Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: Re: Selecting Good Passwords

Re: Selecting Good Passwords

From: der Mouse <mouse_at_Collatz.McRCIM.McGill.EDU>
Date: Tue, 11 Jun 1996 12:00:22 -0400

> We use a password generator that produces pronounceable gibberish.

Note to anyone considering such a thing: such passwords are no stronger
than the source of the random numbers driving them. Most random number
generators "look good" (as in, the resulting "gibberish" looks
"random") but are worthless in the cryptographic sense. And even if
you have a cryptographically strong generator, it's only as good as its
seed. I recall seeing someone reporting on a case where automatic
generation of passwords was experimented with and the simulated
attacker just tried all 2^16 possible seeds for the RNG driving the
password generation and cracked every one of the generated passwords in
less than a cpu-minute. (I don't know where Mark Riggins' generator is
getting its seed data from, tho from someone in "Secure Systems
Engineering" at AT&T I'd hope it's a strong source...but most machines
do not have strong sources of random numbers.)

                                        der Mouse

                            mouse_at_collatz.mcrcim.mcgill.edu
Received on Jun 11 1996

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos