Live data from Hacker News

Unbreakable crypto: Store a 30-character password in your subconscious memory

extremetech.com

31–40 of 91 posts

Re: Unbreakable crypto: Store a 30-character password in your subconscious memory

#31

Earlier quoted context omitted.

Hopefully stress means that you won't be able to do it properly anyway, which means coercion is useless. The real problem is the device stores the password, so the real defence is the tamperproof-ness of the device, not whether you can be tricked or coerced into outputting the sequence.

Yeah, the research paper notes that they need to implement 'coercion detection'. From page 12: "Since our aim is to prevent users from effectively transmitting the ability to authenticate to others, there remains an attack where an adversary coerces a user to authenticate while they are under ad- versary control. It is possible to reduce the effective- ness of this technique if the system could detect if the user is…

That's more of a bug than a feature when you're the one under duress.

Re: Unbreakable crypto: Store a 30-character password in your subconscious memory

#32
>The most important aspect of this work is that it (seemingly) establishes a new cryptographic primitive that completely removes the danger of rubber-hose cryptanalysis — i.e. obtaining passkeys via torture or coercion.

Does not compute. If there is a mechanism by which you can authenticate, you can be coerced into authenticating through that method.

The paper covers this of course:

>Coercion detection. Since our aim is to prevent users from effectively transmitting the ability to authenticate to others, there remains an attack where an adversary coerces a user to authenticate while they are under adversary control. It is possible to reduce the effectiveness of this technique if the system could detect if the user is under duress.

I take issue with the the article suggesting it's completely resistant to coercion. A system that detects duress... interesting I guess but seems like a stretch.

>This equates to around 38 bits of entropy, which is thousands/millions of times more secure than your average, memorable password.

Really? Playing around with KeePass briefly, it seems this is comparable to a 6 character password that includes upper, lower, numeric, and special characters. I wouldn't consider that very strong. Besides the fact that it appears you're not entering the password exactly, but only (if I'm understanding correctly) "good enough".

Re: Unbreakable crypto: Store a 30-character password in your subconscious memory

#33

This is basically the same method I use for laptop hard disk encryption. I don't remember the password, but I typed it so many times my fingers remember exactly the pattern to type. Kind of like playing a piano. Several times i've been drinking and am unable to remember how to log into my machine, because I can't replicate the pattern and don't remember the password. After 15 minutes of concentration it comes back.

Same here with my ATM PIN - I could probably make a guess and tell you what the numbers are but not the order without actually using an ATM pad.

A few weeks ago it was late, I'd just come from the gym and not eaten anything and I couldn't figure out why my PIN wasn't working. Turned out I was trying to use a code that I stopped using a couple years ago.

Re: Unbreakable crypto: Store a 30-character password in your subconscious memory

#34
This proves Authentication, not key storage that enables encryption/decryption. Per the paper, for authentication "a participant is presented with multiple SISL tasks where one of the tasks contains elements from the trained sequence." Hence the system must already know the secret password. If that system is your laptop, then the feds already have the key when they seize it and don't need to resort to rubber hose or its russian variant thermal-rectal cryptography.

Also, the paper assumes physical presence of a live human at some terminal for authentication. At the point that you can make assumptions about who is operating your authentication system, biometrics seem to be a far faster and more reliable authentication system. Both those limitations,however, could change with further research.

Re: Unbreakable crypto: Store a 30-character password in your subconscious memory

#35

Nitpick: This is not unbreakable crypto. This is more of a more secure key storage mechanism. Perhaps also a good defense against phishing attacks. And it's not unbreakable. For starters, this system absolutely requires that the passwords be stored in the clear.

It's not even that. YOu can't store a key with this divice because for the authentication game to work, the system has to have the password.

Re: Unbreakable crypto: Store a 30-character password in your subconscious memory

#36
post #29
post #20

> It also gives you deniability: If a judge or policeman orders you to hand over your password, you can plausibly say that you don’t actually know it The UK law requires that you make the encrypted data intelligible. Since you have encrypted data there's a pretty good chance you have the software to decrypt it. "They" don't want the password, they want the data. Failing to make the data intelligible (whether that's f…

> Mrs Ebastian's more likely Mr Sebastian ... or was that intentional?

I've always liked that about my name -- it has a certain amount of ambiguity.

(It is Mr Seb though. Today, anyway.)

Re: Unbreakable crypto: Store a 30-character password in your subconscious memory

#37
post #16

Earlier quoted context omitted.

I'm not sure you've got 3-4 right, but it doesn't matter. Step 1 sinks the whole thing.

There's also the fact that your password will ALWAYS be shown as one of the sequences. Would-be hacker just tries 5 times and notes that THIS sequence keeps showing up, that must be the right one. Maybe there's a more obtuse use-case but this seems like more of a cool experiment on human memory than a practical cryptography tool.

The paper is cheap and assumes they have a human attacker." Threat model: The proposed system is designed to be used as a local password mechanism requiring physical presence. That is, we consider authentication at the entrance to a secure location where a guard can ensure that a real person is taking the test without the aid of any electronics."

Re: Unbreakable crypto: Store a 30-character password in your subconscious memory

#38
post #20

> It also gives you deniability: If a judge or policeman orders you to hand over your password, you can plausibly say that you don’t actually know it The UK law requires that you make the encrypted data intelligible. Since you have encrypted data there's a pretty good chance you have the software to decrypt it. "They" don't want the password, they want the data. Failing to make the data intelligible (whether that's f…

Hey! No, no voting ring. But I do submit a lot of ET stories, that's for sure. I only try to submit stuff that I think is new/interesting/pertinent.

I think two or three ads per page is pretty good. I have seen some tech sites with much more than that. (As you probably know, running a free site that makes money from ad revenue is pretty tough at the moment, and isn't getting any easier.)

Apologies if you find the stories lousy. I try my best to dig up interesting stuff. Obviously the quality of the reporting isn't as good as if a professional cryptographer/material scientist/engineer etc wrote it -- but... I do the best I can :)

Re: Unbreakable crypto: Store a 30-character password in your subconscious memory

#39

This is basically the same method I use for laptop hard disk encryption. I don't remember the password, but I typed it so many times my fingers remember exactly the pattern to type. Kind of like playing a piano. Several times i've been drinking and am unable to remember how to log into my machine, because I can't replicate the pattern and don't remember the password. After 15 minutes of concentration it comes back.

No, it's not. Your laptop doesn't know your password and hence you can actually use it to generate and encryption key. This system needs the laptop to know your password.

Re: Unbreakable crypto: Store a 30-character password in your subconscious memory

#40
It may not be even close to unbreakable or torture-free as the author implies, but this encryption system (or similar approaches) could work to tighten some classic security flaws with passwords.

For instance, this could prevent employees of a large corporations from writing down or sharing a password with a coworker, or even spelling out their password over the phone to a bogus "support engineer" -- although probably fingerprint/eye/face recognition systems are more practical and easy to implement than a "guitar hero" learning session. But then the OP method has an advantage over those: you can change your implicit-learned password easier than your face or fingerprint...

Post reply on HN