Drawbacks of Liao et al.'s Password Authentication Scheme
Eun‐Jun Yoon, Kee-Young Yoo · International Conference on Next Generation Web Services Practices · 2006
In 2006, Liao et al. proposed a new password authentication scheme over insecure networks. The primary merit of their scheme is its simplicity and practicality for implementation under insecure communication links. The current paper, however, demonstrates that Liao et al.'s scheme is vulnerable to masquerading server attacks, password guessing attacks using lost smart cards, and insider attacks. In addition, we point out that Liao et al.'s password change scheme is insecure, because an unauthorized user can easily change a new password for a smart card