home *** CD-ROM | disk | FTP | other *** search
- Xref: sparky comp.security.misc:853 alt.security:4031 comp.unix.ultrix:5940
- Newsgroups: comp.security.misc,alt.security,comp.unix.ultrix
- Path: sparky!uunet!decwrl!deccrl!news.crl.dec.com!pa.dec.com!decuac!hussar.dco.dec.com!mjr
- From: mjr@hussar.dco.dec.com (Marcus J. "will do TCP/IP for food" Ranum)
- Subject: Re: Problem with npasswd??
- Message-ID: <1992Jul28.192523.1862@decuac.dec.com>
- Sender: news@decuac.dec.com (USENET News System)
- Nntp-Posting-Host: hussar.dco.dec.com
- Organization: Digital Equipment Corporation, Washington ULTRIX Resource Center
- References: <1992Jul27.184324.14697@hubcap.clemson.edu> <1992Jul28.012207.27248@news.uiowa.edu> <1992Jul28.160606.12234@hubcap.clemson.edu>
- Date: Tue, 28 Jul 1992 19:25:23 GMT
- Lines: 16
-
- hubcap@hubcap.clemson.edu (System Janitor) writes:
-
- >Now now. Calm down. I don't think my logic makes me that much of a kook.
- >I want an unCrackable password file. I haven't yet come up with how to
- >get one.
-
- Un-crackable password files are in principle a contradiction
- in terms.
- How many users do you have? If you want to get paranoid enough,
- just modify login to use a cryptographic calculator or something like
- that. Slapping code around to try to keep your users from doing something
- dumb is an endless race - the human capacity for doing dumb is much
- greater than we'd like to think. If you care about security *that* much,
- solve the problem, don't just keep throwing patches at it.
-
- mjr.
-