> > b) transmitted over-the-wire in the clear. > > This one is rather harder. I seem to remember that with Windows one > sometimes sees pure lm hashes sent over-the-wire as well (?). not that i'm aware of. one of the old LM password changes sends the new password in clear-text (COREPLUS or LANMAN1 protocol).