1998-10-30 - Coersion Re: don’t use passwords as private keys (was Re: Using a password as a private key.)

Header Data

From: Richard.Bragg@ssa.co.uk
To: redrook@yahoo.com
Message Hash: 73c562aa3f3729eb5293ab27382d06af0de50e5206e462301a905e231e80ffe9
Message ID: <802566AD.00420227.00@seunt002e.ssa.co.uk>
Reply To: N/A
UTC Datetime: 1998-10-30 13:13:46 UTC
Raw Date: Fri, 30 Oct 1998 21:13:46 +0800

Raw message

From: Richard.Bragg@ssa.co.uk
Date: Fri, 30 Oct 1998 21:13:46 +0800
To: redrook@yahoo.com
Subject: Coersion Re: don't use passwords as private keys (was Re: Using a password as a private key.)
Message-ID: <802566AD.00420227.00@seunt002e.ssa.co.uk>
MIME-Version: 1.0
Content-Type: text/plain



>From information given by a security consultant teaching a course I
attended :

The easiest way to get a password from someone is to ask them.  Many people
will tell you if you look official, friendly etc

Torture is less likely to work as people don't like to have to do
something.  They are often willing to "volenteer" information as long as
they still appear to be in control.







Thread