<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: ElcomSoft Discovers Most of Its Customers Want Stricter Security Policies but Won’t Bother Changing Default Passwords</title>
	<atom:link href="http://blog.crackpassword.com/2012/02/elcomsoft-discovers-most-of-its-customers-want-stricter-security-policies-but-won%E2%80%99t-bother-changing-default-passwords/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.crackpassword.com/2012/02/elcomsoft-discovers-most-of-its-customers-want-stricter-security-policies-but-won%e2%80%99t-bother-changing-default-passwords/</link>
	<description>«...This blog is about &#60;a href=&#34;/?s=password+recovery&#34;&#62;cracking passwords&#60;/a&#62;, &#60;a href=&#34;/?s=forensic&#34;&#62;forensics solutions&#60;/a&#62;,&#60;br&#62;&#60;a href=&#34;/?s=security&#34;&#62;computer and network security&#60;/a&#62;, &#60;a href=&#34;/?s=system+recovery&#34;&#62;system recovery&#60;/a&#62; and other things...»</description>
	<lastBuildDate>Fri, 26 Apr 2013 14:47:50 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: Olga Koksharova</title>
		<link>http://blog.crackpassword.com/2012/02/elcomsoft-discovers-most-of-its-customers-want-stricter-security-policies-but-won%e2%80%99t-bother-changing-default-passwords/comment-page-1/#comment-27780</link>
		<dc:creator>Olga Koksharova</dc:creator>
		<pubDate>Fri, 24 Feb 2012 12:11:35 +0000</pubDate>
		<guid isPermaLink="false">http://blog.crackpassword.com/?p=1961#comment-27780</guid>
		<description><![CDATA[Default passwords seem to be a real problem, so here is our advice. Do not use default passwords, as it&#039;s dangerous, even if they are complex, simply because lists of such passwords are easily found in the Internet - for many different systems and applications. A really strong password should be not only long and complex, it should be unique (of course, there are many other factors such as changing the password on a regular basis; performing password/security audit etc - in other words, a good password policy).

Default passwords are also easily checked by bots and automated scripts: they usually have built-in wordlists that always contain default passwords - to be checked first. The other &#039;dictionary&#039; words follow; but remember the weakest link principle.

After all, default settings are always bad. That&#039;s not only about passwords. Another good example is SSID. With WPA/WPA2, the SSID is added to the password before hashing, so working like a &#039;salt&#039;. But for most common SSIDs (all manufacturs have their own favorite ones), effective rainbow tables can be created.]]></description>
		<content:encoded><![CDATA[<p>Default passwords seem to be a real problem, so here is our advice. Do not use default passwords, as it&#8217;s dangerous, even if they are complex, simply because lists of such passwords are easily found in the Internet &#8211; for many different systems and applications. A really strong password should be not only long and complex, it should be unique (of course, there are many other factors such as changing the password on a regular basis; performing password/security audit etc &#8211; in other words, a good password policy).</p>
<p>Default passwords are also easily checked by bots and automated scripts: they usually have built-in wordlists that always contain default passwords &#8211; to be checked first. The other &#8216;dictionary&#8217; words follow; but remember the weakest link principle.</p>
<p>After all, default settings are always bad. That&#8217;s not only about passwords. Another good example is SSID. With WPA/WPA2, the SSID is added to the password before hashing, so working like a &#8216;salt&#8217;. But for most common SSIDs (all manufacturs have their own favorite ones), effective rainbow tables can be created.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
