Re: Private Key Generation from Passwords/phrases

2007-01-21 Thread Steven M. Bellovin
On Sat, 20 Jan 2007 18:41:34 -0600 Travis H. [EMAIL PROTECTED] wrote: BTW, dictionary attacks can probably be effectively resisted by making the hashes of passwords twice as big, and using a random value concatenated with the password before hashing, and storing it alongside the hash (it's

Re: Private Key Generation from Passwords/phrases

2007-01-21 Thread Travis H.
On Sun, Jan 21, 2007 at 12:13:09AM -0500, Steven M. Bellovin wrote: Could you explain this? It's late, but this makes no sense at all to me. I probably wasn't clear, you bring out my realization that there are a number of unwritten assumptions going on here. Similarly, the size of the output