in ,

Ken Thompson's Unix Password, Hacker News


Somewhere around 2014 I found an/ etc / passwdfile in some dumps of the BSD 3 source tree, containing passwords of all the old timers such as Dennis Ritchie, Ken Thompson, Brian W. Kernighan, Steve Bourne and Bill Joy.

Since the DES-based Crypt (3) algorithm used for these hashes is well known to be weak (and limited to at most 8 characters), I thought it would be an easy target to just crack these passwords for fun. *******

Well known tools for this arejohnandhashcat.

Quickly, I had cracked a fair deal of these passwords, many of which were very weak. (Curiously,bwkused/.,/. ,, which is easy to type on a QWERTY keyboard.)

However,kens password eluded my cracking endeavor. Even an exhaustive search over all lower-case letters and digits took several days (back in 2014) and yielded no result. Since the algorithm was developed by Ken Thompson and Robert Morris, I wondered what’s up there. I also realized, that, compared to other password hashing schemes (such as NTLM), crypt (3) turns out to be quite a bit slower to crack (and perhaps was also less optimized).

Did he really use uppercase letters or even special chars? (A 7-bit exhaustive search would still take over 2 years on a modern GPU.)

The topiccame up againearlier this month onThe Unix Heritage Societymailing list, and Ishared my resultsand frustration of not being able to breakkens password.

Finally, today this secretwas resolvedby Nigel Williams:

From: Nigel WilliamsSubject: Re: [TUHS] Recovered / etc / passwd files  ken is done:  ZghOT0eRm4U9s: p / q2-q4!  took 4  days on an AMD Radeon Vega 64 running hashcat at about 930 MH / s during that time (those familiar know the hash-rate fluctuates and slows down towards the end).

This is a chess move indescriptive notation, and the beginning ofmany common openings. It fits very well to Ken Thompson’sbackground in computer chess.

I’m very happy that this mystery has been solved now and I’m pleased of the answer.

[Update 16:29: fix comment on chess.]

NP: Mel Stone — By Now

Brave Browser
Read More
Payeer******

What do you think?

Leave a Reply

Your email address will not be published. Required fields are marked *

GIPHY App Key not set. Please check settings

The Real Reason Why the PS5 Announcement Crushed GME Stock, Crypto Coins News

The Real Reason Why the PS5 Announcement Crushed GME Stock, Crypto Coins News

The Future of Mathematics? [video], Hacker News