Friday, December 7, 2012

md5crypt() no longer suitable for production use?

A 25-GPU clustered password-cracking computer has passed a new threshold in brute-force guessing, apparently making weaker password algorithms (like LM and NTLM) obsolete.  This has prompted Poul-Henning Kamp, creator of md5crypt() to state that it's not suitable for production use.

What does this mean?  Unfortunately I don't know, but will keep my eyes out.

Perry

No comments: