John Gardiner Myers <[EMAIL PROTECTED]> wrote (in response to mpb):

mpb> NB: AFS passwords from your kaserver(s) are never presented by "ypcat".

jgm> However, they are no less vulnerable to externally mounted dictionary
jgm> attacks.

Yes, but a modicum less trivial than the "NIS ypcat passwd crack" attack.
Given that kpwvalid is easily spoofed, what do other sites do about AFS
password "quality checking"?
--
paul                             http://acm.org/~mpb

Reply via email to