Skip to content

Comment on Researchers discovered the perfect password that’s easy to rememberparent

Comments

Maybe the problem is that we have it backwards. Maybe it shouldn't be something you remember and push to the authentication mechanism, but something that the authentication mechanism pushes to you.

Like, what if you pick the corpus of a novel that you've read as your master password. And the password manager uses that novel plus several other novels that you have selected (but didn't read/won't read?) to give you a series of multiple choice selections to determine if you know the right book. Just a few short passages. Preferably with proper nouns stripped out.

You have to select the passages from the correct book for all the multiple choices. That way rather than recall, the memory factor is recognition. Combine it with a non-memorable token which you have to present first in order to even see the recognition factor test and you might have something workable.

The entropy of multiple choice selections is easily calculable and very low.

number of options * number of questions

This is essentially the same "password reset questions" loophole that allowed the apple cloud storage hack on a bunch of celebrities.

I didn't say to use it by itself. I said that your OTP would be required first to even access it. And of course you could provide backoff. And then you'd also have to be answering a series of multiple choice questions all correctly.

I dunno, just a thought, but do you get what I'm saying about recognition vs recall? Why don't we have the computer test us about things we're good at if part of the test has to be something only our individual brain is capable of?

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.