this is dumb as hell.
cybersecurity
An umbrella community for all things cybersecurity / infosec. News, research, questions, are all welcome!
Community Rules
- Be kind
- Limit promotional activities
- Non-cybersecurity posts should be redirected to other communities within infosec.pub.
Enjoy!
Oh, AI has nothing to do with it. It grabs the RockYou password list and guesses a password based on frequency of use.
This is nothing new.
If they want to do something actually impressive how fast can they crack sha256 hashed passwords without rainbow tables. I will let them off and not require any salting.
Here is the thing, does the corporate entity you work with use Microsoft? Then your password is stored as an NTLM hash in NTDS.dit. That means you are using MD4.
Has anyone in your organization clicked a phishing link? It only takes one weak link to get in. Then it only takes one (Maybe 2) bad configuration for a malicious actor to escalate privileges. Then dump the whole organization passwords from the Domain Controller.
Hope you aren't reusing passwords anywhere.
We are all running password less with passkeys so our Entra passwords are all 128 length randomised that even we don't know because why should we?
Corporate phishing tests are a joke, you can bypass them by filtering for Phishme or kb4 in the email header.
I still don't really understand what passkeys are since I've only ever been introduced to them by companies like Google and Microsoft. Are there any open source implementations of passkeys?
Also, why does no one ever recommend SSH keys, or GPG keys as an alternative method?