Reply to post: Re: Dunce Cap tip

El Reg assesses crypto of UK banks: Who gets to wear the dunce cap?

Ken Hagan Gold badge

Re: Dunce Cap tip

To enlarge on Alan's comment, where a system asks for both a complete password (which can be hashed and salted) and a few characters from a second set (which probably can't) the point of the second line of defence is that you will be asked for a different selection the next time you log in. This hardens the system against keyloggers on the customer's device because for any reasonable length of the second set, it will be quite a while before the same three are asked for.

