June 14 2012 Meeting

Meeting Notes

Attendees:

  • Mike Budzik, Ag IT
  • Josh Gillam, Internal Audit
  • Jeffrey Stuart May, Arxan
  • Pascal Meunier, HUBzero
  • Preston Wiley, CERIS
  • Keith Watson, CERIAS

Presentation

  • Preston Wiley (@prestonsecure) reviewed the “Week of Leaks” consisting of information about user account password hashes from Linkedin, eHarmony, and last.fm.

The Week of Leaks

  • Keith Watson (@ikawnoclast) presented a talk on password hashing. It included a review of password hashing history, cracking, current techniques, and recommended methods.

Password Hashing

Discussion Points:

  • Some discussion included further exploration of password hashing and common issues.

Action Items:

  • The July meeting will be a workshop on scanning and attacking virtual machine infrastructure to discover issues.

  • The August meeting will be a presentation on Trusted Digital Repositories.