Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Sun, 25 Apr 2010 04:11:31 -0400
From: "Matt Weir" <cweir@...edu>
To: <john-users@...ts.openwall.com>
Subject: Re: Re-ordered 'Single Mode' Ruleset

In reply to Solar's comment:

 

>> It is not clear whether you have full (or any) separation between your
training and test sets 

>> when you re-order the rules.  (You do say that you have such separation
for your "UnLock" test, 

>> but that's another one.)

 

The training and cracking sessions were run against different sets of one
million passwords each, even though both of them came from the same
disclosed list, (that's the amazing thing about having a list of 32 million
passwords). I posted another blog entry showing the ruleset being run
against two other password lists, (the phpbb.com list and the MySpace list).
The short answer is that the re-ordered rules performed slightly better than
the original single rule-set against the phpbb.com list, and significantly
better, (in the first 500 million guesses), against the MySpace list. The
post, along with the corresponding graphs, can be viewed at the following
link:

 

http://reusablesec.blogspot.com/2010/04/optimizing-jtrs-single-mode-follow-u
p.html

 

 

Matt Weir

 


Powered by blists - more mailing lists

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.