RE: [Full-Disclosure] Senior M$ member says stop using passwords completely!

From: Todd Towles (toddtowles_at_brookshires.com)
Date: 10/19/04

  • Next message: Joe Random: "[Full-Disclosure] Re: Stupid idea"
    To: "Pavel Kankovsky" <peak@argo.troja.mff.cuni.cz>, <full-disclosure@lists.netsys.com>
    Date: Tue, 19 Oct 2004 15:42:17 -0500
    
    

    I was under the understand that passwords of over 14 characters were
    stored with a more secure hash, therefore 14 characters passwords were
    harder to crack, due to the more secure hash. Windows will create two
    different hashes for passwords shorting than 14 characters, I do
    believe.

    Just use a non-printable character in your password and cracking is
    useless...if they crack it, they can't read what they cracked. ;)

    > -----Original Message-----
    > From: full-disclosure-admin@lists.netsys.com
    > [mailto:full-disclosure-admin@lists.netsys.com] On Behalf Of
    > Pavel Kankovsky
    > Sent: Sunday, October 17, 2004 2:21 PM
    > To: full-disclosure@lists.netsys.com
    > Subject: Re: [Full-Disclosure] Senior M$ member says stop
    > using passwords completely!
    >
    > On Sat, 16 Oct 2004, Frank Knobbe wrote:
    >
    > > It's a nice recommendation of MS to make (to use long passphrases
    > > instead of passwords). But I don't consider 14 chars a "passphrase".
    > > Perhaps they should enable more/all password components to
    > handle much
    > > longer passwords/phrases.
    >
    > A passphrase consisting of 7 words and 12 bits of entropy per
    > a word is as guessable as a password with 14 characters and 6
    > bits of entropy per a character. You get 84 bits of total
    > entropy in both cases.
    >
    > The only advantage of passphrases is that lusers might find
    > long random sequences of words easier to remember than long
    > random sequences of characters.
    >
    > (But wait: 12 bits of entropy per a word--this is equivalent
    > to a uniform choice of one word out of 4096. 4 thousand? That
    > might exceed an average luser's vocabulary by an order of
    > magnitude! ;>)
    >
    > --Pavel Kankovsky aka Peak [ Boycott
    > Microsoft--http://www.vcnet.com/bms ] "Resistance is futile.
    > Open your source code and prepare for assimilation."
    >
    > _______________________________________________
    > Full-Disclosure - We believe in it.
    > Charter: http://lists.netsys.com/full-disclosure-charter.html
    >

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Joe Random: "[Full-Disclosure] Re: Stupid idea"

    Relevant Pages

    • RE: [Full-Disclosure] Senior M$ member says stop using passwords completely!
      ... >stored with a more secure hash, therefore 14 characters passwords were ... due to the more secure hash. ... >useless...if they crack it, they can't read what they cracked. ...
      (Full-Disclosure)
    • Re: Web Site Hackers
      ... I wonder what determines an 'easy to crack PW'! ... If you have a password of "kcifix", 6 characters long all small ... program has to look at 26 to the power of 6 combinations. ... the number of possible passwords to 52 to the power of 16. ...
      (rec.outdoors.rv-travel)
    • Re: US Military bans HTML in emails
      ... Complex passwords are not that much harder to ... Consider a password with a choice of X different characters for each ... takes using all upper- and lowercase letters, ... I can see only two advantages of complex passwords: ...
      (comp.os.vms)
    • RE: Basic question
      ... If somebody else hasn't covered it already, I'll try to send out a Kerberos ... > Unicode character set and can be up to 128 characters long, ... > Pre-W2K user interfaces limits do not allow passwords to ... I believe that you are referring to *LM* hashes. ...
      (Focus-Microsoft)
    • Re: Paper & pencil password algorithm
      ... generator and generate a password as a permutation of a whole ... The advantage of a random sequence generator is that I can make my ... I can't imagine ever wanting passwords ... convenience I'll probably keep most of them between 20 and 50 characters ...
      (sci.crypt)

    Loading