<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	
	>
<channel>
	<title>
	Comments on: Keycloak Client Passwords are insecure by default	</title>
	<atom:link href="https://blog.icod.de/2022/10/10/keycloak-client-passwords-are-insecure-by-default/feed/" rel="self" type="application/rss+xml" />
	<link>https://blog.icod.de/2022/10/10/keycloak-client-passwords-are-insecure-by-default/</link>
	<description>Webentwicklung und sonstiger Unsinn :) Web development and other nonsense :)</description>
	<lastBuildDate>Sun, 13 Nov 2022 14:23:02 +0000</lastBuildDate>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>
	<item>
		<title>
		By: Darko Luketic		</title>
		<link>https://blog.icod.de/2022/10/10/keycloak-client-passwords-are-insecure-by-default/#comment-51245</link>

		<dc:creator><![CDATA[Darko Luketic]]></dc:creator>
		<pubDate>Sun, 13 Nov 2022 14:23:02 +0000</pubDate>
		<guid isPermaLink="false">https://blog.icod.de/?p=1821#comment-51245</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://blog.icod.de/2022/10/10/keycloak-client-passwords-are-insecure-by-default/#comment-51236&quot;&gt;K&lt;/a&gt;.

This image doesn&#039;t say how many distributed systems are working on this.
Ok their blogs post says it&#039;s 1 GPU only.
Assume a government funded distributed system like the NSA operates. 1000s of computers.
How secure is a 32-length password where 1 byte can have 16 possible values? (numbers only + 6)
Not secure at all.
That needs to change and that&#039;s why I created this post, because they aren&#039;t paying attention to it and not doing anything to change that.]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://blog.icod.de/2022/10/10/keycloak-client-passwords-are-insecure-by-default/#comment-51236">K</a>.</p>
<p>This image doesn&#8217;t say how many distributed systems are working on this.<br />
Ok their blogs post says it&#8217;s 1 GPU only.<br />
Assume a government funded distributed system like the NSA operates. 1000s of computers.<br />
How secure is a 32-length password where 1 byte can have 16 possible values? (numbers only + 6)<br />
Not secure at all.<br />
That needs to change and that&#8217;s why I created this post, because they aren&#8217;t paying attention to it and not doing anything to change that.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: K		</title>
		<link>https://blog.icod.de/2022/10/10/keycloak-client-passwords-are-insecure-by-default/#comment-51236</link>

		<dc:creator><![CDATA[K]]></dc:creator>
		<pubDate>Sat, 12 Nov 2022 12:53:44 +0000</pubDate>
		<guid isPermaLink="false">https://blog.icod.de/?p=1821#comment-51236</guid>

					<description><![CDATA[Well according to this (https://images.squarespace-cdn.com/content/v1/5ffe234606e5ec7bfc57a7a3/175e6393-2500-4a0d-81e8-c380bbe896e7/Hive+Systems+Password+Table) it will take a while for a password to cracked.]]></description>
			<content:encoded><![CDATA[<p>Well according to this (<a href="https://images.squarespace-cdn.com/content/v1/5ffe234606e5ec7bfc57a7a3/175e6393-2500-4a0d-81e8-c380bbe896e7/Hive+Systems+Password+Table" rel="nofollow ugc">https://images.squarespace-cdn.com/content/v1/5ffe234606e5ec7bfc57a7a3/175e6393-2500-4a0d-81e8-c380bbe896e7/Hive+Systems+Password+Table</a>) it will take a while for a password to cracked.</p>
]]></content:encoded>
		
			</item>
	</channel>
</rss>
