Skip to content

Repository files navigation

HoneyEncryption

Honey Encryption

Introduction:

This is an implementation of Honey Encryption. The term was tossed by Ari Juels(RSA Labs) & Ronald L. Rivest(MIT CSAIL) during the presentation of The Password That Never Was at Harvard's Center for Research on Computation and Society (CRCS)(2014).

Report:

Latest major Password Breach Report [2011 - 2014] by Shiris Kumar

Presentation:

https://www.slideshare.net/shiriskumar/honey-encryption

Modules:

The project has 3 Modules to simulate different user environments:

  1. honeydev - Contains a set of login page with Honey Encryption implementation
  2. dashboard - Is the site's administrator's page to monitor ongoing activities
  3. hacker - Simulates the scenario of breaching password database and decrypting it at AWS.

Requirements:

  1. Python - to create Honeywords
  2. WAMP/XAMPP - to create a localhost server
  3. MSMTP - to emulate email server. Read CONFIGURE MAIL SERVER to setup mail server at localhost.

Links:

  1. Honeywords : Making Password-Cracking Detectable

  2. Youtube : "The Password That Never Was" (CRCS Lunch Seminar)

About

Honey Security Tool to be two steps ahead of an Adversarial

Resources

Stars

5 stars

Watchers

2 watching

Forks

Releases

Packages

Contributors

Languages