[sldev] [POLICY] Development by consensus (Re: Question regarding upcoming maintenance on 11/27-

Callum Lerwick seg at haxxed.com
Wed Nov 28 02:46:57 PST 2007


On Wed, 2007-11-28 at 09:47 +0000, Matthew Dowd wrote:
> Of course, hashing is of limited protection if someone has grabbed the
> backend database, as they are now in a position to run large scale
> dictionary attacks on the hashes at their leisure on their own
> equipment!

Which requires time. Time enough to detect the intrusion and reset
everyone's  password, instantly invalidating the stolen database.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: This is a digitally signed message part
Url : http://lists.secondlife.com/pipermail/sldev/attachments/20071128/79fe19e3/attachment.pgp


More information about the SLDev mailing list