Great Circle Associates Firewalls
(October 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Algorithmically derived passwords
From: Ryan Russell/SYBASE <Ryan . Russell @ sybase . com>
Date: 26 Oct 97 8:56:54 EDT
To: sedwards <sedwards @ sedwards . com>
Cc: Firewalls <Firewalls @ GreatCircle . COM>

Well, now that we know the formula (assuming
you didn't post a bogus example formula) there
are only 26^3 possibilities to check for.  That's
much easier than the billions of combinations one
would normally have to try when brute-forcing
or doing a dictionary attack with modification
rules.

Are they stupid?  Oh wait, you covered that in your
original note.

Uhh... What was the name of the client? :)

    Ryan






sedwards @
 sedwards .
 com on 10/24/97 02:10:31 PM
To: Firewalls @
 GreatCircle .
 COM @ smtp
cc:  (bcc: Ryan Russell/SYBASE)
Subject: Algorithmically derived passwords

I'm curious as to the "list's" opinion of using a "formula" to create
passwords.

One of my clients gives all of their hosts root passwords like:

 first-letter-of-host-name + (last-digit-of-host-name * 3) % 10\
  + "^" + 3-somewhat-random-letters

Their logic is that it:

) is not susceptible to dictionary based attacks

) is different for each host (as long as the formula is not known)

) is easy to remember or derive (assuming you know the formula)

What do the experts think?

Thanks in advance,
---------------------------------------------------------------------------
Steve Edwards         sedwards @
 sedwards .
 com          Voice: +1-760-723-2727
Newline                                                Fax: +1-760-731-3000





Indexed By Date Previous: Re: sex, lies, and firewall code
From: Ryan Russell/SYBASE <Ryan . Russell @ sybase . com>
Next: Re: sex, lies, and firewall code
From: "Paul D. Robertson" <proberts @ clark . net>
Indexed By Thread Previous: Re: Algorithmically derived passwords
From: Kogula Palan <palank @ pc . jaring . my>
Next: Re: Algorithmically derived passwords
From: "H. Morrow Long" <morrow . long @ yale . edu>

Google
 
Search Internet Search www.greatcircle.com