Lecture 17: May 8, 2026
Reading:
text
, §13.3.1–13.9, 16.1
Assignments:
Homework 3, due May 11, 2026
Greetings and felicitations!
Passwords
Ways to force good password selection: random, pronounceable, computer-aided selection
Best: use passphrases: goal is to make search space as large as possible, distribution as uniform as possible
Attacks
Exhaustive search
Inspired guessing: think of what people would like (see above)
Random guessing: can’t defend against it; bad login messages aid it
Scavenging: passwords often typed where they might be recorded as login name, in other contexts, etc.
Ask the user: very common with some public access services
Defenses
For trial and error at login: dropping or back-off
For thwarting dictionary attacks: salting
Password aging
Pick age so when password is guessed, it’s no longer valid
Implementation: track previous passwords vs. upper, lower time bounds
Ultimate in aging: One-Time Password
Password is valid for only one use
May work from list, or new password may be generated from old by a function
Challenge-response systems
Computer issues challenge, user presents response to verify secret information known/item possessed
Example operations:
f
(
x
) =
x
+1, random, string (for users without computers), time of day, computer sends
E(
x
), you answer
E
(
D
(
E
(
x
))+1)
Note: password never sent over network
Biometrics
Depend on physical characteristics
Examples: pattern of typing (remarkably effective), retinal scans, etc.
Location
Bind user to some location detection device (human, GPS)
Authenticate by location of the device
Multi-factor authentication
Access Control Lists
Full access control lists
Abbreviations (UNIX method)
Matt Bishop
Office: 2209 Watershed Sciences
Phone: +1 (530) 752-8060
Email:
mabishop@ucdavis.edu
ECS 153A, Computer & Information Security & Privacy I
Version of May 7, 2026 at 12:41PM
You can also obtain a PDF version of this.