Comparing Centrally and Locally Verified Memorized Secrets

No ratings

Presented at BSides Las Vegas 2022 by

Secrets memorized by the user (passwords, passphrases, PINs, etc.) can be verified centrally or used locally to unlock a multi-factor authenticator. Centrally verified and locally used memorized secrets have very different vulnerabilities, and therefore should have different complexity and storage requirements. This talk will attempt to clarify some of the terminology in this area and to present candidate requirements for both classes of memorized secrets.