Re: 2.4.22-pre7: are security issues solved?

From: Herbert Xu (herbert@gondor.apana.org.au)
Date: Wed Jul 23 2003 - 05:59:03 EST


On Wed, Jul 23, 2003 at 03:50:22AM -0700, David S. Miller wrote:
>
> > It's much smaller if you didn't know that it was at most 7 characters
> > long. However, if you did know the upper bound, or you were just
> > brute forcing all passwords starting from 1 character, then the
> > difference is relatively minor. This is because
> >
> > n + n^2 + n^3 + n^4 + n^5 + n^6
> >
> > is much smaller than n^7 where n is something like 62 for a reasonable
> > password.
>
> "7" in my example is an arbitrary number, increase it to any larger
> number you like.

Well, as m gets larger, the number

(n + n^2 + ... + n^(m-1)) / n^m

tends to 1 / (n - 1).

In other words, if you can break n^m, then you can probably break

n + n^2 + ... + n^m

Anyway, I'm not that bothered with making /proc/tty/driver root-only,
even if it is only for what seems to me to be dubious reasons.

-- 
Debian GNU/Linux 3.0 is out! ( http://www.debian.org/ )
Email:  Herbert Xu ~{PmV>HI~} <herbert@gondor.apana.org.au>
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/



This archive was generated by hypermail 2b29 : Wed Jul 23 2003 - 22:00:48 EST