SEARCH RESULTS
 
Showing 1-10 of 297 records
 
Expand article

Password policies. Once again.

2007-09-04 22:14:00 by Steve Riley in Steve Riley on Security
 
...password polices and the out-of-box defaults came up. The poster lamented a number of things: that Microsoft doesn't enable account lockout by default, that we don't have a built-in mechanism for automatically disabling unused accounts, that the 42-day default expiration is troublesome. Here's my response; figured that it would make for a...
 
 
 
 
 
Expand article

Password Minder 1.5.0.10 Released

2008-04-12 15:49:00 by Keith Brown in Security Briefs
 
...password dialog to be more reasonable: it now by default specifies a 12-char password, not the 20 it used to - most websites can't handle a password that long. I also removed the lower case 'l' and punctuation, with a button that allows you to add back in the puncutation marks if you want One last minor thing - I added AcceptsReturn=true to...
 
 
 
 
 
Expand article

Password Minder 1.5.0.10 Released

2008-04-12 21:49:00 by keith-brown in Security Briefs
 
...password dialog to be more reasonable: it now by default specifies a 12-char password, not the 20 it used to - most websites can't handle a password that long. I also removed the lower case 'l' and punctuation, with a button that allows you to add back in the puncutation marks if you want One last minor thing - I added AcceptsReturn=true to...
 
 
 
 
 
Expand article

Password Minder 1.5.0.10 Released

2008-04-12 21:49:00 by keith-brown in Security Briefs
 
...password dialog to be more reasonable: it now by default specifies a 12-char password, not the 20 it used to - most websites can't handle a password that long. I also removed the lower case 'l' and punctuation, with a button that allows you to add back in the puncutation marks if you want One last minor thing - I added AcceptsReturn=true to...
 
 
 
 
 
Expand article

Password Minder 1.5.0.10 Released

2008-04-12 22:49:00 by keith-brown in Security Briefs
 
...password dialog to be more reasonable: it now by default specifies a 12-char password, not the 20 it used to - most websites can't handle a password that long. I also removed the lower case 'l' and punctuation, with a button that allows you to add back in the puncutation marks if you want One last minor thing - I added AcceptsReturn=true to...
 
 
 
 
 
Expand article

Weak Hashing Algorithms: Outlook PST file CRC32 password cracking example

2008-10-01 00:18:44 by Editor in Irongeek's Security Site
 
...password cracking example In a previous video I explained the basics of cryptographic hashes. Go watch " A Brief Intro To Cryptographic Hashes/MD5 " before this video. In this tutorial, Ill be giving an example of why weak hashes are bad. The example I'll be using is the CRC32 hash that Outlook uses to store a PST archives password with. The...
 
 
 
 
 
Expand article

FaxBox: the latest in password scams

2008-01-07 18:09:34 by Steve Riley in Steve Riley on Security
 
...password. Most people, sigh, willingly supply their passwords to any seemingly innocuous service. We all know that these services really are vile disgusting filth, the very embodiment of whatever nefarious supreme being you now strongly wish would unleash itself on FaxBox and their ilk So in this case, I'm certainly not going to click on the...
 
 
 
 
 
Expand article

OT: Expiring Password & News

The Article has images
2008-01-25 10:36:53 by Evan Francen in The Breach Blog
...password Hi I believe my computer password will expire on 2/5/08. How do I get a new one/ Do I just call-in Thx for your help Jane B. Doe xxx-xxx-xxxx xxx-xxx-xxxx (Fax The service desk thought I might find some humor in this, maybe you do too. If you don't see a problem with this email then you need some training, eh The Breach Blog...
 
 
 
 
 
Expand article

Forgot your password? may be weakest link in web security

2008-08-27 13:27:57 by Editor in Digg / Security
 
Almost everyone forgets a Web site password once in a while. When you do, you click on the familiar Forgot your password? link. As an experiment, Thompson recently asked a few friends for permission to "hack" into their bank accounts. Using only information gathered from Web sites such as Facebook, he found his way in to each account within minutes
 
 
 
 
 
Expand article

A British Bank Bans a Man's Password