dc.contributor.author | Juels, Ari | |
dc.contributor.author | Rivest, Ronald L. | |
dc.date.accessioned | 2014-10-08T14:42:37Z | |
dc.date.available | 2014-10-08T14:42:37Z | |
dc.date.issued | 2013-11 | |
dc.identifier.isbn | 9781450324779 | |
dc.identifier.uri | http://hdl.handle.net/1721.1/90627 | |
dc.description.abstract | We propose a simple method for improving the security of hashed passwords: the maintenance of additional ``honeywords'' (false passwords) associated with each user's account. An adversary who steals a file of hashed passwords and inverts the hash function cannot tell if he has found the password or a honeyword. The attempted use of a honeyword for login sets off an alarm. An auxiliary server (the ``honeychecker'') can distinguish the user password from honeywords for the login routine, and will set off an alarm if a honeyword is submitted. | en_US |
dc.language.iso | en_US | |
dc.publisher | Association for Computing Machinery (ACM) | en_US |
dc.relation.isversionof | http://dx.doi.org/10.1145/2508859.2516671 | en_US |
dc.rights | Creative Commons Attribution-Noncommercial-Share Alike | en_US |
dc.rights.uri | http://creativecommons.org/licenses/by-nc-sa/4.0/ | en_US |
dc.source | MIT web domain | en_US |
dc.title | Honeywords: making password-cracking detectable | en_US |
dc.type | Article | en_US |
dc.identifier.citation | Ari Juels and Ronald L. Rivest. 2013. Honeywords: making password-cracking detectable. In Proceedings of the 2013 ACM SIGSAC conference on Computer & communications security (CCS '13). ACM, New York, NY, USA, 145-160. | en_US |
dc.contributor.department | Massachusetts Institute of Technology. Computer Science and Artificial Intelligence Laboratory | en_US |
dc.contributor.department | Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science | en_US |
dc.contributor.mitauthor | Rivest, Ronald L. | en_US |
dc.relation.journal | Proceedings of the 2013 ACM SIGSAC conference on Computer & communications security (CCS '13) | en_US |
dc.eprint.version | Original manuscript | en_US |
dc.type.uri | http://purl.org/eprint/type/ConferencePaper | en_US |
eprint.status | http://purl.org/eprint/status/NonPeerReviewed | en_US |
dspace.orderedauthors | Juels, Ari; Rivest, Ronald L. | en_US |
dc.identifier.orcid | https://orcid.org/0000-0002-7105-3690 | |
mit.license | OPEN_ACCESS_POLICY | en_US |
mit.metadata.status | Complete | |