apparea-4----Page:3
1  2  3  4  5  6  7  8  9  10  11  12  13 

Dictionary attacks
How many guesses before the observer can crack the challenge?
1,000,000 ?
10,000,000?
Do you trust users to generate “good enough” passwords?
Client
Server
challenge
Response = name +
hash (challenge, password)
Observer
Dictionary
+
PPT Version