Firewall Wizards mailing list archives
Re: Stanford break in
From: "Paul D. Robertson" <paul () compuwar net>
Date: Thu, 22 Apr 2004 16:57:12 -0400 (EDT)
On Thu, 22 Apr 2004, Carric Dooley wrote:
Here's my take..
Here's my take on your take...
Network synced passwords are the only way to manage a large number of users. If you have 10 workstations and 1 server, it might be fine to have
Yep...
JOHN the Ripper, Rainbow Crack or L0phtcrack could be PART of the process, but it would make more sense to enforce strong passwords when the user sets them. Decide on password guidelines like alpha-numeric, mixed case, and one special character, and leave it to a dll like passfilt.dll or something similar. Yellow stickies just comes down to end-user education, and a good password policy. If the requirements are: "14 random
User education does not work. Every study I've seen over the last 15 years says users and passwords will fail. A large percentage of them will hand them over for chocolate (saw that just this week)- and they *will* write down the ones they need to remember. Perhaps not the first time, but they will. user education will fail in some percentage of the population, and as an attacker, if I get one, I can get more. As an attacker, I can always get one. That's why Secure-ID continues to be expensive- it fixes that problem better than the alternatives. That's why Secure-ID isn't that popular, that problem doesn't need that level of fixing... Frankly, "strong" passwords just need to be non-obvious, as they're really only good at stopping casual attackers at keyboards. If I get the hashes, then I will win, if I'm Abe, I win faster, but winning happens in almost any case. Paul ----------------------------------------------------------------------------- Paul D. Robertson "My statements in this message are personal opinions paul () compuwar net which may have no basis whatsoever in fact." probertson () trusecure com Director of Risk Assessment TruSecure Corporation _______________________________________________ firewall-wizards mailing list firewall-wizards () honor icsalabs com http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
Current thread:
- RE: Stanford break in, (continued)
- RE: Stanford break in Victor Williams (Apr 22)
- RE: Stanford break in R. DuFresne (Apr 22)
- RE: Stanford break in Carric Dooley (Apr 23)
- RE: Stanford break in Victor Williams (Apr 23)
- Re: Stanford break in mlh (Apr 23)
- Re: Stanford break in Luca Berra (Apr 23)
- Re: Stanford break in Chuck Vose (Apr 22)
- Re: Stanford break in Adam Shostack (Apr 22)
- Re: Stanford break in Carric Dooley (Apr 23)
- Passwords (was: Stanford break in) Ben Nagy (Apr 23)
- RE: Stanford break in Carric Dooley (Apr 23)
- RE: Stanford break in Paul D. Robertson (Apr 23)
- RE: Stanford break in Vin McLellan (Apr 26)
- Re: Stanford break in Adam Shostack (Apr 23)
- Re: Stanford break in Bennett Todd (Apr 23)
