New Blast-RADIUS attack breaks 30-year-old protocol used in networks everywhere
arstechnica.com
arstechnica.com
IDK About anyone else but for a very long time anything md5 has been in the same mental bucket as zip or office documents passwords.. a discouragement for the casual user and accidental exposure but not actually secure against any kind of determined attack. ( the accuracy of my mental buckets is perhaps a separate issue )
Although I suppose lots of deployments still go with whatever lowest friction, so maybe lots?
Perhaps it doesn't matter to the health of your network, but if it leads to a customer's account being disabled due to incorrectly assigned abuse, surely it would matter to them.
(57 points, 3 days ago, 7 comments) https://news.ycombinator.com/item?id=40923905
(20 points, 3 days ago) https://news.ycombinator.com/item?id=40919644