home *** CD-ROM | disk | FTP | other *** search
- Xref: sparky comp.security.misc:835 alt.security:4021 comp.unix.ultrix:5917
- Newsgroups: comp.security.misc,alt.security,comp.unix.ultrix
- Path: sparky!uunet!news.uiowa.edu!icaen.uiowa.edu!dsiebert
- From: dsiebert@icaen.uiowa.edu (Doug Siebert)
- Subject: Re: Problem with npasswd??
- Sender: news@news.uiowa.edu (News)
- Message-ID: <1992Jul28.012207.27248@news.uiowa.edu>
- Date: Tue, 28 Jul 1992 01:22:07 GMT
- References: <PCL.92Jul27140810@black.oxford.ac.uk> <1992Jul27.184324.14697@hubcap.clemson.edu>
- Nntp-Posting-Host: l_cae14.icaen.uiowa.edu
- Organization: ISCA
- Lines: 33
-
- In article <1992Jul27.184324.14697@hubcap.clemson.edu> hubcap@hubcap.clemson.edu (System Janitor) writes:
- >Unless I am mistaken, npasswd doesn't check for everything crack does.
- >Even dropping the time consuming crypt part, it seems like it would
- >take an unacceptable amount of time to change your password if it were
- >checked against, say, an 800,000 word dictionary with 300 transmogrification
- >rulesets.
-
- Why should that be time consuming? Space consuming, yes? But not time
- consuming. Ever hear of a binary search? ;-)
-
- >
- >The point is, even if you use npasswd, a cracker will still get some of
- >your passwords. So what if they only get 10 instead of 200, they'll still
- >have some userids from which to launch their nefarious plans.
- >So, aren't you fooling yourself to think that npasswd like schemes
- >enhance your system security enough to make them worthwhile?
-
- With that kind of logic why bother with security at all? If you figure that
- unless you have extreme measures any given site on the Internet will be hit by
- crackers eventually you could just chuck all the security checking altogether,
- couldn't you? If you really do check a 800,000 word dictionary with 300
- transmorgrifications each a cracker would have to work a REALLY long time to
- get even one password, making it more likely for someone to notice him. Its
- certainly an improvement over the alternative, isn't it?
-
- --
- /-----------------------------------------------------------------------------\
- | Doug Siebert | "I don't have to take this abuse |
- | Internet: dsiebert@icaen.uiowa.edu | from you - I've got hundreds of |
- | NeXTMail: dsiebert@chop.isca.uiowa.edu | people waiting in line to abuse |
- | ICBM: 41d 39m 55s N, 91d 30m 43s W | me!" Bill Murray, Ghostbusters |
- \-----------------------------------------------------------------------------/
- Hi, I'm a .signature worm. I've already copied myself into your .signature.
-