During the past decade there have been significant advances in the field of Natural Language Processing (NLP) and, in particular, Information Extraction (IE) [2] which have fueled the development and deployment of a wide variety of systems in diverse application areas. However, one application area that has only recently been explored by the NLP community is the area of Information Assurance and Security. In this paper we describe a system for human authentication called QDP, or Query-Directed Passwords, that uses information extraction techniques with the World Wide Web as a database to provide feedback, from the security viewpoint, on the “quality” of a hint and answer pair input by a user.