Firewall Wizards mailing list archives

Re: Stanford break in


From: "Paul D. Robertson" <paul () compuwar net>
Date: Thu, 22 Apr 2004 16:57:12 -0400 (EDT)

On Thu, 22 Apr 2004, Carric Dooley wrote:

Here's my take..

Here's my take on your take...

Network synced passwords are the only way to manage a large number of
users. If you have 10 workstations and 1 server, it might be fine to have

Yep...

JOHN the Ripper, Rainbow Crack or L0phtcrack could be PART of the process,
but it would make more sense to enforce strong passwords when the user
sets them. Decide on password guidelines like alpha-numeric, mixed case,
and one special character, and leave it to a dll like passfilt.dll or
something similar. Yellow stickies just comes down to end-user education,
and a good password policy. If the requirements are: "14 random

User education does not work.  Every study I've seen over the last 15
years says users and passwords will fail.  A large percentage of them will
hand them over for chocolate (saw that just this week)- and they *will*
write down the ones they need to remember.  Perhaps not the first time,
but they will.  user education will fail in some percentage of the
population, and as an attacker, if I get one, I can get more.  As an
attacker, I can always get one.  That's why Secure-ID continues to be
expensive- it fixes that problem better than the alternatives.  That's why
Secure-ID isn't that popular, that problem doesn't need that level of
fixing...

Frankly, "strong" passwords just need to be non-obvious, as they're really
only good at stopping casual attackers at keyboards.  If I get the hashes,
then I will win, if I'm Abe, I win faster, but winning happens in almost
any case.

Paul
-----------------------------------------------------------------------------
Paul D. Robertson      "My statements in this message are personal opinions
paul () compuwar net       which may have no basis whatsoever in fact."
probertson () trusecure com Director of Risk Assessment TruSecure Corporation
_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: