> I don't think this is misinformation. You would be surprised at the number of IT people who have no clue how fast NTLM hashes can be brute-forced. Spreading this knowledge is good.
That's just depressing, considering how long this has been a problem.
Advice has been, for many years, to avoid using passwords 14 chars or less to force use of NTLMv2.
> You would be surprised at the number of IT people who have no clue [...]
No, you're right. It's widespread lack of knowledge, and letting people know that some stuff is not secure, and other stuff is more secure if you have a complex passphrase, is important.
That's just depressing, considering how long this has been a problem.
Advice has been, for many years, to avoid using passwords 14 chars or less to force use of NTLMv2.
Here's a Microsoft document from 2004: (http://www.windowsecurity.com/articles/Protect-Weak-Authenti...)
> You would be surprised at the number of IT people who have no clue [...]
No, you're right. It's widespread lack of knowledge, and letting people know that some stuff is not secure, and other stuff is more secure if you have a complex passphrase, is important.