Re: authmeth: removal of DIGEST-MD5

Hallvard B Furuseth <[email protected]> Thu, 13 Oct 2005 22:27:46 +0200
Newsgroups gmane.ietf.ldapbis
Message-ID <[email protected]>
Kurt D. Zeilenga writes:
> I note that while CRAM-MD5 and DIGEST-MD5 don't expose the
> actual password, they do expose a hash of that password that
> is quite prone to offline dictionary attacks.  I'd argue
> that you need to be just as careful as to whom you give
> that hash to as you are giving out the actual password.

Or not use passwords that resemble words in dictionaries?

Keep in mind that Unix DES crypt is still in use, though...

-- 
Hallvard