home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.os.vms
- Path: sparky!uunet!zaphod.mps.ohio-state.edu!uwm.edu!ux1.cso.uiuc.edu!usenet.ucs.indiana.edu!fractal!mdchaney
- From: mdchaney@fractal.ucs.indiana.edu (M Darrin Chaney)
- Subject: Re: PASSWORDS & SCHEMES
- Message-ID: <C0Jwzv.5xn@usenet.ucs.indiana.edu>
- Sender: news@usenet.ucs.indiana.edu (USENET News System)
- Nntp-Posting-Host: fractal.ucs.indiana.edu
- Organization: Indiana University, Bloomington
- References: <01GT9TRQCTGKC2ICDK@psulias.bitnet>
- Date: Fri, 8 Jan 1993 20:02:19 GMT
- Lines: 38
-
- JLW@PSULIAS.PSU.EDU ("J.Lance Wilkinson, 865-1818", 814) writes:
- > Since, as Dan mentioned, we have a way to add new items to the
- > DEC-supplied dictionary, I've wanted to do was to adapt a working
- > dictionary-based password policy program (like Ted Neiland's, for
- > example), to, instead of validating the plaintext password against
- > a dictionary, record the plaintext passwords which got this far (thus
- > they are *accepted* by VMS's other filters) in a file. Weekly, we'd
- > analyze the file of recorded plaintext passwords (saved *without* the
- > username, of course) to see if there were any words cropping up more
- > often. These words would then need to be added to the dictionary
- > because they're getting too popular as passwords.
-
- This is an incredibly bad idea. It's somewhat irrelevent if you keep the
- username or not. If you have 20 users change the password in a week, you
- can guess easily, or find out exactly has each one (by looking at the password
- change date in the UAF).
-
- Plus, this is a hacker's dream. Why use dictionaries when you have a file
- of x known good passwords on the system? Think again on this one, and don
- your asbestos suit...
-
- >+-"Never Underestimate the bandwidth of a station wagon full of mag tapes"--+
- >| J.Lance Wilkinson ("Lance") BitNet: JLW@PSULIAS.BITNET |
- >| Systems Design Specialist - Lead InterNet: JLW@PSULIAS.PSU.EDU |
- >| Library Computing Services AT&T:(814) 865-1818 FAX:(814)863-3560 |
- >| E8 Pattee Library "I'd rather be dancing..." |
- >| Penn State University A host is a host from coast to coast, |
- >| University Park, PA 16802 And no one will talk to a host that's close |
- >| <POSTMAST@PSULIAS.BITNET> Unless the host that isn't close |
- >| <POSTMAST@PSUCES.BITNET> Is busy, hung or dead. |
- >+------"He's dead, Jim. I'll get his tricorder. You take his wallet."-------+
-
- Darrin
- --
-
- mdchaney@iubacs mdchaney@bronze.ucs.indiana.edu mdchaney@rose.ucs.indiana.edu
-
- "I want- I need- to live, to see it all..."
-