Honeywords: making password-cracking detectable
Name
Rivest_Honeywords.pdf
Size
369.5 KB
Format
Adobe PDF
Checksum (MD5)
c0007ca4f9598eccdccc30cffaada40a
Author(s) •
Juels, Ari
Rivest, Ronald L.
Date Issued
November 2013
Journal
Proceedings of the 2013 ACM SIGSAC conference on Computer & communications security (CCS '13)
Publisher
Association for Computing Machinery (ACM)
Citation
Ari Juels and Ronald L. Rivest. 2013. Honeywords: making password-cracking detectable. In Proceedings of the 2013 ACM SIGSAC conference on Computer & communications security (CCS '13). ACM, New York, NY, USA, 145-160.
Version
Original manuscript
Abstract
We propose a simple method for improving the security of hashed passwords: the maintenance of additional ``honeywords'' (false passwords) associated with each user's account. An adversary who steals a file of hashed passwords and inverts the hash function cannot tell if he has found the password or a honeyword. The attempted use of a honeyword for login sets off an alarm. An auxiliary server (the ``honeychecker'') can distinguish the user password from honeywords for the login routine, and will set off an alarm if a honeyword is submitted.
MIT Department
Massachusetts Institute of Technology. Computer Science and Artificial Intelligence Laboratory
Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science
Terms of Use
Creative Commons Attribution-Noncommercial-Share Alike
Persistent DSpace Link
DOI of Published Version
https://doi.org/10.1145/2508859.2516671