----- Original Message -----
From: "Bill Stewart" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Cc: <[EMAIL PROTECTED]>; "William Allen Simpson"
<[EMAIL PROTECTED]>
Sent: Friday, December 08, 2000 11:58 PM
Subject: Re: migration paradigm (was: Is PGP broken?)


> A more important problem with passphrase-based keys is collisions -
> two people picking wimpy passwords can end up with the same keys.
> This means that you need to use something besides the key to differentiate
> between the users.  It's not always a problem - if you've got your
> database of known public keys sorted by email address, it's ok,
> but if you've got it sorted by public key, you may have a problem.

Salt should take care of this (as well as reducing the effectiveness
of dictionary attacks).

Enzo



Reply via email to