Re: unix passwords

From: David Magda (dmagda+netnews_at_ee.ryerson.ca)
Date: 04/29/03

  • Next message: Fredje: "IAS and IDS deployment with JASS"
    Date: 29 Apr 2003 08:15:23 -0400
    
    

    elvis@notatla.demon.co.uk (all mail refused) writes:

    > In article <86sms6epmf.fsf@number6.magda.ca>, David Magda wrote:
    > >elvis@notatla.demon.co.uk (all mail refused) writes:
    > >> >Not much use in that. Most systems that store the password in
    > >> >/etc/shadow these days also use the MD5 based hash and not the crypt(3)
    > >> >based hash which John the Ripper attacks. Since the MD5 based one is
    > >>
    > >> John does md5 too...
    > >
    > >Using MD5 instead of DES (which is what crypt(3) basically is)
    > >doesn't really solve any security issues -- it just moves them into
    > >the future.
    >
    > Restricting passwords to 8 significant chars doesn't count as a
    > security issue in your eyes ?

    Of course it's a security issue, but I don't see what I said has
    anything to do with that.

    I missed part of the thread so we may be on slightly different
    frequencies here.

    -- 
    David Magda <dmagda at ee.ryerson.ca>, http://www.magda.ca/
    Because the innovator has for enemies all those who have done well under
    the old conditions, and lukewarm defenders in those who may do well 
    under the new. -- Niccolo Machiavelli, _The Prince_, Chapter VI
    

  • Next message: Fredje: "IAS and IDS deployment with JASS"

    Relevant Pages

    • Re: unix passwords
      ... In article, David Magda wrote: ... Restricting passwords to 8 significant chars doesn't count as a security ...
      (comp.security.unix)
    • Unreal Incident At Harrahs AC Poker Room
      ... hell broke loose - one of the scumbags gets directly in the old guy's ... I couldn't believe my eyes - and there was no security around ... Then I had to laugh when a 75 yr old 80-pound female security guard is ... first on the scene. ...
      (rec.gambling.poker)
    • Norton Your Eyes Only
      ... Subject: Norton Your Eyes Only ... I am having to audit the security of a number of laptops with Norton's Your ... Eyes Only (YEO) installed. ... For more information on SecurityFocus' SIA service which ...
      (Pen-Test)
    • Re: Unwanted programs on Win2K
      ... Chris Berry wrote: ... Security is everybody's problem. ... The more eyes, the better. ... > less likely they are to think that security precautions apply to them. ...
      (Security-Basics)
    • Re: What to report this under?
      ... moves a bit too fast for my old eyes, I can't get the seller name or auction #. ... Anyways, looking under security, I can't find what to report this under, without having the seller's name. ...
      (alt.marketing.online.ebay)