Updated Alternative Passphrase Methods (markdown)
parent
490dd18674
commit
1ee32c3d0e
|
@ -3,18 +3,19 @@ As a general mechanism, we can add a non-exportable direct key signature to any
|
||||||
Exemplary types of such auxiliary information could be flags that the passphrase should be entered as a pin, lock pattern, or obtained via nfc.
|
Exemplary types of such auxiliary information could be flags that the passphrase should be entered as a pin, lock pattern, or obtained via nfc.
|
||||||
|
|
||||||
### NFC
|
### NFC
|
||||||
|
* Easily be lost together with the smartphone
|
||||||
|
* Protects against shoulder surfing
|
||||||
|
* Remote readable when in pocket?
|
||||||
|
|
||||||
### Lockpattern
|
### Lockpattern
|
||||||
|
* Weak: Offline brute force attacks
|
||||||
|
* Smudge attacks
|
||||||
|
|
||||||
### PIN
|
### PIN
|
||||||
|
* Weak: Offline brute force attacks
|
||||||
|
|
||||||
## Export
|
## Export
|
||||||
As on private key export for a new extra long passphrase to protect against offline attacks!
|
As on private key export for a new extra long passphrase to protect against offline attacks!
|
||||||
|
|
||||||
## Attack model
|
## Attack model
|
||||||
| Attack | Passphrase | NFC | PIN | Lockpattern |
|
Differentiate between offline attacks and attacks where an attacker has only short access to the smartphone UI.
|
||||||
|-------- |--- |--- |--- |--- |
|
|
||||||
| Offline brute force attacks | yes | yes | no | no |
|
|
||||||
| Lend smartphone to other guy | | | | |
|
|
||||||
| Shoulder surfing | no | yes | no | no |
|
|
||||||
| Smudge attacks | yes | yes | yes | no |
|
|
Loading…
Reference in New Issue