[cryptography] Data breach at IEEE.org: 100k plaintext passwords.

2012-09-25 Thread Jeffrey Walton
In case anyone on the list might be affected... [Please note: I am not the "I' in the text below] http://ieeelog.com IEEE and the log story IEEE (Institute of Electrical and Electronics Engineers) is renowned as one of the world-leading organizations in standard development and the promotion of

Re: [cryptography] Data breach at IEEE.org: 100k plaintext passwords.

2012-09-25 Thread Kevin W. Wall
-kevin Sent from my Droid; please excuse typos. On Sep 25, 2012 1:39 PM, "Jeffrey Walton" wrote: > > In case anyone on the list might be affected... [Please note: I am not > the "I' in the text below] > > http://ieeelog.com For shame. This should make for a "nice" article in a future _IEEE Securi

Re: [cryptography] Data breach at IEEE.org: 100k plaintext passwords.

2012-09-25 Thread Steven Bellovin
On Sep 25, 2012, at 1:47 PM, Kevin W. Wall wrote: > > -kevin > Sent from my Droid; please excuse typos. > On Sep 25, 2012 1:39 PM, "Jeffrey Walton" wrote: > > > > In case anyone on the list might be affected... [Please note: I am not > > the "I' in the text below] > > > > http://ieeelog.com >

Re: [cryptography] Data breach at IEEE.org: 100k plaintext passwords.

2012-09-25 Thread Patrick Mylund Nielsen
It's interesting how the level of technical expertise of an organization's members seems to have almost no bearing on how sophisticated the organization's infrastructure is. On a related note, I was recently surprised to learn that even the IACR stores passwords in plain text. On Tue, Sep 25, 201

Re: [cryptography] Data breach at IEEE.org: 100k plaintext passwords.

2012-09-25 Thread Jeffrey Walton
On Tue, Sep 25, 2012 at 2:35 PM, Patrick Mylund Nielsen wrote: > It's interesting how the level of technical expertise of an organization's > members seems to have almost no bearing on how sophisticated the > organization's infrastructure is. > > On a related note, I was recently surprised to lear

Re: [cryptography] Data breach at IEEE.org: 100k plaintext passwords.

2012-09-25 Thread Kevin W. Wall
I'm thinking the IEEE should pick up the membership dues for 2013 for all those 100k users. :-p -kevin Sent from my Droid; please excuse typos. ___ cryptography mailing list cryptography@randombit.net http://lists.randombit.net/mailman/listinfo/cryptogra

Re: [cryptography] Data breach at IEEE.org: 100k plaintext passwords.

2012-09-25 Thread Peter Thoenen
>It's interesting how the level of technical expertise of an organization's >members seems to have almost no bearing on how sophisticated the >organization's infrastructure is. Speaking as a long time internal and external IT auditor I would suggest there is a bearing and it's inverted once you

Re: [cryptography] Data breach at IEEE.org: 100k plaintext passwords.

2012-09-25 Thread James A. Donald
-- On 2012-09-26 7:26 AM, Peter Thoenen wrote: > Speaking as a long time internal and external IT auditor I > would suggest there is a bearing and it's inverted once you > exceed a certain organizational size and discount the > outliers (mom&pops on the low end, national security > systems on

Re: [cryptography] Compression Attack on SSL

2012-09-25 Thread Thai Duong
We just published the slides that we use for ekoparty 2012 at https://docs.google.com/presentation/d/11eBmGiHbYcHR9gL5nDyZChu_-lCa2GizeuOfaLU2HOU/preview?sle=true#slide=id.g1e3070b2_1_30 . Cheers, Thai. >- When did FF disable this? I went looking in the diffs but couldn't find it =/ On Tue,

Re: [cryptography] Data breach at IEEE.org: 100k plaintext passwords.

2012-09-25 Thread dan
>It's interesting how the level of technical expertise of an >organization's members seems to have almost no bearing on how >sophisticated the organization's infrastructure is. A person is smart. People are dumb. -- Kay ___ cryptography mailing lis