Passwords and Cryptwords
Michael M. Clark, Kent E. Seamons · 2022
Computers get faster every year; brains don’t. Passwords and other memorized credentials have unique usability advantages over tokens and biometrics, so we desire to design secure systems that maintain lengths that users can memorize. Some passwords are subject primarily to online attacks, and are simple to defend with rate limits and lockouts. Others, used to generate encryption keys, must be secure against offline attacks. We coin the term “cryptword” to distinguish these from passwords subject primarily to online attacks.