Re: 2.4.22-pre7: are security issues solved?

From: John Bradford (john_at_grabjohn.com)
Date: 07/23/03

  • Next message: Alan Cox: "Re: Promise SATA driver GPL'd"
    Date:	Wed, 23 Jul 2003 13:56:14 +0100
    To: davem@redhat.com, herbert@gondor.apana.org.au
    
    

    > > If I know your password is 7 characters I have a smaller
    > > space of passwords to search to just brute-force it.
    >
    > It's much smaller if you didn't know that it was at most 7 characters
    > long. However, if you did know the upper bound, or you were just
    > brute forcing all passwords starting from 1 character, then the
    > difference is relatively minor. This is because
    >
    > n + n^2 + n^3 + n^4 + n^5 + n^6
    >
    > is much smaller than n^7 where n is something like 62 for a reasonable
    > password.
    >
    > So if your password was broken using this method, then it's probably
    > too short anyway.

    One time passwords are much more secure.

    John.
    -
    To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
    the body of a message to majordomo@vger.kernel.org
    More majordomo info at http://vger.kernel.org/majordomo-info.html
    Please read the FAQ at http://www.tux.org/lkml/


  • Next message: Alan Cox: "Re: Promise SATA driver GPL'd"

    Relevant Pages

    • Re: US Military bans HTML in emails
      ... Complex passwords are not that much harder to ... Consider a password with a choice of X different characters for each ... takes using all upper- and lowercase letters, ... I can see only two advantages of complex passwords: ...
      (comp.os.vms)
    • RE: Basic question
      ... If somebody else hasn't covered it already, I'll try to send out a Kerberos ... > Unicode character set and can be up to 128 characters long, ... > Pre-W2K user interfaces limits do not allow passwords to ... I believe that you are referring to *LM* hashes. ...
      (Focus-Microsoft)
    • RE: Password statistics and standards
      ... If you shut off the storage of LM hashes, over 9 Characters will buy you ... Take a look at Perfect Passwords for some creative ideas: ... information about accounts which is helpful in telling me ... Norwich University ...
      (Security-Basics)
    • Re: US Military bans HTML in emails
      ... You mean like requiring 6-character passwords to now be "complex"? ... the need for non-alpha characters. ... I've seen passwords with zeros for O's and 3's for E's. ... What hacker ever think of that? ...
      (comp.os.vms)
    • Re: US Military bans HTML in emails
      ... Now the MIS departments has tightened security. ... You mean like requiring 6-character passwords to now be "complex"? ... the need for non-alpha characters. ... I assume here that the hacker has somehow obtained a backup tape ...
      (comp.os.vms)