Security Basics mailing list archives

RE: ADS Password Storage Protection


From: "Roger A. Grimes" <roger () banneretcs com>
Date: Wed, 19 Jul 2006 23:03:23 -0400

It's the math. 

Password keyspace is represented as X^L, where X is the number of
possible characters that can be used and L is the password length.
Because L is used as the exponent, it will always be X-1 times better
than X by itself (simplifying greatly of course).

Roger

*****************************************************************
*Roger A. Grimes, InfoWorld, Security Columnist 
*CPA, CISSP, MCSE: Security (2000/2003/MVP), CEH, yada...yada...
*email: roger_grimes () infoworld com or roger () banneretcs com
*Author of Professional Windows Desktop and Server Hardening (Wrox)
*http://www.amazon.com/gp/product/0764599909
*****************************************************************

 

-----Original Message-----
From: Pranav Lal [mailto:pranav.lal () gmail com] 
Sent: Tuesday, July 18, 2006 12:43 PM
To: security-basics () securityfocus com
Subject: RE: ADS Password Storage Protection

Hi Roger,
<snip Let me comment on this post by saying that password length beats
complexity character for character. 
PL] do you have any documentation to support the above statement? I ask
out of interest.

Pranav


------------------------------------------------------------------------
---
This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE The NSA has
designated Norwich University a center of Academic Excellence in
Information Security. Our program offers unparalleled Infosec management
education and the case study affords you unmatched consulting
experience. 
Using interactive e-Learning technology, you can earn this esteemed
degree, without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
------------------------------------------------------------------------
---


---------------------------------------------------------------------------
This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic Excellence
in Information Security. Our program offers unparalleled Infosec management
education and the case study affords you unmatched consulting experience.
Using interactive e-Learning technology, you can earn this esteemed degree,
without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------


Current thread: