3 ms·
> Are there any good sources on what sort of generative trickery a good cracking tool will use? Two answers: 1) It's not worth trying to keep up with, unless
by hackuser 10y ago
> Are there any good sources on what sort of generative trickery a good cracking tool will use?
Two answers:
1) It's not worth trying to keep up with, unless that's your specialty. There are people who spend days thinking up attacks; how much time will you need to spend to keep up with them?
Far more time-effective than trying to anticipate all the specific attacks is to use provably secure defenses: Passwords that are mathematically too expensive to brute force, and which cannot be guessed by other means (e.g., by knowing personal information about you). That shifts the weak link from your password to the security of your OS, network, and applications, which probably have a couple of holes in them.
2) This will give you an idea of the scope of possible attacks. Note that it's 9 years old: https://www.schneier.com/blog/archives/2007/01/choosing_secure.html https://www.schneier.com/blog/archives/2007/01/choosing_secu...