home *** CD-ROM | disk | FTP | other *** search
- Xref: sparky sci.crypt:2724 comp.security.misc:787
- Newsgroups: sci.crypt,comp.security.misc
- Path: sparky!uunet!decwrl!pa.dec.com!nntpd2.cxo.dec.com!nntpd.lkg.dec.com!Nephi.Enet.DEC.Com!coar
- From: coar@Nephi.Enet.DEC.Com (Rodent of Unusual Size)
- Subject: Re: Crypt should be based on MD5 (was: the Crypt 16 discussion)
- Message-ID: <1992Jul23.125640.4682@nntpd.lkg.dec.com>
- Summary: Can limit exposure
- Keywords: password, expiration, goodness/evility
- Sender: usenet@nntpd.lkg.dec.com (USENET News System)
- Organisation: Employed by (*NOT* speaker for) DEC, Boxborough, MA, U.S.A.
- Organization: Digital Equipment Corp.
- Date: Thu, 23 Jul 1992 13:45:20 GMT
- Lines: 27
-
-
- Well, having a password expiration can limit exposure under some
- circumstances. If passwords are fairly well chosen (none of this 91Jan,
- 91Feb, 91Mar stuff), and one should happen to be revealed accidentally
- (NOT deduced or decrypted), the account is exposed only until the next
- time the password must be changed. The actual window of exposure can be
- anywhere from 0 to T (where T is the password lifetime), depending upon
- when the password was disclosed.
-
- I'm not sure of the value of this, but it seemed reasonable to bring it
- up.
-
- Of course, if the lifetime is too long, this window grows. If it is too
- short, the user will circumvent it by writing the password down in a
- convenient place or otherwise not safeguard it appropriately. Based upon
- experience, I feel a couple of months is a reasonable value for most
- users. Your kilometreage may vary..
-
- Practical security is a balancing act, sailing between the Scylla of
- exposure and the Charybdis of user convenience.
-
- #ken :-)} Jeratol the Chaotic
-
- Coar@Nephi.Enet.DEC.Com | All opinions herein contained, stated or implied,
- Coar@DECUS.Org | are solely those of the author. And he's fullovem.
- Coar@Eisner.DECUS.Org | `... it was mine art, ... that made gape the pine
- Massachusetts, USA | and let thee out.' - Prospero (_The Tempest_)
-