Relay-Version: version B 2.10 5/3/83; site utzoo.UUCP Path: utzoo!watmath!clyde!rutgers!princeton!allegra!ulysses!ucbvax!JPL-VLSI.ARPA!tencati From: tencati@JPL-VLSI.ARPA.UUCP Newsgroups: mod.computers.vax Subject: re: password verification... Message-ID: <870202103821.088@Jpl-VLSI.ARPA> Date: Mon, 2-Feb-87 13:38:21 EST Article-I.D.: Jpl-VLSI.870202103821.088 Posted: Mon Feb 2 13:38:21 1987 Date-Received: Wed, 4-Feb-87 01:38:00 EST Sender: daemon@ucbvax.BERKELEY.EDU Organization: The ARPA Internet Lines: 14 Approved: info-vax@sri-kl.arpa Please be careful about publishing code that encrypts passwords using the same formula DEC uses... These code fragments can fall into the hands of hackers who can then build "password-guessers" that will get around VMS security since there is now no way to catch "logfails". I know the module in and of itself is useful, but this list is *widely* read, and I think a little caution should be exercised in the distribution of such software. Ron Tencati System Mgr, JPL-VLSI.ARPA Jet Propulsion Laboratory 4800 Oak Grove Drive Pasadena, Ca. 91109