%% You should probably cite draft-bellovin-hpw-01 instead of this revision. @techreport{bellovin-hpw-00, number = {draft-bellovin-hpw-00}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-bellovin-hpw/00/}, author = {Steven Bellovin}, title = {{Hashed Password Exchange}}, pagetotal = 11, year = 2012, month = jan, day = 4, abstract = {Many systems (e.g., cryptographic protocols relying on symmetric cryptography) require that plaintext passwords be stored. Given how often people reuse passwords on different systems, this poses a very serious risk if a single machine is compromised. We propose a scheme to derive passwords limited to a single machine from a typed password, and explain how a protocol definition can specify this scheme.}, }