LM (LAN Manager) and NTLM (NT LAN Manager) are two authentication protocols used in Windows environments for securing access to resources. They have significant differences in terms of security, functionality, and usage. Here’s a detailed comparison:
LM (LAN Manager)
**1. Historical Context:
LM was introduced in the 1980s as part of Microsoft's LAN Manager software.
It was used in early Windows versions, such as Windows 95 and Windows 98.
**2. Security:
Weak Hashing Algorithm: LM uses a relatively weak hashing algorithm that is susceptible to modern attacks.
Case-Insensitive: LM passwords are not case-sensitive, reducing the complexity and security of the passwords.
Divided Passwords: LM splits the password into two 7-character chunks and hashes them separately, further weakening the security.
Vulnerable to Attacks: Due to the weak hashing and short password segments, LM is highly vulnerable to brute-force and rainbow table attacks.
**3. Password Handling:
No Salting: LM hashes are not salted, making them more vulnerable to precomputed attacks.
Legacy Compatibility: Despite its weaknesses, LM was kept for compatibility with older systems until it was deprecated.
NTLM (NT LAN Manager)
**1. Historical Context:
NTLM was introduced with Windows NT and has been used in various versions of Windows, including Windows 2000, XP, Vista, 7, and Server editions.
NTLM is still used in some form in modern Windows versions, though it is being replaced by more secure protocols like Kerberos.
**2. Security:
Stronger Hashing Algorithm: NTLM uses a stronger hashing algorithm (MD4 and MD5 in different versions) than LM.
Case-Sensitive: NTLM passwords are case-sensitive, increasing the complexity and security of the passwords.
Single Hash: NTLM hashes the entire password as a single entity, unlike LM's splitting method.
NTLMv2: An improved version, NTLMv2, introduced more security enhancements, including the use of stronger cryptographic algorithms and better handling of challenge-response mechanisms.
**3. Password Handling:
Salting: NTLMv2 includes salting mechanisms to make precomputed attacks more difficult.
Challenge-Response: NTLM uses a challenge-response mechanism for authentication, where the server sends a challenge, and the client responds with a hashed value, adding an extra layer of security compared to LM.
Backward Compatibility: NTLM can still be used in environments where older systems are present, but it is recommended to use NTLMv2 for enhanced security.
Key Differences
Hashing Algorithm:
LM: Uses DES-based hashing which is weaker.
NTLM: Uses MD4 and MD5-based hashing (NTLMv2 is stronger).
Password Case Sensitivity:
LM: Case-insensitive.
NTLM: Case-sensitive.
Password Length Handling:
LM: Splits passwords into 7-character chunks.
NTLM: Handles the entire password as a single hash.
Security Vulnerabilities:
LM: Highly vulnerable to brute-force, rainbow table, and other modern attacks.
NTLM: More secure, especially NTLMv2, but still has vulnerabilities compared to newer protocols like Kerberos.
Usage:
LM: Deprecated and should not be used in modern environments.
NTLM: Still in use, particularly NTLMv2, but gradually being replaced by more secure protocols like Kerberos.
Summary
LM is an older and much weaker authentication protocol that has been largely phased out due to its significant security vulnerabilities. NTLM, especially NTLMv2, offers improved security features but is still not as robust as modern authentication protocols like Kerberos. For contemporary environments, it is recommended to use NTLMv2 if NTLM is necessary, but to prefer Kerberos wherever possible for its stronger security guarantees.