*BSD News Article 72169


Return to BSD News archive

Path: euryale.cc.adfa.oz.au!newshost.anu.edu.au!harbinger.cc.monash.edu.au!nntp.coast.net!howland.reston.ans.net!Germany.EU.net!Dortmund.Germany.EU.net!interface-business.de!usenet
From: j@ida.interface-business.de (J Wunsch)
Newsgroups: comp.unix.admin,comp.unix.bsd.bsdi.misc,comp.unix.bsd.freebsd.misc,comp.unix.bsd.misc
Subject: Re: DES worses MD5 password file
Date: 27 Jun 1996 11:18:38 GMT
Organization: interface business GmbH, Dresden
Lines: 16
Message-ID: <4qtqme$h3k@innocence.interface-business.de>
References: <4qhuas$m6o@news.idt.net> <4qs2ff$b1f@cynic.portal.ca>
Reply-To: joerg_wunsch@interface-business.de (Joerg Wunsch)
NNTP-Posting-Host: ida.interface-business.de
X-Newsreader: knews 0.9.6
X-Phone: +49-351-31809-14
X-Fax: +49-351-3361187
X-PGP-Fingerprint: DC 47 E6 E4 FF A6 E9 8F  93 21 E0 7D F9 12 D6 4E
Xref: euryale.cc.adfa.oz.au comp.unix.admin:44150 comp.unix.bsd.bsdi.misc:4162 comp.unix.bsd.freebsd.misc:22263 comp.unix.bsd.misc:1171

curt@cynic.portal.ca (Curt Sampson) wrote:

> I think this is a good argument for using the old, crummy Unix DES
> in password files until you're absolutely sure that the system
> users are residing on is going to be the last one they'll ever
> reside on.

Convince your government(s) about this first.  Remember that it hasn't
really been the stronger MD5 algorithm alone that forced FreeBSD to
pick a non-DES password encryption algorithm in the first place, but
rather the braindead policy of the US government.

-- 
J"org Wunsch					       Unix support engineer
joerg_wunsch@interface-business.de       http://www.interface-business.de/~j