RE: Using non-printable characters in passwords

From: Chris Berry (compjma_at_hotmail.com)
Date: 08/13/03

  • Next message: Leonard.Ong_at_nokia.com: "Nortel Contivity VPN and Firewalls"
    To: security-basics@securityfocus.com
    Date: Tue, 12 Aug 2003 17:57:50 -0700
    
    

    >From: "dave kleiman" <dave@netmedic.net>
    >Not quite;
    >
    >If you pass the 14 character margin, No LM hash will be stored of the
    >password. 14 characters is its limit, so if you enforce a policy of 15 or
    >greater you do not have to worry about it.

    That's true, but I wouldn't rely on that. It's pretty easy to disable the
    storing of the LM hash permanently.

    Chris Berry
    compjma@hotmail.com
    Systems Administrator
    JM Associates

    "Q: How many software engineers does it take to change a lightbulb ?
    A: It can't be done; it's a hardware problem."

    _________________________________________________________________
    Add photos to your messages with MSN 8. Get 2 months FREE*.
    http://join.msn.com/?page=features/featuredemail

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: Leonard.Ong_at_nokia.com: "Nortel Contivity VPN and Firewalls"

    Relevant Pages

    • Re: [opensuse] KDE3-4 did teams change?
      ... Hash: SHA1 ... It's ok for me, don't worry, I guessed. ... For additional commands, e-mail: opensuse+help@xxxxxxxxxxxx ...
      (SuSE)
    • Re: Is this encryption method ok?
      ... of r leaking through the encryption, or the worry that r might have ... leak, as long as enough entropy is left to hash into a session key, ...
      (sci.crypt)
    • Re: (OT) lincense protection generator
      ... Why not check if all files you use are in appropriate directories, but not worry about same computer? ... You could also use some kind of hash on all your files, and check that they haven't been changed using that. ... Because i don't want the users to move the folders around or mess with ... the program or taking copies home to fiddle with it, ...
      (comp.lang.python)
    • FreeBSD RELENG_7, console line messgae garbled on reboot
      ... Hash: SHA1 ... So I see it's nothing to worry about, but nevertheless I saw this just some minutes ago after detaching an usb drive. ...
      (freebsd-current)
    • Re: How can I remove duplicates from an ArrayList?
      ... one approach is to use a hash table instead of an arraylist since a hash ... table enforces unique constraints. ... You wouldn't need to worry about ... duplicates since an exception is thrown. ...
      (microsoft.public.dotnet.framework.aspnet.webcontrols)