[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: root via ssh / why su - ?



On Mon, May 28, 2001 at 09:18:17PM +1000, Brian May wrote:
> (Just a thought: perhaps a better solution would be to store these
> passwords on a computer file, but GPG encrypt them?)

If you've got a PalmPilot, etc., there's a wonderful utility called STRIP
(Secure Tool for Remembering Important Passwords) that does just this.  It
stores and categorizes passwords in an encrypted (either DES or IDEA,
depending on which version you download) database.

It will also generate passwords for you, but there was a bug discovered
about a month and a half ago which results in it only having 64k available
random number seeds, making STRIP-generated passwords very vulnerable to a
modified dictionary attack.  I'm not sure whether this has been fixed yet.

-- 
That's not gibberish...  It's Linux. - Byers, The Lone Gunmen
Geek Code 3.12:  GCS d? s+: a C++ UL++++$ P++>+++ L+++>++++ E- W--(++) N+
o+ !K w--- O M- V? PS+ PE Y+ PGP t 5++ X+ R++ tv+ b+ DI++++ D G e* h r y+



Reply to: