Security Basics mailing list archives
Re: Password statistics and standards
From: Dathan Bennett <dathan () shsu edu>
Date: Tue, 17 Oct 2006 09:20:08 -0500
dave kleiman wrote:
I don't understand what you mean. Rainbow tables have been generated for 14-character NTLM passwords. Check out the Project RainbowCrack homepage (http://www.antsight.com/zsl/rainbowcrack/). Are you referring to the 8-character set available for MD5?If you shut off the storage of LM hashes, over 9 Characters will buy you some time. (Rainbow tables are only up to 8 characters on NTLM.)
If you're referring to NTLM, over 14 characters is pointless, because the algorithm truncates your password at 14 characters anyway. Otherwise, I'd say you're right. Precomputing tables for 14+ character passwords is time- and space-prohibitive, even for today's machines.To be safe over 14 characters would be the best, should be safe for a while, or at least until the tables catch up. (maybe a year or so)
~Dathan --------------------------------------------------------------------------- This list is sponsored by: Norwich University EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINEThe NSA has designated Norwich University a center of Academic Excellence in Information Security. Our program offers unparalleled Infosec management education and the case study affords you unmatched consulting experience. Using interactive e-Learning technology, you can earn this esteemed degree, without disrupting your career or home life.
http://www.msia.norwich.edu/secfocus ---------------------------------------------------------------------------
Current thread:
- Password statistics and standards samhenry (Oct 15)
- Re: Password statistics and standards Frynge Customer Support (Oct 16)
- RE: Password statistics and standards Peter Marshall (Oct 16)
- RE: Password statistics and standards dave kleiman (Oct 16)
- Re: Password statistics and standards Dathan Bennett (Oct 17)
- RE: Password statistics and standards John Lightfoot (Oct 18)
- Re: Password statistics and standards Ansgar -59cobalt- Wiechers (Oct 19)
- RE: Password statistics and standards dave kleiman (Oct 19)
- Re: Password statistics and standards Dathan Bennett (Oct 20)
- RE: Password statistics and standards dave kleiman (Oct 20)
- Re: Password statistics and standards Frynge Customer Support (Oct 16)
- RE: Changing the domain password policy Roger A. Grimes (Oct 17)
