On Fri, 10 May 2019 00:24:18 -0400, Bob Bridges <robhbrid...@gmail.com> wrote:

>The lesson I take from this, and pass on to
>my clients, is that read access to the security database is a huge exposure
>and in most cases - that is, for most user IDs - completely unnecessary.
>

Doesn't the KDFAES password encryption algorithm make it *much* more difficult 
to crack passwords,  given access to the RACF database?  I realize nothing is 
impossible to crack.. but at least not currently feasible with current 
available hardware.

Dana

----------------------------------------------------------------------
For IBM-MAIN subscribe / signoff / archive access instructions,
send email to lists...@listserv.ua.edu with the message: INFO IBM-MAIN

Reply via email to