Sr. Web Developer
mediabistro.com
US-NY-New York

Justtechjobs.com Post A Job | Post A Resume

Comments for: jesus19990502

Message # 1013018:
Date: 08/21/02 17:04
By: Lee Profile
Subject: RE: Think like an Application Architect

Jon is, of course, correct -- dictionary attacks are very simple, highly effective exploits.

However, the pronouncable password should be -- as I noted -- be for one-time use only. Just give users a sunjump password to get in and then force them to change to a password with the necessary complexity to make dictionary attacks less of an issue.

Yes, this still leaves the site vulnerable if: 1) One knows a user who has just gotten one of these one-time passwords (or can see the usernames) 2) Runs dictionary attack when the password has not been yet changed.

Hole? Sure. But for the most part, pretty secure. You could add a layer of complexity by forcing the user to enter some other info to authenticate themselves, but that's getting a little out there.

Previous Message | Next Message


Comments:
re: pronouncable is importantSaint05/15/03 17:56
RE: easy to remember gibberishJames11/28/02 20:13
RE: See FIPS-181tom11/07/02 13:58
Big Mistakegilhad10/30/02 09:26
RE: Think like an Application ArchitectLee08/21/02 17:04
easy to remember gibberishAndrew Penry07/27/02 19:39
RE: Think like an Application ArchitectJon Nadal07/24/02 15:33
Think like an Application ArchitectLee04/16/02 22:01
RE: Another possible accessMike Marinescu03/01/02 01:53
RE: See FIPS-181mike01/09/02 10:52
QuestionJeff Williams12/20/01 22:05
Parse ErrorVijay Avarachen11/26/01 06:45
RE: One (of many) alternative solutionBrian Clancey08/23/01 16:49
RE: Another possible accessDavid Altherr07/06/01 12:29
RE: One (of many) alternative solutionHugh Bothwell06/23/01 11:22
RE: html editor and coursesJames Diss06/07/01 07:39
How about alternate vowels & consonants?Tom Westmacott05/07/01 12:29
One (of many) alternative solutionJack Healy05/03/01 09:29
RE: Another possible accessJeremy Weiskotten04/19/01 18:59
html editor and coursesMarlon Benjamin03/08/01 11:01
See FIPS-181Andy03/07/01 17:24
RE: Another possible accessKatie03/02/01 19:19
RE: Insecurity.Bill Canaday02/26/01 15:12
RE: Insecurity.Jay02/21/01 11:26
RE: Insecurity.Lance Sloan02/08/01 15:56
RE: Insecurity.Allen02/03/01 11:49
RE: Another possible accessMartin Scheffler01/11/01 06:17
RE: Insecurity.Matt12/15/00 17:50
Insecurity.Michal Zajaczkowski11/27/00 06:34
Another possible accessTomas Krojzl09/16/00 09:16
 

If you are looking for help, please post on the appropriate forum here. Your questions will be answered much more quickly.

Add A Comment:

Name:

Email:

Subject:

Message:

To reduce spam posts, messages are now manually approved

You are not [logged in]. That means your account will not get credit for this post.