Re: unix passwords

From: David Magda (dmagda+netnews_at_ee.ryerson.ca)
Date: 04/25/03

  • Next message: karim: "Re: How to give read only permissions to a directory ro a user?"
    Date: 25 Apr 2003 08:19:20 -0400
    
    

    elvis@notatla.demon.co.uk (all mail refused) writes:
    > >Not much use in that. Most systems that store the password in
    > >/etc/shadow these days also use the MD5 based hash and not the crypt(3)
    > >based hash which John the Ripper attacks. Since the MD5 based one is
    >
    > John does md5 too...

    Using MD5 instead of DES (which is what crypt(3) basically is)
    doesn't really solve any security issues -- it just moves them into
    the future.

    Eventually computers will be fast enought that MD5 hashes can be
    attacked just as quickly as crypt(3) ones.

    The only "future proof" technique is OpenBSD's bcrypt setup:

            http://www.openbsd.org/events.html#usenix99

    Their paper describing the techinque is at:

            http://www.openbsd.org/papers/bcrypt-paper.ps

    Really quite an ingenious way of doing things.

    -- 
    David Magda <dmagda at ee.ryerson.ca>, http://www.magda.ca/
    Because the innovator has for enemies all those who have done well under
    the old conditions, and lukewarm defenders in those who may do well 
    under the new. -- Niccolo Machiavelli, _The Prince_, Chapter VI
    

  • Next message: karim: "Re: How to give read only permissions to a directory ro a user?"

    Relevant Pages

    • Re: Wal Mart Kills Suspected Shoplifter in Parking Lot
      ... >> These were not security guards. ... >> Stores policies encouraged them to take those actions, Wal Mart itself ... >> corporation's policies if the individual store sees fit. ...
      (alt.gathering.rainbow)
    • Re: Event ID 623
      ... Another place to check would be the number of security and distribution ... MVP - Directory Services ... The version store for this instance has reached its ... Event Source: NTDS SDPROP ...
      (microsoft.public.windows.server.active_directory)
    • Re: TV Licensing are conning the BBC
      ... You could have forgiven the security man for believing ... >the store had given him powers to stop and check people. ... "On suspicion of theft" he replied. ... The police came at 9:45pm, 45 minuted after the store had closed ...
      (uk.legal)
    • Re: Pentester convicted..
      ... Starting at your "The door opens." ... Inform the store's customers that he was able to enter the store, ... NOT tell the store owners that he entered the store, ... A security pro notices a flaw, checks to make sure he is not on crack by ...
      (Pen-Test)
    • Re: Exmerge problem!!!
      ... Create a new security group called "Exmerge" in Active Directory ... In the Exchange System Manager, locate the MAILBOX STORE you wish to ... > Information Store, no nothing.It just denies me access to the Mailbox ... > the 'Log file not initialized' log file for more information. ...
      (microsoft.public.exchange.admin)