Talking Identity Banner
  • http://www.cellartapes.com jaymz

    what if you had to type another minimum equal length expression in the same field when you enter your password.
    SAM would keep a history of the insignificant phrases you had used and refuse to let you use the same one within however many retries (this number could be modulated too to get around scripts)
    anyone grabbing the hash for your password would then, after trying to de-hash it, have to key in a phrase INCLUDING the bits that are your password but which is not a phrase you have used within the appropriate number of retries.
    maybe this phrase could be from a list of legal phrases or maybe this would just be defeating the point, but i reckon this would be pretty hard to crack if implemented (with any flaws ironed out!)
    jaymz

Follow me on Twitter Connect on LinkedIn My Presentations on Slideshare Profile of Nishant Kaushik, architect for Identity Management