Firewall Wizards mailing list archives

RE: "Proactive" Password Checking


From: "Moore, James" <James.Moore () MSFC NASA GOV>
Date: Tue, 16 Nov 1999 15:07:13 -0600

Well, that's what passfilt.dll does... it simply checks to see whether or
not the user's proposed new password meets the criteria defined in the dll's
logic. It does give them a response "right now" wrt whether or not their
password passes muster. It's not perfect, and it doesn't guarantee that the
password cracker won't be able to break it easily, but if its logic is well
structured it does improve one's odds that he has selected a "good"
password. And again, it does not obviate the need for "after the fact"
verification... the password cracker will sit in the background plugging
away, looking for those weak passwords that slipped through the crack in
passfilt.dll. 

I guess I'm responsible for the tangent this thread has taken. I was hoping
to find a good resource for coding a customized replacement for the standard
passfilt.dll that MS supplies. Since it doesn't appear that anyone knows of
one, maybe we oughta' just let this one die. My apologies to the group for
the diversion.

        Joe Yao then wrote....
        I believe his point is that the cracker can set his engine and
motion
        and go off, and come back in a couple of days for his results.  But
when
        your user says, "Computer, I would like to change my password,
please",
        or uses one of those quaint mouse thingies to press an icon, or a
        keyboard to enter a command line, he, she, or it usually would
prefer to
        have a response that second instead of in a couple of days.

On Fri, Nov 12, 1999 at 09:42:07AM -0600, Moore, James wrote:
...
I'm not sure I fully understand Alan's point wrt L0phtcrack etc., but I
don't believe password crackers obviate the utility of a tool such as
passfilt.dll.
...
-----Original Message-----
From:     Alan Ramsbottom [SMTP:ACR () als co uk]
Sent:     Tuesday, November 09, 1999 12:44 PM
...
Bear in mind that you can't afford to spend the 5 (or 50 or 500 or..)
mins
that it might take Crack, John the Ripper, L0phtcrack et al to find a
password. If anyone's worried enough to write custom password filters
then
they should probably run offline password crackers on a regular basis.


-- 
Joe Yao                               jsdy () cospo osis gov - Joseph S. D.
Yao
COSPO/OSIS Computer Support                                   EMT-B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.



Current thread: