Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <20181029155851.GA14817@openwall.com>
Date: Mon, 29 Oct 2018 16:58:51 +0100
From: Solar Designer <solar@...nwall.com>
To: passwords@...ts.openwall.com
Subject: Bloom filter patent

Hi,

A couple of weeks ago, I learned that a company claims to have patented
the use of Bloom filter for checking whether a password is known to have
been compromised:

hxxps://blog.shapesecurity.com/2018/09/26/look-ma-no-passwords-how-why-blackfish-uses-bloom-filters/
hxxps://www.shapesecurity.com/blackfish/

"Blackfish doesn't store passwords

The security of the Blackfish system itself was the most important
design consideration.  Shape's patented design uses a Bloom filter,
enabling Blackfish to perform lookups of your user's credentials without
maintaining a database of compromised passwords."

Naturally, I find patenting this unethical for many reasons.

Now, I bring this up in here because Arnold Reinhold and I happened to
comment on this idea in here last year:

https://www.openwall.com/lists/passwords/2017/10/29/2

I wonder if this possibly pre-dates the patent application if one has in
fact been made.  I tried searching for patents granted to this company
and found many, some of them looking particularly questionable, but not
a patent on use of Bloom filters.  Maybe the patent is not yet granted.

Arnold, would you care and know how to possibly notify the US patent
office about this and hopefully prevent this patent from being granted?

Alexander

Powered by blists - more mailing lists

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.