Live data from Hacker News

A memory of Bob Morris

it.slashdot.org

21–23 of 23 posts

Re: A memory of Bob Morris

#21
post #20
post #7

Am I the only one who finds that action malicious and unflattering? It's one thing to try to hack into systems that you have no access to, and an entirely different thing to replace /bin/login to harvest passwords on a machine you have root access on. I really don't see this as touching, warm or fuzzy at all. It has nothing to do with hacking, it's just a way of getting everyone's passwords.

Things were different then. I remember, a few years after the worm, Sun had just come out with shadow passwords; but our system hadn't implemented them yet. So I decided to run a dictionary attack the passwords stored in /etc/passwd. I wanted to show our sysadmins that going shadow was better, by telling them how many passwords could be broken. Obviously, I ran this password cracker on the same machine, and didn't bo…

I guess you're right. I do agree that people are too touchy today.

Re: A memory of Bob Morris

#22
post #20
post #7

Am I the only one who finds that action malicious and unflattering? It's one thing to try to hack into systems that you have no access to, and an entirely different thing to replace /bin/login to harvest passwords on a machine you have root access on. I really don't see this as touching, warm or fuzzy at all. It has nothing to do with hacking, it's just a way of getting everyone's passwords.

Things were different then. I remember, a few years after the worm, Sun had just come out with shadow passwords; but our system hadn't implemented them yet. So I decided to run a dictionary attack the passwords stored in /etc/passwd. I wanted to show our sysadmins that going shadow was better, by telling them how many passwords could be broken. Obviously, I ran this password cracker on the same machine, and didn't bo…

People got into a LOT of trouble over that as early as 1995, cf. the Randal Schwartz case: http://www.lightlink.com/spacenka/fors/

Re: A memory of Bob Morris

#23
post #20

Earlier quoted context omitted.

Things were different then. I remember, a few years after the worm, Sun had just come out with shadow passwords; but our system hadn't implemented them yet. So I decided to run a dictionary attack the passwords stored in /etc/passwd. I wanted to show our sysadmins that going shadow was better, by telling them how many passwords could be broken. Obviously, I ran this password cracker on the same machine, and didn't bo…

People got into a LOT of trouble over that as early as 1995, cf. the Randal Schwartz case: http://www.lightlink.com/spacenka/fors/

I remember that episode. Memory's fuzzy, but I think Merlyn wasn't employed by Intel at that time; I think even his consultant gig had just lapsed. I think someone at Intel just got a bee up his bonnet and decided to raise a stink; and things snowballed after that.

In my case, I was a student with unbounded curiosity at a Univ; and the sysadmins were very tolerant then.

Post reply on HN