Say Hello! Networking for Professionals
Register Get Password Search Today's Posts Mark Forums Read
Join the Discussion

Not a member yet? Register for FREE!
Go Back   Join the Discussion / Discussion Groups / General / Off Topic
Reload this Page question about passwords

General / Off Topic Discussion on all aspects of daily life in general . Topics such as work, marriage, relationships and so on.

JOIN TODAY! It's FREE . . . Discuss topics and issues that matter to you!

8,000 active members posting their views, facts and opinions on issues and topics that are important to people of today.

Join a Discussion or better yet and Start a Discussion of your own!

Reply
 
Thread Tools
Old 10-01-2007   #1 (permalink)
jeb
Just getting started
 
Join Date: Oct 2007
Posts: 13
Default question about passwords

Hi, I had a question about passwords. If I use a password like 12345 for my sites, does that mean someone could guess it? I'm not sure what a good password would be. Something that people couldn't guess is what I mean.
jeb is offline   Reply With Quote
Old 10-01-2007   #2 (permalink)
bns
Moderator
 
bns's Avatar
 
Join Date: May 2007
Location: Indiana, USA
Posts: 1,648
Default Re: question about passwords

How about something like 5Tk%geE23*^d

Pretty damn sure no one would guess that. Seriously, use both upper and lower case letters, numbers, and special characters. It makes them really hard to guess. Essentially impossible.
"Give a man fire, and he will be warm for a day; set a man on fire and he will be warm for the rest of his (short) life."---Wofl
bns is offline   Reply With Quote
Old 10-01-2007   #3 (permalink)
yaaarrrgg
Eligible for a custom title
 
yaaarrrgg's Avatar
 
Join Date: May 2007
Location: Indiana, USA
Posts: 791
Default Re: question about passwords

here's a couple simple tips for increasing the strength of passwords:

1. pick a word that's easy to remember, then use numeric substitutions for letters, such as:

A 4
B
C
D
E 3
F
G
H
I 1
J
C
L
M
N
O 0
P
Q
R
S 5
T
U
V
W
X
Y
Z 2


for example:

password -> p455w0rd


2. also add non-alphnumeric chars, for example:


p455w0rd -> p455;w0rd


3. for even better security use both upper and lower case letters:

p455w0rd -> P455;w0rD
yaaarrrgg is offline   Reply With Quote
Old 10-01-2007   #4 (permalink)
scooper
for all your bloviation needs
 
scooper's Avatar
 
Join Date: Jul 2007
Posts: 267
Default Re: question about passwords

Quote:
Originally Posted by jeb View Post
Hi, I had a question about passwords. If I use a password like 12345 for my sites, does that mean someone could guess it? I'm not sure what a good password would be. Something that people couldn't guess is what I mean.
Caveat: I'm not a security expert. This is just a bunch of info I've gathered over the years.

People write software for cracking passwords. They do dictionary lookups, number sequences, name mangling, etc. Your 5 digit password would be guessed relatively quickly by a program that goes through all possible numbers. Worse than that, the digits being ordered makes it an obvious thing to try on its own. And if you use it in multiple places, one crack gives access to many things.

Some general advice is to use words words with imbedded capital letters, punctuation and numbers in order to foil dictionary attacks and attacks on obvious combos. The longer the password the better, e.g. longer than 6-8 letters is a start. The other thing is to not use the same password in multiple places. If a particular site has its database hacked and someone has your password he can use it everywhere it's valid. You just have to think about the worst case scenarios.

If you're a Firefox user and you want to try a tool that helps with the issue of not repeating passwords, you can try my Password Hasher. Note that you should still use a strong password for the master key or you haven't gained much security. Try to read the FAQ and other documentation before using.

In general, security's more of a pain than we want it to be. Staying secure requires thought and effort. Wish it weren't so, but it is.
~~ \_O< ~~ \_O< ~~ \_O< ~~~~~~~~~~~~~~~~
Check out my SiteSig reverse search engine.
Let me know what you think!
scooper is offline   Reply With Quote
Old 10-01-2007   #5 (permalink)
Rasczak
Stirrer Of Shit
 
Rasczak's Avatar
 
Join Date: May 2007
Location: Oahu
Posts: 3,522
Send a message via ICQ to Rasczak Send a message via AIM to Rasczak Send a message via Yahoo to Rasczak
Default Re: question about passwords

On another password related issue, one thing I think is dumber than hell is when they force you to change your password often. I think it makes people more likely to write their passwords down somewhere handy like a sticky under the keyboard or blotter. Or there's more calls to the admin for password resets.

I think this throws a lot more risk into the mix than if someone has one well-memorized strong password that they use for years.
Eric
"For whoever habitually suppresses the truth in the interests of tact will produce a deformity from the womb of his thought." -Sir Basil H. Liddel-Hart
http://self-composed.com
Rasczak is offline   Reply With Quote
Old 10-01-2007   #6 (permalink)
bns
Moderator
 
bns's Avatar
 
Join Date: May 2007
Location: Indiana, USA
Posts: 1,648
Default Re: question about passwords

Quote:
Originally Posted by Rasczak View Post
On another password related issue, one thing I think is dumber than hell is when they force you to change your password often. I think it makes people more likely to write their passwords down somewhere handy like a sticky under the keyboard or blotter. Or there's more calls to the admin for password resets.

I think this throws a lot more risk into the mix than if someone has one well-memorized strong password that they use for years.
I could see changing it once a year or so, but not more often than that. I agree with you.
"Give a man fire, and he will be warm for a day; set a man on fire and he will be warm for the rest of his (short) life."---Wofl
bns is offline   Reply With Quote
Old 10-01-2007   #7 (permalink)
scooper
for all your bloviation needs
 
scooper's Avatar
 
Join Date: Jul 2007
Posts: 267
Default Re: question about passwords

Quote:
Originally Posted by bns View Post
I could see changing it once a year or so, but not more often than that. I agree with you.
I can't wait for good biometric security, e.g. retina scan or fingerprint, to be pervasive, assuming they can adequately protect privacy.

At a large (3 letter) company I worked for we had to change passwords frequently. Passwords were checked for quality (not easy to remember/guess). And they didn't allow you to make your new ones at all similar to the old. Of course if anybody outside the company had broken in and stolen all our source code it would have set them back 5 years. We didn't have access to actual important stuff, like financials.
~~ \_O< ~~ \_O< ~~ \_O< ~~~~~~~~~~~~~~~~
Check out my SiteSig reverse search engine.
Let me know what you think!
scooper is offline   Reply With Quote
Old 10-01-2007   #8 (permalink)
DaiTengu
 
Posts: n/a
Default Re: question about passwords

For many years I've used this Password Generator. It will generate a random string of numbers and letters, with options to include uppercase, punctuation & other characters, and some other stuff.

For instance, a 64 character password:
!Ecus=Udapra=A$-*ReSp_sPEWEWE?rUpa*adre+ede#tecrewEfr@FrEswupRu=
  Reply With Quote
Old 10-01-2007   #9 (permalink)
MRiGnS
the wicked one
 
MRiGnS's Avatar
 
Join Date: May 2007
Location: Saarbrücken, Germany
Posts: 1,918
Send a message via ICQ to MRiGnS Send a message via Skype™ to MRiGnS
Default Re: question about passwords

I can use my built-in pass generator :D

Code:
tr -cd [:graph:] < /dev/urandom | head -c 64
the 64 is the number of characters you want.

EDIT: If you don't want any punctuation characters in the password and only alphanumeric characters use the following instead:

Code:
tr -cd [:alnum:] < /dev/urandom | head -c 64


Quote:
[:alnum:]
all letters and digits

[:alpha:]
all letters

[:blank:]
all horizontal whitespace

[:cntrl:]
all control characters

[:digit:]
all digits

[:graph:]
all printable characters, not including space

[:lower:]
all lower case letters

[:print:]
all printable characters, including space

[:punct:]
all punctuation characters

[:space:]
all horizontal or vertical whitespace

[:upper:]
all upper case letters

[:xdigit:]
all hexadecimal digits

Last edited by MRiGnS : 10-01-2007 at 01:41 PM.
regards,
Julian

my blog
MRiGnS is offline   Reply With Quote
Old 10-01-2007   #10 (permalink)
eljalill
Just getting started
 
Join Date: Jun 2007
Posts: 10
Default Re: question about passwords

Something I like to do, is thinking of a sentence like: a secure password would be a nice thing to have. Then just take the first (or second, whatever you like) letter of each word, and the password will be: Aspwbantth.
As far as I know this is neither easy to remember nor that easy to forget, as long as you remember your sentence! And if you have a number in it, or make it so that it requires colons and such, it is even more secure.
eljalill is offline   Reply With Quote
Old 10-01-2007   #11 (permalink)
holihue
Interested participant
 
holihue's Avatar
 
Join Date: May 2007
Location: Lyngen, Norway
Posts: 25
Send a message via Skype™ to holihue
Default Re: question about passwords

Quote:
Originally Posted by yaaarrrgg View Post
password -> p455w0rd


2. also add non-alphnumeric chars, for example:


p455w0rd -> p455;w0rd


3. for even better security use both upper and lower case letters:

p455w0rd -> P455;w0rD

Check this:
Hellkeepa's Home Page - Ultra-1337 Translator
holihue is offline   Reply With Quote
Old 10-01-2007   #12 (permalink)
jeb
Just getting started
 
Join Date: Oct 2007
Posts: 13
Default Re: question about passwords

Cool, thanks for the tips!!!
jeb is offline   Reply With Quote
Old 10-01-2007   #13 (permalink)
Wofl
Devils advocate
 
Wofl's Avatar
 
Join Date: May 2007
Posts: 282
Send a message via ICQ to Wofl Send a message via AIM to Wofl Send a message via MSN to Wofl Send a message via Yahoo to Wofl
Default Re: question about passwords

a simple and dirty way would be to just thke the md5sum of some random, usergenerated file (a text document you made for school).

would be hard to guess, and then add some random special caracter in there, just because
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~~~~~~~~~~~~~~~~

-----BEGIN GEEK CODE BLOCK-----
Version 3.1
GE/CS/S/m/IT d- s++:- a--- C++(++++)>$ UL(B)++>$ P+ L+++ E w+(++) N o-- K- w--- !O V? PS++ PE Y+ PGP t+ 5? X R tv-- b+ DI+++ D G++ e->++++(*) h!(*) !r y-
------END GEEK CODE BLOCK------


My list is Gods list and he speaks to me and George Bush. -- wherespapa
Wofl is offline   Reply With Quote
Old 11-01-2007   #14 (permalink)
masoris
Discussion starter
 
masoris's Avatar
 
Join Date: May 2007
Location: South Korea
Posts: 68
Default Re: question about passwords

Use sentence in exotic language. For example "watashiwatensaida", it means "I'm so genius" in Japanese. You can remember easily those sentences, but it is hard to memory unless they don't understand what it means.
"The limits of my language mean the limits of my world." - Ludwig Wittgenstein
masoris is offline   Reply With Quote
Old 11-01-2007   #15 (permalink)
meghnarmajhi
Just getting started
 
meghnarmajhi's Avatar
 
Join Date: Nov 2007
Posts: 8
Default Re: question about passwords

I have read these recommendations somewhere:

1. At least eight chararters long.
2. Use both upper and lower case letters.
3. Use at least one numeric character.
4. Use at least one special character.
meghnarmajhi is offline   Reply With Quote
Old 11-07-2007   #16 (permalink)
JoJo
Just getting started
 
Join Date: Nov 2007
Posts: 9
Default Re: question about passwords

Personally I don't tend to worry about password strength very much - my passwords are strong enough for me to be comfortable with. For most sites (forums etc.) I use one of my 4 usual passwords. I think that if someone got a hold of one and tried to impersonate me or screw with my user account the damage would be easily reparable as forum members and staff would recognize that it isn't really me (based on rhetorical style and such things). Also I could in most cases contact an admin and explain the situation. For sites such at this one where I am new and no one really knows me yet this wouldn't work, but still it wouldn't be a big deal to me as I would simply register another account and use that one from then on. I'd probably also drop a PM to a staff member explaining the situation. In either case any harm done would be superficial.
For sites such as e-mail, banking/financial things, pay services such as my cable TV provider site, I use a unique password that is only for that site. For sites on which I have been granted some special security clearance (such as where I am an admin or something) I also use a unique password and I change it quite frequently as an added measure simply because there are other peoples assets on the line and I would feel horrible if those were compromised due to someone else logging in as me. Also with those sites I might increase the strength of the password beyond the the level I am usually satisfied with.
_____________________________
If I could care less I would.
JoJo is offline   Reply With Quote
Reply


Thread Tools



All times are GMT -5. The time now is 07:20 AM.



vBulletin® Version 3.6.7. Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.0.0 ©2007, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32