Subject: CAcert Code Development list.
List archive
- From: Christophe Berger <chris AT berger.cx>
- To: cacert-devel AT lists.cacert.org
- Subject: Re: password advice
- Date: Wed, 28 Sep 2011 00:50:27 +0200
- Authentication-results: lists.cacert.org; dkim=pass (768-bit key) header.i= AT berger.cx; dkim-asp=none
Hi,
On Tue, Sep 27, 2011 at 12:29 PM, Ian G
<iang AT cacert.org>
wrote:
> If we ever get around to reworking the sign-up / password UI, perhaps we can
> use this as our advice for passwords....
>
> http://xkcd.com/936/
>
> Mind you, I don't understand the small print in the second box. Anyone know
> what a stolen hash is about?
For example : on Windows systems there is a local cache of passwords,
so if you get into a system, or have an access and can exploit
asecurity flaw you may be able to grab the password hash NT or NTLM
hashed.
These password hash can be bruteforced to get more access on the
system, or on the neigbours systems.
It is commonly used in penetration testing against Windows/AD
password, but also against any other password hash that can be found
on a system/web service/...
Windows password can also be brute forced using rainbow tables
(http://en.wikipedia.org/wiki/Rainbow_table), it's faster when you
have the correct tables (ie. precomputed with the characters used in
passwords)
The fact is that even long passwords can be guessed using these
techniques (rainbow tables), if they are not enough complex.
Regards,
Christophe
- password advice, Ian G, 09/27/2011
- Re: password advice, Marek Michał Mazur, 09/27/2011
- Re: password advice, ianG, 09/28/2011
- Re: password advice, mmazur, 09/28/2011
- AW: password advice, ulrich, 09/28/2011
- Re: AW: password advice, mmazur, 09/28/2011
- Re: AW: password advice, Philipp Gühring, 09/28/2011
- Re: AW: password advice, Marek Michał Mazur, 09/28/2011
- Re: password advice, Michael Tänzer, 09/28/2011
- Re: AW: password advice, Philipp Gühring, 09/28/2011
- Re: AW: password advice, mmazur, 09/28/2011
- AW: password advice, ulrich, 09/28/2011
- Re: password advice, mmazur, 09/28/2011
- Re: password advice, Faramir, 09/28/2011
- Re: password advice, ianG, 09/28/2011
- Re: password advice, Marek Michał Mazur, 09/27/2011
- Re: password advice, Christophe Berger, 09/27/2011
Archive powered by MHonArc 2.6.16.