Subject: Computer Science   / Algorithms
Question
? Which tool, on which operating system was able to recover passwords the
quickest? Provide examples of the timing by your experimental
observations.
? Which tool(s) provided estimates of how long it might take to crack the
passwords? What was the longest amount of time it reported, and for
which username?
? Compare the amount of time it took for three passwords that you
were able to recover.
? Compare the complexity of the passwords for those discussed in the last
question. What can you say about recovery time relevant to complexity
of these specific accounts?
? What are the 4 types of character sets generally discussed when forming
strong passwords? How many of the 4 sets should you use, as a minimum?
What general rules are typically stated for minimum password length?
? How often should password policies require users to change their
passwords?
? Discuss the pros and cons of using the same username accounts and
passwords on multiple machines.
? What are the ethical issues of using password cracker and recovery tools?
Are there any limitations, policies or regulations in their use on local
machines? Home networks? Small business local networks? Intranets?
Internets? Where might customer data be stored?
? If you were using these tools for approved penetration testing, how might
you get the sponsor to provide guidance and limitations to your test team?
? Discuss any legal issues in using these tools on home networks in
States, which have anti-wiretap communications regulations. Who has
to know about the tools being used in your household?

