[aklug] Re: Also surprising

From: Christopher Howard <choward@indicium.us>
Date: Tue Dec 08 2009 - 16:31:46 AKST

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

barsalou wrote:
> I saw this article on slashdot as well:
>
> http://it.slashdot.org/story/09/12/07/2322235/WPA-PSK-Cracking-As-a-Service
>
> The interesting parts of this to me are two fold:
>
> - Do I want to be submitting my passwords to a service that might
> capture them and add them to the "dictionary"?
>
> - The potentially reduces the whole idea that it would take someone
> too long to crack a password with a certain key strength argument.
>
> I'm not an expert in this area, so my perceptions of the last issue
> may be flawed.
>
> Mike B.
>
> ----------------------------------------------------------------
> This message was sent using IMP, the Internet Messaging Program.
>
> ---------
> To unsubscribe, send email to <aklug-request@aklug.org>
> with 'unsubscribe' in the message body.
>

I liked one of the comments to the article:

"No 'random' data that you get from the net should be trusted. I throw
old 16-sided gaming dice to generate a transparent X-Y grid, which is
then set over the top of my cat's litter box. The positions of the cat
turds are normalized against a reference litter box and fed into a fancy
matrix algorithm, the output of which is SHA4 hashed and truncated to
make the WPA2 key."

I'm going to ask my prof if he is ever heard of that approach.

- --
Christopher Howard
http://indicium.us
http://theologia.indicium.us
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.11 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iEYEARECAAYFAkse/gIACgkQQ5FLNdi0BcW1IACeMxwR8//weadjqyLxijWTWkMy
EqoAn3MUJ/aMI1fAy7v/X9G85jsd7d1N
=jea4
-----END PGP SIGNATURE-----
---------
To unsubscribe, send email to <aklug-request@aklug.org>
with 'unsubscribe' in the message body.
Received on Tue Dec 8 16:33:31 2009

This archive was generated by hypermail 2.1.8 : Tue Dec 08 2009 - 16:33:31 AKST