After reading some of the conference papers about different ways to make password authentication more secure, I found an interesting idea of introducing decoy passwords as "traps" for adversaries. Such decoy passwords are usually referred as honeywords. Honeywords are supposed to be able to trigger an alarm when adversary is trying to log in.
I will evaluate on this idea in my case study. The aim is to find out is this method really useful and wether it can be implemented in today's services
Comments
Post a Comment