4 ms·
I think the thesis of this article is rather forced. The actual claim is something like: "Passwords don't matter, as long as your password isn't in the top few
by mquander 7y ago
I think the thesis of this article is rather forced. The actual claim is something like:
"Passwords don't matter, as long as your password isn't in the top few dozen common ones, it's not in any credentials breach accessible to attackers, it's longer than 8 characters or so, and you don't reuse it."
That was a lot of criteria that seemed to matter, if you ask me.
- padobson 7y agoAnd also "Passwords don't matter as long as you aren't important enough or connected to a person or organization important enough to try more than the most routine password vulnerabilities"
- mikekchar 7y agoThat would be a shocking statement to make. However, I don't see anything like that in the original article. Did I miss it somewhere?
- H8crilA 7y agoYes for example in password spray - attackers often try just < 20 passwords. If your account is high value they could try a lot more.
- mikekchar 7y agoBut the original article literally never says that. It doesn't talk about the "value" of different kinds of accounts at all (and I just reread the "Spray" section to make sure I didn't miss it). It would be incredibly naive to think that one account has significantly more value than another because once you are in the system, your ability to compromise it skyrockets -- no matter what kind of account you have. Sure, you're probably trying to work your way up to administrative account level, but there are so many more local attacks than remote attacks that it isn't even funny. I'm not sure there is an accusation that the article is being naive in this way or not (there seems to be some confusion). It would be really shocking to see a blog post from Microsoft talking about security that would say something so naive. But as far as I can tell, they didn't.
- padobson 7y agoFrom the third paragraph: That’s a key difference between hypothetical and practical security – your attacker will only do really wacky, creative stuff you hear about at conferences (or wherever) when there’s no easier way and the target of the attack justifies the extra effort. Emphasis mine.
- kerng 7y agoThere is some very bad analysis or interpretation done here. Just with one or two minor tweaks the analysis falls flat. For instance, they seem to only look at mass scale script kiddie sprays, a targeted attack will likely not use the mentioned passwords. As one can come up with much better and more likely to succeed candidates. It also entirely misses attacks that come from a more privileged position (like in Windows directly authenticating to the domain controller) where an adversary can do millions of attempts in short time because of typical monitoring gaps.