PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
January 1, 2005209 citations

A convenient method for securely managing passwords

View Full Paper
JHJ. Alex HaldermanBWBrent WatersEFEdward W. Felten

Key Points

Key points are not available for this paper at this time.

Abstract

Computer users are asked to generate, keep secret, and recall an increasing number of passwords for uses including host accounts, email servers, e-commerce sites, and online financial services. Unfortunately, the password entropy that users can comfortably memorize seems insufficient to store unique, secure passwords for all these accounts, and it is likely to remain constant as the number of passwords (and the adversary's computational power) increases into the future. In this paper, we propose a technique that uses a strengthened cryptographic hash function to compute secure passwords for arbitrarily many accounts while requiring the user to memorize only a single short password. This mechanism functions entirely on the client; no server-side changes are needed. Unlike previous approaches, our design is both highly resistant to brute force attacks and nearly stateless, allowing users to retrieve their passwords from any location so long as they can execute our program and remember a short secret. This combination of security and convenience will, we believe, entice users to adopt our scheme. We discuss the construction of our algorithm in detail, compare its strengths and weaknesses to those of related approaches, and present Password Multiplier, an implementation in the form of an extension to the Mozilla Firefox web browser.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Halderman et al. (2005) studied this question.

synapsesocial.com/papers/6a0da7e088250cfcc2a50da6https://doi.org/10.1145/1060745.1060815
Ask AI
Helpful
Bookmark
Share
View Full Paper