Re: [cryptography] Data breach at IEEE.org: 100k plaintext passwords.

2012-09-25 Thread Kevin W. Wall
-kevin Sent from my Droid; please excuse typos. On Sep 25, 2012 1:39 PM, Jeffrey Walton noloa...@gmail.com wrote: In case anyone on the list might be affected... [Please note: I am not the I' in the text below] http://ieeelog.com For shame. This should make for a nice article in a future

Re: [cryptography] Data breach at IEEE.org: 100k plaintext passwords.

2012-09-25 Thread Steven Bellovin
On Sep 25, 2012, at 1:47 PM, Kevin W. Wall kevin.w.w...@gmail.com wrote: -kevin Sent from my Droid; please excuse typos. On Sep 25, 2012 1:39 PM, Jeffrey Walton noloa...@gmail.com wrote: In case anyone on the list might be affected... [Please note: I am not the I' in the text below]

Re: [cryptography] Data breach at IEEE.org: 100k plaintext passwords.

2012-09-25 Thread Patrick Mylund Nielsen
It's interesting how the level of technical expertise of an organization's members seems to have almost no bearing on how sophisticated the organization's infrastructure is. On a related note, I was recently surprised to learn that even the IACR stores passwords in plain text. On Tue, Sep 25,

Re: [cryptography] Data breach at IEEE.org: 100k plaintext passwords.

2012-09-25 Thread Jeffrey Walton
On Tue, Sep 25, 2012 at 2:35 PM, Patrick Mylund Nielsen cryptogra...@patrickmylund.com wrote: It's interesting how the level of technical expertise of an organization's members seems to have almost no bearing on how sophisticated the organization's infrastructure is. On a related note, I was

Re: [cryptography] Data breach at IEEE.org: 100k plaintext passwords.

2012-09-25 Thread Kevin W. Wall
I'm thinking the IEEE should pick up the membership dues for 2013 for all those 100k users. :-p -kevin Sent from my Droid; please excuse typos. ___ cryptography mailing list cryptography@randombit.net

Re: [cryptography] Data breach at IEEE.org: 100k plaintext passwords.

2012-09-25 Thread Peter Thoenen
It's interesting how the level of technical expertise of an organization's members seems to have almost no bearing on how sophisticated the organization's infrastructure is. Speaking as a long time internal and external IT auditor I would suggest there is a bearing and it's inverted once you