An engineer runs 'service password-encryption' on a router, then views the running configuration and sees 'password 7 0822455D0A16' under a VTY line. A colleague claims this fully protects the password from disclosure. Why is this claim incorrect?
- AType 7 encryption is functionally identical to the strong MD5 hashing used by 'enable secret'
- BType 7 encryption uses a weak, reversible cipher that can be decrypted almost instantly with widely available tools
- CThe 'service password-encryption' command only encrypts passwords for the enable secret, not line passwords
- DType 7 encrypted passwords require AAA to be enabled before they take effect
Show answer & explanationAnswer & explanation
Correct answer: B. Type 7 encryption uses a weak, reversible cipher that can be decrypted almost instantly with widely available tools
Type 7 encryption (used by 'service password-encryption') is a simple, reversible Vigenere-style cipher designed only to prevent casual shoulder-surfing, not real cryptographic protection. Numerous free online tools and scripts can instantly decrypt type 7 passwords, so it does not provide strong security compared to hashed passwords like type 5 or type 9 (scrypt) used with 'enable secret'.
Why the other options are wrong
- A. Type 5/9 used by enable secret are one-way hashes, fundamentally stronger and non-reversible, unlike type 7.
- C. 'service password-encryption' does apply type 7 encryption to line passwords such as VTY and console passwords.
- D. AAA has no bearing on whether type 7 encryption takes effect; it works independently of AAA configuration.
Type 7 Password Weakness
'service password-encryption' applies a weak, reversible Type 7 cipher to plaintext passwords, which offers only minimal protection since it can be decrypted using freely available tools.
- Type 7 is reversible; type 5/9 hashes are not
- Protects against casual viewing only, not real attacks
- 'enable secret' should always be used instead of 'enable password' for stronger protection
Memory trick: Type 7 hides passwords from your coworker, not from a hacker.