4 ms·
Not really clever. Format strings have a fairly restricted format; that one can't have all that many bits of entropy. Once the obfuscation method occurred to an
by captaincrowbar 11y ago
Not really clever. Format strings have a fairly restricted format; that one can't have all that many bits of entropy. Once the obfuscation method occurred to an attacker, it wouldn't take long to brute force it even if they didn't have a file to search for suggestions. (And now that the idea is out there, I bet any number of hackers, wearing assorted coloured hats, are trying this out on other systems Even As We Speak.)
- w-ll 11y agomost attkers bruteforce common string passwords. Even if i had a binary to run strings thru this would pass by me. Not that im super smart or clever, but this is a interesting camouflage.
- tajen 11y agoThe goal is to weaken security and open a breach. Even a boolean would have been satisfying as a password.
- IshKebab 11y agoWhy would obfuscation method randomly occur to the attacker? It wouldn't. You'd only realise by looking at the code and at that point you have the password anyway.
- qb45 11y ago> Not really clever. Format strings have a fairly restricted format; that one can't have all that many bits of entropy. I fully agree that now is a great time to brute-force every ssh server found on the Internet with randomly generated valid format strings. However, did you know it before this password was published? I think it was a novel idea.