Re: XDM has the same problem as netscape ?!
17 Dec
2003
17 Dec
'03
11:17 p.m.
Ian Goldberg wrote:
Nelson Minar <nelson@santafe.edu> wrote:
Last time I looked, the MIT-MAGIC-COOKIE-1 scheme used in X11R4 had the same problem: the random seed was based on the current time to the microsecond, modulo the granularity of the system clock. I think I figured that on my hardware, if I could figure out which minute the X server started (easy with finger), I'd only have to try a few thousand keys or so. Caveat: I never actually proved the idea.
Wow. I just checked, and Nelson's right. [ code extracts snipped]
I just checked X11R6, and the same method is used there, so it hasn't changed since X11R4. -Arve.
8179
Age (days ago)
8179
Last active (days ago)
0 comments
1 participants
participants (1)
-
Arve Kjoelen