[Cryptography] Security weakness in iCloud keychain

William Allen Simpson william.allen.simpson at gmail.com
Tue May 8 21:28:46 EDT 2018


On 5/8/18 2:04 AM, Jon Callas wrote:
> [...] If this manager could go out and change the password for you automagically as well, then as the life of any given random password approaches a single login, then that simple password system approaches the security of that type of two-factor, while gaining the benefit that a stolen database of shared secrets has ever-decaying usefulness, which lowers the incentive to hack that database in the first place. Single factor with automated change is arguably better than two-factor.
> 
Here we are almost 25 years later back at Photuris....


More information about the cryptography mailing list