
|
Dictionary attacks How many guesses before the observer can crack the challenge? 1,000,000 ? 10,000,000? Do you trust users to generate “good enough” passwords? Client Server challenge Response = name + hash (challenge, password) Observer Dictionary + |