Tuesday, March 19, 2013

Security & Hacking (Facepalm edition): "Cisco switches to weaker hashing scheme, passwords cracked wide open"


TL:DR version:
"It turns out that Cisco's new method for converting passwords into one-way hashes uses a single iteration of the SHA256 function with no cryptographic salt. The revelation came as a shock to many security experts because the technique requires little time and computing resources."

