[46735] in Cypherpunks

home help back first fref pref prev next nref lref last post

Info on new MS "Password-Caching" algorithm?

daemon@ATHENA.MIT.EDU (Rich Graves)
Sun Jan 7 20:35:58 1996

Date: Sun, 7 Jan 1996 17:25:23 -0800 (PST)
From: Rich Graves <llurch@networking.stanford.edu>
To: cypherpunks@toad.com

-----BEGIN PGP SIGNED MESSAGE-----

Happy St. Ogelthorpe's Day.

On December 14th (they say December 13th), Microsoft released an
executable that is supposed to replace the bit of Windows 95 that by
default stores all local and network passwords in clearly labeled .PWL
files encrypted according to an algorithm similar to the ultra-secure
ROT-13. See http://www.windows.microsoft.com/pr/clarifications.htm for 
Microsoft's PR spin and http://www.c2.org/hackmsoft/ for accurate 
information. The issue was first broached on the win95netbugs list on 
November 1st, and knowledgeable people (i.e., not me) started discussing 
it here on November 29th.

I was rather disappointed to discover that the .PWL bug fix patch does not
even include a ReadMe. Double-click on it and it basically says, "Trust
me, I know what I'm doing." I'm almost tempted to release a different
program with the same name. 

On December 8th, the Windows Networking Program Manager told me they'd be 
releasing the functional details for outside security review. This does 
not appear to have happened. Has anyone dug into how it works? I'll poke 
around next week (I haven't had a Windoze box to play with since the 
22nd), but I don't really know what I'm doing...

Microsoft has also not commented publicly on the fact that Windows for
Workgroups has always used the same buggy .PWL encryption method. In fact,
their "Knowledge Base" article q90210 [sic] still assures administrators
that passwords are encrypted securely on Windows for Workgroups machines,
while they've known this to be untrue for over a month. Search for
"password" on http://www-leland.stanford.edu/~llurch/win95netbugs/kb.html. 
Save the article, because they'll probably "revise" it in MSNewSpeak 
later.

I'm a bit concerned that with all the dissecting of the minutiae of
reasonable encryption software that goes on here, software that is worse
than useless is on the rise among the unwashed masses. Win95 and WFW by
default force you to enter a password for "login" to an insecure
single-user OS. That password is not stored securely. Most normal people
are using "Windows Logon" passwords that are the same or very similar to 
the passwords they use for services that are otherwise secure. This is 
not good.

And now it's another brute-force attack on Netscape's 40-bit keys, which
all of us knew was possible (we're joking about time to crack a 40-bit key
as a new benchmark), that's getting the press coverage. Something doesn't
seem right to me. 

- -rich
 owner-win95netbugs@lists.stanford.edu
 ftp://ftp.stanford.edu/pub/mailing-lists/win95netbugs/
 gopher://quixote.stanford.edu/1m/win95netbugs
 http://www-leland.stanford.edu/~llurch/win95netbugs/faq.html

-----BEGIN PGP SIGNATURE-----
Version: 2.6.2
Comment: I am not a crook. Bwahahaha.

iQCVAwUBMPBxlI3DXUbM57SdAQHc5QQAwl4dTU8hAfkFVSFFQigWWnNotBzNWiZr
Van+ZXYDmPIniPcPm+mwvQFWEyocw62SWfQeRlN0hQTm4S/K28UrGmgKsV9v7qlI
7CGUSOzMMRqPCI+TGTIT6JSmA16KmgwVBfhU7LxKYghW68K5RXPrhZS0lzG2wLiW
fCsHWXm+fPo=
=wEYO
-----END PGP SIGNATURE-----

home help back first fref pref prev next nref lref last post