From: Bruce Schneier <schneier@counterpane.com>
To: Mok-Kong Shen <cryptography@c2.net
Message Hash: 58d244ceb3d52c7b0d98c9feacae3db3df1d5831277d380415793c79855086db
Message ID: <199809220946.EAA09436@mixer.visi.com>
Reply To: <Pine.LNX.3.96.980921133001.20069A-100000@blackbox>
UTC Datetime: 1998-09-21 20:47:56 UTC
Raw Date: Tue, 22 Sep 1998 04:47:56 +0800
From: Bruce Schneier <schneier@counterpane.com>
Date: Tue, 22 Sep 1998 04:47:56 +0800
To: Mok-Kong Shen <cryptography@c2.net
Subject: Re: ArcotSign (was Re: Does security depend on hardware?)
In-Reply-To: <Pine.LNX.3.96.980921133001.20069A-100000@blackbox>
Message-ID: <199809220946.EAA09436@mixer.visi.com>
MIME-Version: 1.0
Content-Type: text/plain
At 08:59 AM 9/22/98 +0100, Mok-Kong Shen wrote:
>bram wrote:
>>
>> On Mon, 21 Sep 1998, Bruce Schneier wrote:
>>
>> > Here's the basic idea: Strew a million passwords on your hard drive, and
>> > make it impossible to verify which is the correct one offline. So,
someone
>> > who steals the password file off the client cannot run a cracking tool
>> > against the file.
>>
>> Is this really patentable? It sounds a *lot* like the original public-key
>> algorithm (the one involving lots of little 'puzzles')
>
>A question : How does the legitimate user find his password?
>(Sorry for not having followed this thread from the beginning.)
He uses a remembered secret and some mathematical magic.
Bruce
**********************************************************************
Bruce Schneier, President, Counterpane Systems Phone: 612-823-1098
101 E Minnehaha Parkway, Minneapolis, MN 55419 Fax: 612-823-1590
Free crypto newsletter. See: http://www.counterpane.com
Return to September 1998
Return to ““Todd S. Glassey” <TSGman@earthlink.net>”