Earlier quoted context omitted.
Hopefully stress means that you won't be able to do it properly anyway, which means coercion is useless. The real problem is the device stores the password, so the real defence is the tamperproof-ness of the device, not whether you can be tricked or coerced into outputting the sequence.
Yeah, the research paper notes that they need to implement 'coercion detection'. From page 12: "Since our aim is to prevent users from effectively transmitting the ability to authenticate to others, there remains an attack where an adversary coerces a user to authenticate while they are under ad- versary control. It is possible to reduce the effective- ness of this technique if the system could detect if the user is…
Unbreakable crypto: Store a 30-character password in your subconscious memory
31–40 of 91 posts
Re: Unbreakable crypto: Store a 30-character password in your subconscious memory
#32Does not compute. If there is a mechanism by which you can authenticate, you can be coerced into authenticating through that method.
The paper covers this of course:
>Coercion detection. Since our aim is to prevent users from effectively transmitting the ability to authenticate to others, there remains an attack where an adversary coerces a user to authenticate while they are under adversary control. It is possible to reduce the effectiveness of this technique if the system could detect if the user is under duress.
I take issue with the the article suggesting it's completely resistant to coercion. A system that detects duress... interesting I guess but seems like a stretch.
>This equates to around 38 bits of entropy, which is thousands/millions of times more secure than your average, memorable password.
Really? Playing around with KeePass briefly, it seems this is comparable to a 6 character password that includes upper, lower, numeric, and special characters. I wouldn't consider that very strong. Besides the fact that it appears you're not entering the password exactly, but only (if I'm understanding correctly) "good enough".
Re: Unbreakable crypto: Store a 30-character password in your subconscious memory
#33This is basically the same method I use for laptop hard disk encryption. I don't remember the password, but I typed it so many times my fingers remember exactly the pattern to type. Kind of like playing a piano. Several times i've been drinking and am unable to remember how to log into my machine, because I can't replicate the pattern and don't remember the password. After 15 minutes of concentration it comes back.
A few weeks ago it was late, I'd just come from the gym and not eaten anything and I couldn't figure out why my PIN wasn't working. Turned out I was trying to use a code that I stopped using a couple years ago.
Re: Unbreakable crypto: Store a 30-character password in your subconscious memory
#34Also, the paper assumes physical presence of a live human at some terminal for authentication. At the point that you can make assumptions about who is operating your authentication system, biometrics seem to be a far faster and more reliable authentication system. Both those limitations,however, could change with further research.
Re: Unbreakable crypto: Store a 30-character password in your subconscious memory
#35Nitpick: This is not unbreakable crypto. This is more of a more secure key storage mechanism. Perhaps also a good defense against phishing attacks. And it's not unbreakable. For starters, this system absolutely requires that the passwords be stored in the clear.
Re: Unbreakable crypto: Store a 30-character password in your subconscious memory
#36> It also gives you deniability: If a judge or policeman orders you to hand over your password, you can plausibly say that you don’t actually know it The UK law requires that you make the encrypted data intelligible. Since you have encrypted data there's a pretty good chance you have the software to decrypt it. "They" don't want the password, they want the data. Failing to make the data intelligible (whether that's f…
> Mrs Ebastian's more likely Mr Sebastian ... or was that intentional?
(It is Mr Seb though. Today, anyway.)
Re: Unbreakable crypto: Store a 30-character password in your subconscious memory
#37Earlier quoted context omitted.
I'm not sure you've got 3-4 right, but it doesn't matter. Step 1 sinks the whole thing.
There's also the fact that your password will ALWAYS be shown as one of the sequences. Would-be hacker just tries 5 times and notes that THIS sequence keeps showing up, that must be the right one. Maybe there's a more obtuse use-case but this seems like more of a cool experiment on human memory than a practical cryptography tool.
Re: Unbreakable crypto: Store a 30-character password in your subconscious memory
#38> It also gives you deniability: If a judge or policeman orders you to hand over your password, you can plausibly say that you don’t actually know it The UK law requires that you make the encrypted data intelligible. Since you have encrypted data there's a pretty good chance you have the software to decrypt it. "They" don't want the password, they want the data. Failing to make the data intelligible (whether that's f…
I think two or three ads per page is pretty good. I have seen some tech sites with much more than that. (As you probably know, running a free site that makes money from ad revenue is pretty tough at the moment, and isn't getting any easier.)
Apologies if you find the stories lousy. I try my best to dig up interesting stuff. Obviously the quality of the reporting isn't as good as if a professional cryptographer/material scientist/engineer etc wrote it -- but... I do the best I can :)
Re: Unbreakable crypto: Store a 30-character password in your subconscious memory
#39This is basically the same method I use for laptop hard disk encryption. I don't remember the password, but I typed it so many times my fingers remember exactly the pattern to type. Kind of like playing a piano. Several times i've been drinking and am unable to remember how to log into my machine, because I can't replicate the pattern and don't remember the password. After 15 minutes of concentration it comes back.
Re: Unbreakable crypto: Store a 30-character password in your subconscious memory
#40For instance, this could prevent employees of a large corporations from writing down or sharing a password with a coworker, or even spelling out their password over the phone to a bogus "support engineer" -- although probably fingerprint/eye/face recognition systems are more practical and easy to implement than a "guitar hero" learning session. But then the OP method has an advantage over those: you can change your implicit-learned password easier than your face or fingerprint...