RHUL-MA-2001-2 An active attack against a key agreement protocol based on a shared password is described. If poorly chosen, as passwords often are, the password can be compromised by a simple brute force search.