BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] 19,000 person company passwords stolen via HTTPS
- Subject: [Discuss] 19,000 person company passwords stolen via HTTPS
- From: richard.pieri at gmail.com (Rich Pieri)
- Date: Tue, 6 Oct 2015 19:19:20 -0400
- In-reply-to: <BLUPR04MB36986C34B8A2EDA4C94DE55DC370@BLUPR04MB369.namprd04.prod.outlook.com>
- References: <BLUPR04MB369931CAF23BF8AD78B3003DC370@BLUPR04MB369.namprd04.prod.outlook.com> <5613E03B.5060900@gmail.com> <06D81B5F-E028-467A-8CCC-96B5AE1F2D6C@gmail.com> <BLUPR04MB36986C34B8A2EDA4C94DE55DC370@BLUPR04MB369.namprd04.prod.outlook.com>
On 10/6/2015 5:12 PM, Edward Ned Harvey (blu) wrote: > I have no idea what RP was talking about, or if there was a point at > all, but Anthony, you're right. I know in CBCrypt, there is no basket > with all the eggs. Yes, there is. The authenticating server has a piece of information for each user which can be used to uniquely identify that user. Encrypting these unique pieces of information, these eggs, does not prevent me from cracking them open. It slows me down but it won't keep me out. The point is that this paradigm is broken, backwards. It's /etc/passwd in fancy dress. Users and clients should not be authenticating themselves to servers and services. Servers and services should be authenticating themselves to the users and clients which use them. -- Rich P.
- References:
- [Discuss] 19,000 person company passwords stolen via HTTPS
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- [Discuss] 19,000 person company passwords stolen via HTTPS
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] 19,000 person company passwords stolen via HTTPS
- From: agabriel2 at gmail.com (Dr. Anthony Gabrielson)
- [Discuss] 19,000 person company passwords stolen via HTTPS
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- [Discuss] 19,000 person company passwords stolen via HTTPS
- Prev by Date: [Discuss] 19,000 person company passwords stolen via HTTPS
- Next by Date: [Discuss] 19,000 person company passwords stolen via HTTPS
- Previous by thread: [Discuss] 19,000 person company passwords stolen via HTTPS
- Next by thread: [Discuss] 19,000 person company passwords stolen via HTTPS
- Index(es):