ANN: Article on Password Authentication

From: QHenrick_Hellstr=F6m_=5BStreamSec=5D=22?= (henrick_at_REMOVEstreamsec.se)
Date: 07/10/04


Date: Sat, 10 Jul 2004 17:37:56 +0200

http://www.streamsec.se/files_download/password.pdf

"Password authentication is used in many systems for authenticating the
identity of one or both peers of a connection. Most schemes that are
used today are trivially insecure, even if they employ cryptographic
algorithms such as hash functions and encryption functions. This paper
will help you spot some common weaknesses and design more secure
password authentication schemes using symmetric cryptographic techniques."

Additionally, a demo for the SRP protocol (Secure Remote Password
Protocol) has been added to StreamSec Public Key Crypto Tools 3.0.

-- 
Henrick Hellström
www.streamsec.com