Microsoft Security Errors
A blog post written by Robert Hensing (a MS employee) suggests that you should use pass phrases instead of passwords. His main point is that a long password is better than a complex one. I got two other points from the post (and comments). One, those pass phrases are hard to brute force on a letter by letter basis. But what stops somebody from using word by word brute forcing? For example, today's brute force attack would try every possible combination of letters and numbers. Why couldn't that just be changed to try every combination of words? That would probably be easier, because secure passwords (today) are composed of eight or more letters while pass phrases would only be three to five words. And two, MS considers backwards compatibility to be more important than security. They still store the LM (Lan Manager) hashes of their passwords, which are, by their own admission, less secure. And I thought that my Windows box was secure because the password was pretty good. Well then, whatever. If you didn't get this post, congratulations, you're not a nerd.

0 Comments:
Post a Comment
Subscribe to Post Comments [Atom]
<< Home