Boston Linux & UNIX was originally founded in 1994 as part of The Boston Computer Society. We meet on the third Wednesday of each month at the Massachusetts Institute of Technology, in Building E51.

BLU Discuss list archive


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Discuss] 19,000 person company passwords stolen via HTTPS



On 10/6/2015 8:01 PM, Dr. Anthony Gabrielson wrote:
> PGP is not a monolithic data store although it can interface with
> one.  DoD encryption boxes are not monolithic. It all depends on the
> model and how trust is defined and established.

/etc/passwd is. So is every web service authentication system that I've 
ever seen in production.


> What are your requirements and why?

Reliable, verifiable authentication that scales globally without any 
party having more than one set of credentials in their possession. 
Because the only way to guarantee that 19,000 company (or 37 million 
Ashley Madison) passwords/hashes/ciphers/whatever can't be stolen in a 
massive breach is not to have 19,000 company (or 37 million Ashley 
Madison) passwords/hashes/ciphers/whatever in one place.

-- 
Rich P.



BLU is a member of BostonUserGroups
BLU is a member of BostonUserGroups
We also thank MIT for the use of their facilities.

Valid HTML 4.01! Valid CSS!



Boston Linux & Unix / webmaster@blu.org