home *** CD-ROM | disk | FTP | other *** search
- Xref: sparky comp.security.misc:834 alt.security:4020 comp.unix.ultrix:5916
- Newsgroups: comp.security.misc,alt.security,comp.unix.ultrix
- Path: sparky!uunet!cs.utexas.edu!qt.cs.utexas.edu!yale.edu!yale!gumby!destroyer!ubc-cs!newsserver.sfu.ca!sfu.ca!vanepp
- From: vanepp@fraser.sfu.ca (Peter Van Epp)
- Subject: Re: Problem with npasswd??
- Message-ID: <vanepp.712283688@sfu.ca>
- Sender: news@sfu.ca
- Organization: Simon Fraser University, Burnaby, B.C., Canada
- References: <PCL.92Jul27140810@black.oxford.ac.uk> <1992Jul27.184324.14697@hubcap.clemson.edu> <1992Jul27.201712.15229@jato.jpl.nasa.gov>
- Date: Tue, 28 Jul 1992 00:34:48 GMT
- Lines: 34
-
- dave@jato.jpl.nasa.gov (Dave Hayes) writes:
-
- >hubcap@hubcap.clemson.edu (System Janitor) writes:
- >>The point is, even if you use npasswd, a cracker will still get some of
- >>your passwords. So what if they only get 10 instead of 200, they'll still
- >>have some userids from which to launch their nefarious plans.
- >>So, aren't you fooling yourself to think that npasswd like schemes
- >>enhance your system security enough to make them worthwhile?
-
- >This is a hard statement to agree with, given that it is only a matter
- >of time before someone puts crack-like word scanning in npasswd.
-
- >Keep in mind that scanning plaintext matches is far faster than scanning
- >crypted ones.
-
- >--
- >Dave Hayes - Network & Communications Engineering - JPL / NASA - Pasadena CA
- >dave@elxr.jpl.nasa.gov dave@jato.jpl.nasa.gov ...usc!elroy!dxh
-
- > If it works...use it. If it doesn't, find out why and use THAT.
-
- And given that you have that plaintext password at this point, you don't have
- to search anything like the whole dictionary since after doing the transform
- you can eliminate all entries that for instance don't match the first letter
- of the word (assuming a sorted dictionary) cutting the work down to a managable
- level.
- Even now when this isn't true, it reduces the number of bad passwords
- that they have to find with Crack before you do. Npassword isn't an end in
- itself, you still need to do a bunch more things, but it is one of the things
- that helps.
-
-
- Peter Van Epp / Operations and Technical Support
- Simon Fraser University, Burnaby, B.C. Canada
-