17 Dec
2003
17 Dec
'03
11:17 p.m.
Joel McNamara wrote: | Peter Gutmann has an interesting article in sci.crypt, demonstrating how | weak Microsoft's encryption is with basic access control in Windows for | Workgroups (I'm assuming Win95 uses the same algorithm). Essentially, he | shows how a 32-bit key is created to be passed to RC4 for encrypting .PWL | files. I think a t-shirt is definitely in order for this. While Peter did a nice job of showing how Windows stores passwords, my understanding is that those passwords are decrypted by Windows, and sent over the net in the clear. Seems much easier to snarf them there.. Adam -- "It is seldom that liberty of any kind is lost all at once." -Hume