Major security flaw undermines Apple and Google users, researchers discover
1–10 of 24 posts
Re: Major security flaw undermines Apple and Google users, researchers discover
#2Re: Major security flaw undermines Apple and Google users, researchers discover
#3Re: Major security flaw undermines Apple and Google users, researchers discover
#4Back in the day, Microsoft stored passwords in a fairly insecure format. Then they got security religion, and improved the strength of their password storage dramatically. It was very hard to crack the new format. (I don't remember exactly, but this would have been somewhere around when NT came out.)
But Microsoft was always big on backward compatibility. They wanted users of old machines to still be able to log in to the new servers. So they stored the passwords in the new, strong format, and in the old, weak format, so that they could still authenticate old clients. And that meant that attackers could still get the passwords in the weak format if they could get on the server.
This is from memory, and it's been over a decade, so I may not have all the details exactly correct...
Re: Major security flaw undermines Apple and Google users, researchers discover
#5The story has a familiar ring. Back in the day, Microsoft stored passwords in a fairly insecure format. Then they got security religion, and improved the strength of their password storage dramatically. It was very hard to crack the new format. (I don't remember exactly, but this would have been somewhere around when NT came out.) But Microsoft was always big on backward compatibility. They wanted users of old machin…
Re: Major security flaw undermines Apple and Google users, researchers discover
#6The story has a familiar ring. Back in the day, Microsoft stored passwords in a fairly insecure format. Then they got security religion, and improved the strength of their password storage dramatically. It was very hard to crack the new format. (I don't remember exactly, but this would have been somewhere around when NT came out.) But Microsoft was always big on backward compatibility. They wanted users of old machin…
Ah, LM vs NT hash.
Re: Major security flaw undermines Apple and Google users, researchers discover
#7If http://dualec.org/DualECTLS.pdf is the actual paper, I am not sure why Apple and Google users are more exposed than others. The paper requires a more thoughtful reading, of couse, but it does not appear to single out these two vendors.
http://blog.cryptographyengineering.com/2015/03/attack-of-we...
Re: Major security flaw undermines Apple and Google users, researchers discover
#8Earlier quoted context omitted.
Ah, LM vs NT hash.
http://en.wikipedia.org/wiki/LM_hash vs http://en.wikipedia.org/wiki/NT_LAN_Manager#NTLMv1 and http://en.wikipedia.org/wiki/NT_LAN_Manager#NTLMv2
Re: Major security flaw undermines Apple and Google users, researchers discover
#9The story has a familiar ring. Back in the day, Microsoft stored passwords in a fairly insecure format. Then they got security religion, and improved the strength of their password storage dramatically. It was very hard to crack the new format. (I don't remember exactly, but this would have been somewhere around when NT came out.) But Microsoft was always big on backward compatibility. They wanted users of old machin…
Ah, LM vs NT hash.
Re: Major security flaw undermines Apple and Google users, researchers discover
#10The story has a familiar ring. Back in the day, Microsoft stored passwords in a fairly insecure format. Then they got security religion, and improved the strength of their password storage dramatically. It was very hard to crack the new format. (I don't remember exactly, but this would have been somewhere around when NT came out.) But Microsoft was always big on backward compatibility. They wanted users of old machin…