home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!olivea!decwrl!pa.dec.com!decuac!hussar.dco.dec.com!mjr
- From: mjr@hussar.dco.dec.com (Marcus J. "will do TCP/IP for food" Ranum)
- Newsgroups: comp.unix.ultrix
- Subject: Re: Problem with npasswd??
- Message-ID: <1992Jul29.201836.2443@decuac.dec.com>
- Date: 29 Jul 92 20:18:36 GMT
- References: <1992Jul28.160606.12234@hubcap.clemson.edu> <1992Jul28.192523.1862@decuac.dec.com> <1992Jul29.134918.14912@hubcap.clemson.edu>
- Sender: news@decuac.dec.com (USENET News System)
- Organization: Digital Equipment Corporation, Washington ULTRIX Resource Center
- Lines: 23
- Nntp-Posting-Host: hussar.dco.dec.com
-
- >> Un-crackable password files are in principle a contradiction
- >>in terms.
- >
- >I am not searching for un-crackable passwords, just un-Crackable ones. In
- >other words, I want to combat Crack, which is available to every bored
- >undergrad in the universe.
-
- Do away with your password file entirely and replace it with
- a cryptographic smart card authentication system. That's what I meant
- about solving the problem, rather than the symptoms. In short what you
- are saying is:
-
- 1) I don't trust my users not to do something dumb
- 2) Therefore I will add logic to my software to make it increasingly
- hard for them to do something dumb
-
- You still haven't solved the problem: that you don't trust your
- users and you're still insecure - you've just vigorously attacked *ONE*
- of the symptoms. If you don't trust your users, just take one more step
- and make *SURE* that your authentication system doesn't in any way shape
- or form require you to trust your users at all.
-
- mjr.
-