David Hibbeln pinged me this morning that Robert Hensing started a blog.  Who?  You ask?  Security Dude at Microsoft. That’s who.  Good stuff.  Subscribed!  He does the Security Incident Response stuff at Microsoft.  Talk about a “been there, seen that” kind of job.

He starts off with passphrases and getting rid of LMhash.  Start reading… and then go change your password to a passphrase.


