)




At 12:48 PM 9/22/98 +0100, Mok-Kong Shen wrote:
>Bruce Schneier wrote:
>> 
>> At 08:59 AM 9/22/98 +0100, Mok-Kong Shen wrote:
>
>> >A question : How does the legitimate user find his password?
>> >(Sorry for not having followed this thread from the beginning.)
>> 
>> He uses a remembered secret and some mathematical magic.
>
>Another naive question: Why is the remembered secret not sufficient
>(thus doing away with the magic)?

One of the significant improvements is that the scheme is immune to
offline password guessing attacks.

Bruce
**********************************************************************
Bruce Schneier, President, Counterpane Systems     Phone: 612-823-1098
101 E Minnehaha Parkway, Minneapolis, MN  55419      Fax: 612-823-1590
           Free crypto newsletter.  See:  http://www.counterpane.com