Security Basics mailing list archives
Re: ADS Password Storage Protection
From: "Jeffrey F. Bloss" <jbloss () tampabay rr com>
Date: Wed, 19 Jul 2006 14:51:20 -0400
dave kleiman wrote:
Eric, I beg to differ. Are you suggesting that a 40-60 character passphrase "&Old King Cole was a merry old soul, a merry old soul was he; he called for his pipe, he called for his bowl!!" is not more secure than "$%Op13f987&"
In some ways yes, and in some ways no. :) The essence of the LM Hash vulnerability is being able to derive an entire pass phrase from a portion. Since pass phrases were hashed in "chunks" it was possible to crack a smaller chunk and potentially guess the rest from that information. If you discovered the text "garzel" and knew a pet's name was "garzelfloposaurus"... :) Your Old King Cole example suffers from the same weakness. It wouldn't take long to figure out the rest if we knew the "&Old Ki" part. And of course "&Old Ki" is less secure than "$%Op13f987&" in every way. -- Hand crafted on 19 July, 2006 at 14:41:28 EDT Does the name Pavlov ring a bell?
Attachment:
signature.asc
Description:
Current thread:
- RE: ADS Password Storage Protection, (continued)
- RE: ADS Password Storage Protection Roger A. Grimes (Jul 19)
- RE: ADS Password Storage Protection Pranav Lal (Jul 19)
- RE: ADS Password Storage Protection Roger A. Grimes (Jul 21)
- Re: Re: RE: ADS Password Storage Protection eric . baechle (Jul 17)
- RE: Re: RE: ADS Password Storage Protection dave kleiman (Jul 18)
- RE: Re: RE: ADS Password Storage Protection Baechle, Eric (Jul 19)
- RE: Re: RE: ADS Password Storage Protection dave kleiman (Jul 19)
- RE: Re: RE: ADS Password Storage Protection Baechle, Eric (Jul 19)
- RE: Re: RE: ADS Password Storage Protection Roger A. Grimes (Jul 21)
- RE: Re: RE: ADS Password Storage Protection Michael Yelland (Jul 21)
- RE: Re: RE: ADS Password Storage Protection dave kleiman (Jul 18)
- Re: ADS Password Storage Protection Jeffrey F. Bloss (Jul 21)
- RE: ADS Password Storage Protection dave kleiman (Jul 21)
- Re: ADS Password Storage Protection Jeffrey F. Bloss (Jul 21)
- RE: ADS Password Storage Protection Roger A. Grimes (Jul 24)
- RE: ADS Password Storage Protection Depp, Dennis M. (Jul 19)
- RE: ADS Password Storage Protection Roger A. Grimes (Jul 21)
- Re: ADS Password Storage Protection ab (Jul 19)
