Follow Slashdot blog updates by subscribing to our blog RSS feed

 



Forgot your password?
typodupeerror

Comment False accept rate (Score 1) 138

"has a false accept rate of only 0.09%"

So that's about a 1/1000 false accept rate against a brute force attack, which is comparable to some biometrics. This actually isn't very good. A determined attacker will not just send random pictures, but will send pictures that they think the target of the attack may have used. This results on a much higher false accept rate.

Even 1/1000 is marginal enough that substantial rate limiting is going to be needed to keep the account secure. Compare that against the security of, say, a 6-digit random one-time password (1/1 million).

And as another commenter pointed out, it's not meaningful to talk about false accept rate without also talking about the false reject rate.

Submission + - NIST Solicits Comments on Electronic Authentication Guideline (nist.gov)

Jim Fenton writes: The National Institute of Standards and Technology (NIST) is poised to make what is expected to be a major revision of Special Publication 800-63-2, Electronic Authentication Guideline. While normative only for the Federal Government, it is widely referenced elsewhere and specifies requirements to meet each of four Levels of Assurance (LOA). Should this structure change? Are there changes in technology or threats that should be considered in the revision? NIST would like to hear from you!

Comment My system crashed too (Score 1) 480

My Fedora 8 machine (kernel: 2.6.26.6-49.fc8) crashed around midnight UTC as well. Last syslog message was at 23:40:07 UTC so it may have not happened at exactly midnight; it would be unusual not to have something logged for 20 minutes. When I got to the machine, it was completely unresponsive; couldn't get it to do anything but reboot. The hardware has been very reliable and it's on a UPS.

I have seen a thread on linux.debian.user about this happening on Debian.

Before someone points it out, yes, I know that support for Fedora 8 goes away in a week or so.

Slashdot Top Deals

Hotels are tired of getting ripped off. I checked into a hotel and they had towels from my house. -- Mark Guido

Working...