<?xml version='1.0' encoding='UTF-8'?>

<reference anchor='I-D.bellovin-hpw'>
<front>
<title>Hashed Password Exchange</title>

<author initials='S' surname='Bellovin' fullname='Steven Bellovin'>
    <organization />
</author>

<date month='March' day='11' year='2012' />

<abstract><t>Many systems (e.g., cryptographic protocols relying on symmetric cryptography) require that plaintext passwords be stored.  Given how often people reuse passwords on different systems, this poses a very serious risk if a single machine is compromised.  We propose a scheme to derive passwords limited to a single machine from a typed password, and explain how a protocol definition can specify this scheme.</t></abstract>

</front>

<seriesInfo name='Internet-Draft' value='draft-bellovin-hpw-01' />
<format type='TXT'
        target='http://www.ietf.org/internet-drafts/draft-bellovin-hpw-01.txt' />
</reference>

