|
|
Invisible schrieb:
> http://eprint.iacr.org/2005/434.pdf
>
> (OK, not a random paper but a crypto paper...)
I guess they're overestimating the entropy in the user's responses:
"The entropy of the total secret is the sum of the entropy of each choice"
What rubbish! This will greatly depend on the dictionary of choices
offered, and the user in question. A user /will/ exhibit some personal
bias in each choice, and this bias will prevail across all responses.
For instance, if the dictionary is mixed with words representing (a)
animals, (b) latin words, (c) pop stars, and (d) philosophers, some user
may have a strong preference for the animal names.
Some other user may prefer words in the center rather than the periphery.
"Over-the-shoulder-attacks" are also likely to be a problem with this
authentication scheme, but at least they're aware of this fact.
Post a reply to this message
|
|