Re: Foibles of user security questions

2008-01-14 Thread ' =JeffH '
of possible relevance... Mike Just. Designing and Evaluating Challenge-Question Systems. IEEE SECURITY PRIVACY, 1540-7993/04, SEPTEMBER/OCTOBER 2004. =JeffH - The Cryptography Mailing List Unsubscribe by sending

RE: Foibles of user security questions

2008-01-14 Thread Dave Korn
On 07 January 2008 17:14, Leichter, Jerry wrote: Reported on Computerworld recently: To improve security, a system was modified to ask one of a set of fixed-form questions after the password was entered. Users had to provide the answers up front to enroll. One question: Mother's maiden

Re: Foibles of user security questions

2008-01-14 Thread Peter Gutmann
Florian Weimer [EMAIL PROTECTED] writes: * Jerry Leichter: I can just see the day when someone's fingerprint is rejected as insufficiently complex. It's been claimed that once you reach the retirement age, one person in ten hasn't got any fingerprints which can be used for biometric purposes.