[77182] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: Private Key Generation from Passwords/phrases

daemon@ATHENA.MIT.EDU (Allen)
Wed Jan 24 16:40:42 2007

X-Original-To: cryptography@metzdowd.com
X-Original-To: cryptography@metzdowd.com
Date: Wed, 24 Jan 2007 12:44:19 -0800
From: Allen <netsecurity@sound-by-design.com>
To: cryptography@metzdowd.com
In-Reply-To: <45B62BE9.7040807@masktech.de>



Matthias Bruestle wrote:

[snip]

> Regarding passphrase entropy: Getting entropy into a
> rememberable passphrase is a related, but completely different
> problem.

Here might be a screwy way of increasing the entropy of a 
passphrase while still allowing it to be readable/memorization.

At Cambridge a number of years ago they were doing readability
studies and out of it came the following funny quote:

> I cdnuolt  blveiee taht I cluod aulaclty uesdnatnrd waht I was
> rdenaig. The phonemneal  pweor of the hmuan mnid !
> 
> Aodccrnig to rserceah at Cmabrigde Uinervtisy,  it dnsoe't
> mttaer in waht oredr the ltteers in a wrod are, the olny
> iprmoatnt tihng is taht the frist and lsat ltteer be in the
> rghit pclae. The  rset can be a taotl mses and you can sitll
> raed it wouthit a porbelm. Tihs is bcuseae the hmuan mnid deos
> not raed ervey lteter by istlef, but the wrod  as a wlohe.
> 
> Azmanig huh? Yaeh and I awlyas tghuoht slpeling was ipmrtnoat.

Well, it sure messes with any dictionary based attack. :)

Best,

Allen



---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com

home help back first fref pref prev next nref lref last post