From: Ben Laurie <ben@algroup.co.uk>
To: David Jablon <dpj@world.std.com>
Message Hash: c6b65891c5ba3c2089806684acb639c1c31a9621c489cd87223787b66e1eb367
Message ID: <3608B833.DA9AC6FE@algroup.co.uk>
Reply To: <Pine.LNX.3.96.980921133001.20069A-100000@blackbox>
UTC Datetime: 1998-09-22 19:59:58 UTC
Raw Date: Wed, 23 Sep 1998 03:59:58 +0800
From: Ben Laurie <ben@algroup.co.uk>
Date: Wed, 23 Sep 1998 03:59:58 +0800
To: David Jablon <dpj@world.std.com>
Subject: Re: ArcotSign (was Re: Does security depend on hardware?)
In-Reply-To: <Pine.LNX.3.96.980921133001.20069A-100000@blackbox>
Message-ID: <3608B833.DA9AC6FE@algroup.co.uk>
MIME-Version: 1.0
Content-Type: text/plain
David Jablon wrote:
>
> Bruce Schneier wrote:
> >> The advantages are that offline password guessing is impossible.
>
> At 03:24 PM 9/22/98 +0100, Ben Laurie wrote:
> > The 'I' word always makes me nervous - do you really mean that, or do
> > you just mean "very difficult"?
>
> Why be nervous? It's not that hard to prevent off-line
> guessing of the PIN, given access to just the client's stored
> data. Here "impossible" means "as hard as breaking your
> favorite PK method".
Which is:
a) not impossible
b) not proven to be as difficult as we think it is (cf. quantum
computers, novel factorisation methods).
That's why.
Cheers,
Ben.
--
Ben Laurie |Phone: +44 (181) 735 0686| Apache Group member
Freelance Consultant |Fax: +44 (181) 735 0689|http://www.apache.org/
and Technical Director|Email: ben@algroup.co.uk |
A.L. Digital Ltd, |Apache-SSL author http://www.apache-ssl.org/
London, England. |"Apache: TDG" http://www.ora.com/catalog/apache/
WE'RE RECRUITING! http://www.aldigital.co.uk/
Return to September 1998
Return to ““Todd S. Glassey” <TSGman@earthlink.net>”