@techreport{bellovin-hpw-01, number = {draft-bellovin-hpw-01}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-bellovin-hpw/01/}, author = {Steven Bellovin}, title = {{Hashed Password Exchange}}, pagetotal = 9, year = 2012, month = mar, day = 11, abstract = {Many systems (e.g., cryptographic protocols relying on symmetric cryptography) require that plaintext passwords be stored. Given how often people reuse passwords on different systems, this poses a very serious risk if a single machine is compromised. We propose a scheme to derive passwords limited to a single machine from a typed password, and explain how a protocol definition can specify this scheme.}, }