Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> I don't think this is misinformation. You would be surprised at the number of IT people who have no clue how fast NTLM hashes can be brute-forced. Spreading this knowledge is good.

That's just depressing, considering how long this has been a problem.

Advice has been, for many years, to avoid using passwords 14 chars or less to force use of NTLMv2.

Here's a Microsoft document from 2004: (http://www.windowsecurity.com/articles/Protect-Weak-Authenti...)

> You would be surprised at the number of IT people who have no clue [...]

No, you're right. It's widespread lack of knowledge, and letting people know that some stuff is not secure, and other stuff is more secure if you have a complex passphrase, is important.



Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: