Subject: Re: crypt(3)
To: der Mouse <mouse@Collatz.McRCIM.McGill.EDU>
From: Tobias Weingartner <weingart@austin.BrandonU.CA>
List: current-users
Date: 11/15/1994 09:21:05
In message <199411141814.NAA05066@Collatz.McRCIM.McGill.EDU>, der Mouse writes:
> 
> If this _is_ because of export restrictions, would anyone be interested
> in a one-way function for passwords that I built on top of md5?  Since
> it has nothing to do with any encryption method, it should be fully
> exportable from everywhere.
> 

I'd be interested, and things would be *much* more secure, but
it would definitely be incompatible with the rest of the unix
world.

As in upgrade, we could make libcrypt do both.  New entries get the
MD5 hash, and old entries still get checked.  That is if you have the
DES software.

Any thoughts anyone?

--Toby.
*----------------------------------------------------------------------------*
| Tobias Weingartner | Email: weingart@BrandonU.Ca | Need a Unix sys-admin?  |
| Box 27, Beulah, MB |-----------------------------| Send E-Mail for resume, |
| R0M 0B0, Canada    | Unix Guru, Admin, Sys-Prgmr | and other details...    |
|----------------------------------------------------------------------------|
|      %SYSTEM-F-ANARCHISM, The operating system has been overthrown         |
*----------------------------------------------------------------------------*