I don't think this is misinformation. You would be surprised at the number of IT people who have no clue how fast NTLM hashes can be brute-forced. Spreading this knowledge is good.
Ranting about NTLM, I am also shocked at how many people are unaware of the pass-the-hash vulnerability enabled by the mere possession of hashes, without having to brute-force them: http://www.youtube.com/watch?v=DkbBCR_vfRQ (disclaimer: I made this video and was a developer for Metasploit/Nexpose).
> I don't think this is misinformation. You would be surprised at the number of IT people who have no clue how fast NTLM hashes can be brute-forced. Spreading this knowledge is good.
That's just depressing, considering how long this has been a problem.
Advice has been, for many years, to avoid using passwords 14 chars or less to force use of NTLMv2.
> You would be surprised at the number of IT people who have no clue [...]
No, you're right. It's widespread lack of knowledge, and letting people know that some stuff is not secure, and other stuff is more secure if you have a complex passphrase, is important.
Ranting about NTLM, I am also shocked at how many people are unaware of the pass-the-hash vulnerability enabled by the mere possession of hashes, without having to brute-force them: http://www.youtube.com/watch?v=DkbBCR_vfRQ (disclaimer: I made this video and was a developer for Metasploit/Nexpose).