Security Basics mailing list archives

Re: password cracking: one char at a time.


From: Kurt Buff <kurt.buff () gmail com>
Date: Mon, 21 Nov 2005 11:15:42 -0800

michael young wrote:
Hi all,
   I was wondering if is at all possible to discover a password one char
at a time.
Normally, you either get the password right or wrong (all or nothing).
Does anyone know if this can be done? Does it depend on the encryption
algorithm
used to encrypt the password? Is that a difference for 1 and/or 2 way
passwords?

thank you,
Michael

This is the kind of attack that any reasonable password protection
scheme is designed to foil.

In particular, I remember that the design goal of one encryption
algorithm was to be such that if a single charcter of the input changed,
fifty percent of the output changed, or something to that effect.

Kurt


Current thread: