Beefy Boxes and Bandwidth Generously Provided by pair Networks
Syntactic Confectionery Delight

Re: Re: (Ovid) (2): Too Convenient Security?

by jreades (Friar)
on Jan 08, 2002 at 04:14 UTC ( #137003=note: print w/replies, xml ) Need Help??

in reply to Re: (Ovid) (2): Too Convenient Security?
in thread Too Convenient Security?

It's not that keeping the salt seperate would be so hard, it's that it wouldn't buy you anything. A modern OS will protect the password hashes+salts together, so that even if a cracker gets the list of users, they've got nothing to work on.

There might, however, be an exception to this principle -- two machines connected by a physical link or over a network using one of the secure protocols (ssh/https). In this scenario, you could, for instance, hash the password on one machine, hash the salt on the other, and then hash some form of the two together to gain access to the target machine... kind of a bizarre setup, but it just might work.

In this situation, you acutally could keep your salts in one place and your keys in another. The two machines would have to be able to talk to each other in a trusted way (no man-in-the-middle attacks), but you're essentially requiring the cracker to gain access to two machines in order to understand what's going on.

Of course, on the flip side you introduce new points of failure... especially over an insecure network.

Just a thought, and I profess only the most basic knowledge of cryptography.

  • Comment on Re: Re: (Ovid) (2): Too Convenient Security?

Log In?

What's my password?
Create A New User
Domain Nodelet?
Node Status?
node history
Node Type: note [id://137003]
and the web crawler heard nothing...

How do I use this? | Other CB clients
Other Users?
Others musing on the Monastery: (4)
As of 2023-02-01 12:13 GMT
Find Nodes?
    Voting Booth?

    No recent polls found