Posted by feross 3 days ago
The attack is, guess a password, hash it, and attempt to decrypt.
With AES Kerberos keys there is a salt... but not a good one. It is just the domain (realm) and the username.
Their ubiquitous systems have been notoriously insecure for decades.
They are one of the highest revenue firms on the planet.
It is going to take strict liability for software developers before we all pull up our socks and put an end to this nonsense. When it is a marketing advantage to produce insecure software, what else can fix our industry?
I despair
Their ubiquitous systems have been notoriously insecure for decades.
They are one of the highest revenue firms on the planet.
It is going to take strict liability for software developers before we all pull up oursocks and put an end to this nonsense. When it is a marketing advantage to produce insecure software, what else can fix our industry?
I despair
Did he not get the memo that this is not allowed?