Skip to content

shiriskumar/HoneyEncryption

Repository files navigation

HoneyEncryption

Honey Encryption

Introduction:

This is an implementation of Honey Encryption. The term was tossed by Ari Juels(RSA Labs) & Ronald L. Rivest(MIT CSAIL) during the presentation of The Password That Never Was at Harvard's Center for Research on Computation and Society (CRCS)(2014).

Report:

Latest major Password Breach Report [2011 - 2014] by Shiris Kumar

Presentation:

https://www.slideshare.net/shiriskumar/honey-encryption

Modules:

The project has 3 Modules to simulate different user environments:

  1. honeydev - Contains a set of login page with Honey Encryption implementation
  2. dashboard - Is the site's administrator's page to monitor ongoing activities
  3. hacker - Simulates the scenario of breaching password database and decrypting it at AWS.

Requirements:

  1. Python - to create Honeywords
  2. WAMP/XAMPP - to create a localhost server
  3. MSMTP - to emulate email server. Read CONFIGURE MAIL SERVER to setup mail server at localhost.

Links:

  1. Honeywords : Making Password-Cracking Detectable

  2. Youtube : "The Password That Never Was" (CRCS Lunch Seminar)

About

Honey Security Tool to be two steps ahead of an Adversarial

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published