home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!olivea!decwrl!deccrl!news.crl.dec.com!news!nntpd.lkg.dec.com!Nephi.Enet.DEC.Com!coar
- From: coar@Nephi.Enet.DEC.Com (Rodent of Unusual Size)
- Newsgroups: alt.security
- Subject: Re: passwd security check
- Summary: VMS uses salt and *username*, not UIC
- Keywords: VMS, password, encryption
- Message-ID: <1992Jul23.163013.11058@nntpd.lkg.dec.com>
- Date: 23 Jul 92 17:08:56 GMT
- Sender: usenet@nntpd.lkg.dec.com (USENET News System)
- Organization: Digital Equipment Corp.
- Lines: 19
- Organisation: Employed by (*NOT* speaker for) DEC, Boxborough, MA, U.S.A.
-
-
- In article <1992Jul23.092715.1@zodiac.rutgers.edu>, leichter@zodiac.rutgers.edu writes...
- >
- >In hashing passwords, VMS uses both a random salt (16 bits worth) AND the
- >UIC (user/group number, 32 bits) as part of the hash.
-
- Actually, it's the *username* that goes into the soup, not the UIC. Hence
- even users with the same salt and UIC won't hash the same. At least, this
- is the case with the VMS-supplied algorithms; if you've instituted your
- own, this need not apply.
-
- > -- Jerry
-
- #ken :-)} Jeratol the Chaotic
-
- Coar@Nephi.Enet.DEC.Com | All opinions herein contained, stated or implied,
- Coar@DECUS.Org | are solely those of the author. And he's fullovem.
- Coar@Eisner.DECUS.Org | `... it was mine art, ... that made gape the pine
- Massachusetts, USA | and let thee out.' - Prospero (_The Tempest_)
-