[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: inetd questions



On Mon, Dec 11, 2000 at 10:28:53AM -0700, Myles Green wrote:
> 
> Huh? WTF are you smoking? There's no binary stuff there, just a _good_ 
> mix of upper and lower case plus numbers and other keyboard symbols.

want to bet smart ass?

$ cat /dev/urandom | od -s8 -An
æÅãHÓà «Ï
Üäþ1èvp'­·¤Äß
WÚ¬:ÐVÂa¡S
¦FI¬Û¸¨ÌZÔÔ
rÝ:Qï0|öU¡íúC¶@
åwSßôIîxU25,\¿è¾Oçø|
ĺþ*Fãdª_<V
Y»p½>:ª¡º¨/Ýâ:u_ÇY¾ÝO
N£"XG±£5Ê+ÉÐ¥
ë·B}êúé9#ñF
[øÛÿ^µNa
RZ½4PÍgÊC¸1r»#±ÑZÀ3
V#ñ§þCRñʽÓÉð
íä/«9åø£,
6sWâ>-»Âëo
i"Ùå@qØ;ÂkéÔ>
±*¸h³¢}c
®:üУXh¨kn}¾ß2
81Îï¹@¡3
~g̬&u6~+¤&ÞòYq+ÆJó
¨r»åWN²².*
t©fÒ¶pü=¹
<åS¸6UA O5üôu¾9
<95Îw÷õu·¾S
ïóg÷¹8¬!/ToJ±÷
Ør@Öwà¹î
s¨Ú®Ã=]úGòÜÀrÒÒÛ½
ýZÒÊ[õóÁ¸j§7Ð6á!=QúX
`_~mÞJðQ
P4ÏþîÞ»GÒ?
Vº¨6}Qª§
r÷*äÇRÜMC*u¯
ïÔD:ЧKí
*¾ÍÞ»ÓÖÎNl
ÁÐø¤ßvµð
å)DªÎHFç¾
ûªäÌ:ÑîNý²
àd=¨ò\a¥@³
»&%Ûþ¶ü3¬
l¾D%0õNª4w
zâ]:þm´zr¦ædäh¯Ú
ï9v_Ê\¹Î
t.Á1ÄôáöÐ_
òÇÐBÍ¡}gfüb
;}驹QüN"ÔÔô
m <<âÏ,q¤
faÆL®ë¨¼¡hޢŸ
eý±»Y÷æ&BÁ1E¹
{ÚX[7¨ö¯6cöþݵN
º4¦ºÑMÅÄn7R¡Jhcj
ÚàǾFÅsï
Å5wð<gKæy
ª¬B6]#{©¦íÎN
¯Paá\ê&·I4
¢ÜÅã¤ÄîÝ»ç­
sêirÅè]ïSs´,2O,ÔÖ7®ÂÃsÙ
þZJLÙg`Ù
¼ÓkùÌüz¥±¦_F¹vAS
v@ät0³x!
¤ÏrÎffÔÀÕg
ä`¦¦íAؼ
owÞ{ÜXúº¢Á9®|irÅØÅÄ×
¼R)Ïñ»ÿwc¯
à­Tð´Lç^ýÁ¥
TþðäÎìnN(
ñÙ/JÐof¾:H
²ð~ùNªøëZÚè½<
6ÑBb>&¤UÇ&KM
Û`Ò®VúþÚ]
ÿ!ÐéL¥Pê
û¡<þmuy)
"æýp»GT´á!i_eyò¢±÷y
St±¯{É·0]É5è4#ê
K%ÈÍ3hyðÔÚ/Òñ
$ uname -a
Linux socrates 2.2.18 #1 Mon Dec 11 05:55:24 AKST 2000 ppc unknown

same thing happens on my intel box running 2.2.16.  

> By any standards, those will be tough passwords to crack. Of course 

they sure will since they are impossible to actually use.

> it's your box and you can use your birth date if you want, just don't 
> expect it to reamain a secret for very long.

did i say that?  no i said you can use the makepasswd package would
DOES create secure random passwords from /dev/random (NOT
/dev/urandom, so your even getting better quality entropy) 

tell what is so damn insecure about these?

$ while true ; do makepasswd --chars=12 ; done
t2nWXiWynAU8
qdesULEdwzLG
g3YfAxqxLG1d
3ozxc6aPbAi4
Ng8jBynWUwjg
U727TSua9FYW
ETgas7dp7szx
oTbAFMp1TWAJ
3LyIv5hs1Wx8
LM80L6gUmjMa
qccT163EtJpb
Gf99d7fVbuxK
UmR5oqyII19G
qAHNgbrSygg6
xYnCquo137qe
p0g1gG37jQSi
uMI8hJpufKsB
eAoqSuhG6MoG
4IgBSLf9qNI3
Q8t2zdGvJs9N
6gDj1zJwazii
JamPPfFKwCxJ

you have to actually pound the keyboard somewhere else to generate
enough entropy to get that many, unlike /dev/urandom old entropy won't
be hashed and reused.   but tell me do those look like birthdates to
you?  

-- 
Ethan Benson
http://www.alaska.net/~erbenson/

Attachment: pgplN2JysE19z.pgp
Description: PGP signature


Reply to: