Comment on How Quickly Can AI Crack Your Password?
adminofoz@lemmy.cafe 4 weeks agoHere is the thing, does the corporate entity you work with use Microsoft? Then your password is stored as an NTLM hash in NTDS.dit. That means you are using MD4.
Has anyone in your organization clicked a phishing link? It only takes one weak link to get in. Then it only takes one (Maybe 2) bad configuration for a malicious actor to escalate privileges. Then dump the whole organization passwords from the Domain Controller.
Hope you aren’t reusing passwords anywhere.
The article isnt bullshit.
slazer2au@lemmy.world 4 weeks ago
We are all running password less with passkeys so our Entra passwords are all 128 length randomised that even we don’t know because why should we?
Corporate phishing tests are a joke, you can bypass them by filtering for Phishme or kb4 in the email header.
adminofoz@lemmy.cafe 4 weeks ago
slazer2au@lemmy.world 4 weeks ago
From something i read a while ago when you enable passwordless entra resets your password to something that stupidly long I don’t actively make them that long even in my password manager.
I am well aware of evilnginx :D