Rick Smith at Secure Computing <[EMAIL PROTECTED]> writes:
> Now, just how do we intend to address such concerns in our memory-based 
> authentication systems? Our whole technology for using memorized secrets is 
> built on the belief that people will remember and recite these secrets 
> perfectly. Some applications could take more of a 'biometric pattern 
> matching' strategy that measures the distance between the actual passphrase 
> and a stored pattern. But this won't provide us with a secret we can use in 
> crypto applications like PGP.

There has been some work on addressing this issue.  See

http://www.counterpane.com/personal-entropy.html
-- 
  __
\/ o\ [EMAIL PROTECTED]
/\__/ http://www.cluefactory.org.uk/paul/

Reply via email to