The Channel logo

News

By | Richard Chirgwin 30th January 2014 03:29

Give hackers your data, says former RSA man

Just don't make it real data: feeding them fakes should see them off

Former RSA chief scientist Ari Juels has outlined a cunning way to foil crackers: let them think they've busted into a system and then give them fake data to play with.

The idea is not entirely novel because Juels last year proposed a scheme he called “Honeywords” in this paper, co-authored with RSA founder Ronald Rivest. Honeywords is a kind of “security by obscurity”, but in a good way: instead of an attacker stealing a table that has one password per user, the password table has the real password as well as a bunch of fakes – the “honeywords” – for each user.

As well as putting a potential fog of confusion in front of an attacker, a system could be setup to raise an alarm on attempts to log in using the honeywords, because that's a reliable indicator that the password table has been accessed.

Juels' new “Honey Encryption” proposal, with co-developer Thomas Ristenpart of the University of Wisconsin, takes this idea a step further, be refining a systems' response to unauthorised access attempts: instead of a login failure, the attacker would be served up fake data that resembles real data.

As MIT Review reports, even if an attacker eventually hits upon the right user ID / password combination, “the real data should be lost amongst the crowd of spoof data.”

For example, ten thousand attempts to get a credit card number would yield ten thousand fake-but-plausible numbers, leaving the attacker with the job of testing the validity of each number. Even better: if an attacker was trying to access a system's password store, each attempt failed at a master password would yield fake data.

MIT Review says Juels is now working on the code for a fake password vault generator for use with the Honey Encryption scheme. ®

comment icon Read 23 comments on this article alert Send corrections

Opinion

Baby looks taken aback/shocked/affronted. Photo by Shutterstock

Kat Hall

Plans for 2 million FTTP connections in next four years 'not enough'
Microsoft CEO Satya Nadella
Stranded_ships

Chris Mellor

Thousands of layoffs announced as spinning rust enters its death spiral

Features

STRASBOURG, JUNE 29, 2016: The seat of the European Parliament. by Marco Aprile for shutterstock. EDITORIAL USE ONLY
Plan b, image via Shutterstock
EU workers, new markets: post-Brexit pressure on May & Co
Tough question, pic via Shutterstock
Honest mistake with your licensing? Audit police look at it on a 'case by case basis'