4 ms·
And also "Passwords don't matter as long as you aren't important enough or connected to a person or organization important enough to try more than the most rout
by padobson 7y ago
And also "Passwords don't matter as long as you aren't important enough or connected to a person or organization important enough to try more than the most routine password vulnerabilities"
- mikekchar 7y agoThat would be a shocking statement to make. However, I don't see anything like that in the original article. Did I miss it somewhere?
- H8crilA 7y agoYes for example in password spray - attackers often try just < 20 passwords. If your account is high value they could try a lot more.
- mikekchar 7y agoBut the original article literally never says that. It doesn't talk about the "value" of different kinds of accounts at all (and I just reread the "Spray" section to make sure I didn't miss it). It would be incredibly naive to think that one account has significantly more value than another because once you are in the system, your ability to compromise it skyrockets -- no matter what kind of account you have. Sure, you're probably trying to work your way up to administrative account level, but there are so many more local attacks than remote attacks that it isn't even funny. I'm not sure there is an accusation that the article is being naive in this way or not (there seems to be some confusion). It would be really shocking to see a blog post from Microsoft talking about security that would say something so naive. But as far as I can tell, they didn't.
- padobson 7y agoFrom the third paragraph: That’s a key difference between hypothetical and practical security – your attacker will only do really wacky, creative stuff you hear about at conferences (or wherever) when there’s no easier way and the target of the attack justifies the extra effort. Emphasis mine.