ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    The NIST Finally Formally Chooses SAM Security Model for Passwords

    Scheduled Pinned Locked Moved News
    nistsecurity
    14 Posts 6 Posters 1.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • JaredBuschJ
      JaredBusch @Dashrender
      last edited by

      @dashrender said in The NIST Finally Formally Chooses SAM Security Model for Passwords:

      Could have sworn I posted about this weeks ago. 😉

      You did, but you didn't claim that NIST followed your recommendation.

      scottalanmillerS 1 Reply Last reply Reply Quote 2
      • scottalanmillerS
        scottalanmiller @JaredBusch
        last edited by

        @jaredbusch said in The NIST Finally Formally Chooses SAM Security Model for Passwords:

        @dashrender said in The NIST Finally Formally Chooses SAM Security Model for Passwords:

        Could have sworn I posted about this weeks ago. 😉

        You did, but you didn't claim that NIST followed your recommendation.

        I only said that they mirrored it, not followed it. Not quite the same.

        1 Reply Last reply Reply Quote 0
        • gjacobseG
          gjacobse
          last edited by

          just found this:

          Man who came up with rules for creating passwords says he blew it

          DashrenderD 1 Reply Last reply Reply Quote 2
          • DashrenderD
            Dashrender @gjacobse
            last edited by

            @gjacobse said in The NIST Finally Formally Chooses SAM Security Model for Passwords:

            just found this:

            Man who came up with rules for creating passwords says he blew it

            During the interview, Burr also admitted that he didn't know much about how passwords worked when he created the memo.

            WTF are you doing making a memo then? Not that we probably really understood the potential issues at that point, but still.

            DustinB3403D scottalanmillerS 2 Replies Last reply Reply Quote 0
            • DustinB3403D
              DustinB3403 @Dashrender
              last edited by

              @dashrender said in The NIST Finally Formally Chooses SAM Security Model for Passwords:

              @gjacobse said in The NIST Finally Formally Chooses SAM Security Model for Passwords:

              just found this:

              Man who came up with rules for creating passwords says he blew it

              During the interview, Burr also admitted that he didn't know much about how passwords worked when he created the memo.

              WTF are you doing making a memo then? Not that we probably really understood the potential issues at that point, but still.

              Because he was fucking paid to write the memo. Do what you're told or find a new job.

              Obviously.

              DashrenderD 1 Reply Last reply Reply Quote 0
              • DashrenderD
                Dashrender @DustinB3403
                last edited by

                @dustinb3403 said in The NIST Finally Formally Chooses SAM Security Model for Passwords:

                @dashrender said in The NIST Finally Formally Chooses SAM Security Model for Passwords:

                @gjacobse said in The NIST Finally Formally Chooses SAM Security Model for Passwords:

                just found this:

                Man who came up with rules for creating passwords says he blew it

                During the interview, Burr also admitted that he didn't know much about how passwords worked when he created the memo.

                WTF are you doing making a memo then? Not that we probably really understood the potential issues at that point, but still.

                Because he was fucking paid to write the memo. Do what you're told or find a new job.

                Obviously.

                Yeah - more govment meaningless crap! 🙂

                1 Reply Last reply Reply Quote 0
                • scottalanmillerS
                  scottalanmiller @Dashrender
                  last edited by

                  @dashrender said in The NIST Finally Formally Chooses SAM Security Model for Passwords:

                  @gjacobse said in The NIST Finally Formally Chooses SAM Security Model for Passwords:

                  just found this:

                  Man who came up with rules for creating passwords says he blew it

                  During the interview, Burr also admitted that he didn't know much about how passwords worked when he created the memo.

                  WTF are you doing making a memo then? Not that we probably really understood the potential issues at that point, but still.

                  We all knew whoever did it didn't know the first thing about passwords. But why the NIST let him make it... that's the real question.

                  DustinB3403D DashrenderD 2 Replies Last reply Reply Quote 1
                  • DustinB3403D
                    DustinB3403 @scottalanmiller
                    last edited by

                    @scottalanmiller is that really the question.

                    More importantly why does it fucking matter. It was written so long ago and there has been plenty of time and evidence that what was written down was complete bullshit.

                    scottalanmillerS 1 Reply Last reply Reply Quote 0
                    • DashrenderD
                      Dashrender @scottalanmiller
                      last edited by

                      @scottalanmiller said in The NIST Finally Formally Chooses SAM Security Model for Passwords:

                      @dashrender said in The NIST Finally Formally Chooses SAM Security Model for Passwords:

                      @gjacobse said in The NIST Finally Formally Chooses SAM Security Model for Passwords:

                      just found this:

                      Man who came up with rules for creating passwords says he blew it

                      During the interview, Burr also admitted that he didn't know much about how passwords worked when he created the memo.

                      WTF are you doing making a memo then? Not that we probably really understood the potential issues at that point, but still.

                      We all knew whoever did it didn't know the first thing about passwords. But why the NIST let him make it... that's the real question.

                      this was my real question...

                      1 Reply Last reply Reply Quote 0
                      • scottalanmillerS
                        scottalanmiller @DustinB3403
                        last edited by

                        @dustinb3403 said in The NIST Finally Formally Chooses SAM Security Model for Passwords:

                        @scottalanmiller is that really the question.

                        More importantly why does it fucking matter. It was written so long ago and there has been plenty of time and evidence that what was written down was complete bullshit.

                        Except they new it was BS in 2003, too.

                        1 Reply Last reply Reply Quote 2
                        • 1 / 1
                        • First post
                          Last post