Re: It's not possible to allow non-OPIE logins only from trusted

看板FB_security作者時間14年前 (2011/03/16 16:01), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串24/26 (看更多)
RW <rwmaillists@googlemail.com> writes: > Dag-Erling Sm=C3=B8rgrav <des@des.no> writes: > > RW <rwmaillists@googlemail.com> writes: > > > IIRC there is/was a weakness in FreeBSD's OPIE implementation in > > > that it's susceptible to rainbow table attacks - I think part of > > > the hash is discarded. > > Can you provide more details? > http://lists.freebsd.org/pipermail/freebsd-security/2009-February/005114.= html Heh :) My first comment was a reference to the quality of the code, not the design. My second comment is basically the same thing I just said - we cannot change this without breaking compatibility. DES --=20 Dag-Erling Sm=C3=B8rgrav - des@des.no _______________________________________________ freebsd-security@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-security To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
文章代碼(AID): #1DW6u_UM (FB_security)
討論串 (同標題文章)
完整討論串 (本文為第 24 之 26 篇):
文章代碼(AID): #1DW6u_UM (FB_security)