Firewall Wizards mailing list archives
RE: "Proactive" Password Checking
From: "Moore, James" <James.Moore () MSFC NASA GOV>
Date: Tue, 16 Nov 1999 15:07:13 -0600
Well, that's what passfilt.dll does... it simply checks to see whether or
not the user's proposed new password meets the criteria defined in the dll's
logic. It does give them a response "right now" wrt whether or not their
password passes muster. It's not perfect, and it doesn't guarantee that the
password cracker won't be able to break it easily, but if its logic is well
structured it does improve one's odds that he has selected a "good"
password. And again, it does not obviate the need for "after the fact"
verification... the password cracker will sit in the background plugging
away, looking for those weak passwords that slipped through the crack in
passfilt.dll.
I guess I'm responsible for the tangent this thread has taken. I was hoping
to find a good resource for coding a customized replacement for the standard
passfilt.dll that MS supplies. Since it doesn't appear that anyone knows of
one, maybe we oughta' just let this one die. My apologies to the group for
the diversion.
Joe Yao then wrote....
I believe his point is that the cracker can set his engine and
motion
and go off, and come back in a couple of days for his results. But
when
your user says, "Computer, I would like to change my password,
please",
or uses one of those quaint mouse thingies to press an icon, or a
keyboard to enter a command line, he, she, or it usually would
prefer to
have a response that second instead of in a couple of days.
On Fri, Nov 12, 1999 at 09:42:07AM -0600, Moore, James wrote: ...I'm not sure I fully understand Alan's point wrt L0phtcrack etc., but I don't believe password crackers obviate the utility of a tool such as passfilt.dll....-----Original Message----- From: Alan Ramsbottom [SMTP:ACR () als co uk] Sent: Tuesday, November 09, 1999 12:44 PM...Bear in mind that you can't afford to spend the 5 (or 50 or 500 or..)minsthat it might take Crack, John the Ripper, L0phtcrack et al to find a password. If anyone's worried enough to write custom password filtersthenthey should probably run offline password crackers on a regular basis.-- Joe Yao jsdy () cospo osis gov - Joseph S. D. Yao COSPO/OSIS Computer Support EMT-B ----------------------------------------------------------------------- This message is not an official statement of COSPO policies.
Current thread:
- RE: "Proactive" Password Checking, (continued)
- RE: "Proactive" Password Checking bhe (Nov 14)
- RE: "Proactive" Password Checking Moore, James (Nov 14)
- Re: "Proactive" Password Checking Joseph S D Yao (Nov 17)
- RE: "Proactive" Password Checking Bill_Royds (Nov 14)
- RE: "Proactive" Password Checking Eric Toll (Nov 15)
- Re: "Proactive" Password Checking Joseph S D Yao (Nov 17)
- RE: "Proactive" Password Checking Moore, James (Nov 15)
- Re: "Proactive" Password Checking Andreas Gunnarsson (Nov 15)
- RE: "Proactive" Password Checking sean . kelly (Nov 15)
- Re: "Proactive" Password Checking Eric Toll (Nov 15)
- RE: "Proactive" Password Checking Moore, James (Nov 17)
- RE: "Proactive" Password Checking Russ (Nov 17)
- Re: "Proactive" Password Checking Aleph One (Nov 18)
- RE: "Proactive" Password Checking Vin McLellan (Nov 17)
- RE: "Proactive" Password Checking Moore, James (Nov 17)
- RE: "Proactive" Password Checking Matt Carothers (Nov 21)
- Re: "Proactive" Password Checking Barney Wolff (Nov 17)
- Re: "Proactive" Password Checking Eric Budke (Nov 18)
