Security Basics mailing list archives

Re: Password statistics and standards


From: Dathan Bennett <dathan () shsu edu>
Date: Tue, 17 Oct 2006 09:20:08 -0500

dave kleiman wrote:
If you shut off the storage of LM hashes, over 9 Characters will buy you
some time. (Rainbow tables are only up to 8 characters on NTLM.)
I don't understand what you mean. Rainbow tables have been generated for 14-character NTLM passwords. Check out the Project RainbowCrack homepage (http://www.antsight.com/zsl/rainbowcrack/). Are you referring to the 8-character set available for MD5?

To be safe over 14 characters would be the best, should be safe for a while,
or at least until the tables catch up. (maybe a year or so)

If you're referring to NTLM, over 14 characters is pointless, because the algorithm truncates your password at 14 characters anyway. Otherwise, I'd say you're right. Precomputing tables for 14+ character passwords is time- and space-prohibitive, even for today's machines.

~Dathan

---------------------------------------------------------------------------
This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic Excellence in Information Security. Our program offers unparalleled Infosec management education and the case study affords you unmatched consulting experience. Using interactive e-Learning technology, you can earn this esteemed degree, without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------


Current thread: