| Oracle FAQ | Your Portal to the Oracle Knowledge Grid | |
Home -> Community -> Usenet -> c.d.o.server -> Re: Does oracle provide encryption function??
Connor McDonald <connor_mcdonald_at_yahoo.com> writes:
>
> This opens up security problems in the same way that Unix had (with
> freeware such as 'crack') before people started using things that shadow
> files etc.
To be clear, he's referring to users using predictable passwords. In this scheme it allows offline attacks against the passwords, which if they're guessable eventually lets the attacker crack it without raising any alarms.
It's not clear shadow password files or anything like that really helps much. Using a better hash helps, and barring guessable passwords helps, but if the passwords guessable offline it's likely guessable online just as well.
--
greg
Received on Thu Feb 10 2000 - 03:34:50 CST
![]() |
![]() |