Community discussions

MikroTik App
 
User avatar
luqasz
Member Candidate
Member Candidate
Topic Author
Posts: 101
Joined: Thu Aug 16, 2007 9:53 pm
Location: Poland

insecure method to store passwords.

Thu Dec 08, 2011 4:06 pm

 
ayufan
Member
Member
Posts: 334
Joined: Sun Jun 03, 2007 9:35 pm
Contact:

Re: insecure method to store passwords.

Thu Dec 08, 2011 4:58 pm

Yes, we are. Problem was told many times before.
 
User avatar
luqasz
Member Candidate
Member Candidate
Topic Author
Posts: 101
Joined: Thu Aug 16, 2007 9:53 pm
Location: Poland

Re: insecure method to store passwords.

Thu Dec 08, 2011 7:07 pm

and ? any official statement ?
 
User avatar
normis
MikroTik Support
MikroTik Support
Posts: 26385
Joined: Fri May 28, 2004 11:04 am
Location: Riga, Latvia

Re: insecure method to store passwords.

Fri Dec 09, 2011 10:09 am

1. don't give your router to somebody who will hack it. lock it away from public.
2. keep backup files safe

given enough time, any encryption can be cracked. so use also other methods of protection.
 
ayufan
Member
Member
Posts: 334
Joined: Sun Jun 03, 2007 9:35 pm
Contact:

Re: insecure method to store passwords.

Fri Dec 09, 2011 11:24 am

given enough time, any encryption can be cracked. so use also other methods of protection.
normis you're funny ;) how can you say that passwords in routeros are encrypted? no they are not, if by encryption you mean simple xor, then it's not very nice...

It wonders me who in your company made such faux pas when industry standard is password hashed with some random salt.
 
User avatar
normis
MikroTik Support
MikroTik Support
Posts: 26385
Joined: Fri May 28, 2004 11:04 am
Location: Riga, Latvia

Re: insecure method to store passwords.

Fri Dec 09, 2011 11:49 am

please read my post again, because you completely missed my point. I said - why even bother encrypting it? it will just take a little more time to read. Better deal with your other security hole - why can somebody take your router and do what he pleases?

Who is online

Users browsing this forum: Amazon [Bot], marsando, rspott, vingjfg and 199 guests