From: unruh@invalid.ca   
      
   On 2012-06-13, Robert Riches wrote:   
   > On 2012-06-13, unruh wrote:   
   >> On 2012-06-13, Robert Riches wrote:   
   >>> On 2012-06-13, Moe Trin wrote:   
   >>>> ...   
   >>>>   
   >>>> I just love brain-dead features like that. If you've been following   
   >>>> the stupidity being revealed about the LinkedIn password fiasco, one   
   >>>> researcher discovered some of the exposed passwords were apparently   
   >>>> produced by an ancient and highly b0rken program called "mkpasswd".   
   >>>   
   >>> Okay, _WHAT_ is wrong with mkpasswd?   
   >>>   
   >>   
   >> Bad random number generator? Eg, rand, which has 32K different values.   
   >> That is not much these days.   
   >   
   > A 15-bit seed random number generator to generate passwords?   
   > That's insane! It should come with a warning label. One would   
   > get more entropy by flailing at the keyboard with eyes closed.   
   >   
   > Why doesn't it just read from /dev/random?   
      
   The more recent versions do. (expect-fedora-5.32.2-random.patch on   
   Mandriva does just that)   
   But not /dev/random, /dev/urandom (using /dev/random is crazy)   
      
   >   
      
   --- SoupGate-Win32 v1.05   
    * Origin: you cannot sedate... all the things you hate (1:229/2)   
|