Decoy Password Vaults: At Least as Hard as Steganography? [chapter]

Cecilia Pasquini, Pascal Schöttle, Rainer Böhme
2017 IFIP Advances in Information and Communication Technology  
Cracking-resistant password vaults have been recently proposed with the goal of thwarting offline attacks. This requires the generation of synthetic password vaults that are statistically indistinguishable from real ones. In this work, we establish a conceptual link between this problem and steganography, where the stego objects must be undetectable among cover objects. We compare the two frameworks and highlight parallels and differences. Moreover, we transfer results obtained in the
more » ... phy literature into the context of decoy generation. Our results include the infeasibility of perfectly secure decoy vaults and the conjecture that secure decoy vaults are at least as hard to construct as secure steganography. The final publication is available at Springer via http://dx.
doi:10.1007/978-3-319-58469-0_24 fatcat:szm7uuvwufettj6eknsgb2ixmy