Jump to content


Photo

Passwords


  • Please log in to reply
26 replies to this topic

#1 ᗅᗺᗷᗅ

ᗅᗺᗷᗅ

    The Invictan Formerly Known as Jorost

  • Lord Protector
  • 16192 posts
  • Gender:Household pet that walked across the keyboard - male
  • Location:Massachusetts
  • Ruler Name:Jorost
  • Nation Name:Invicta Crownlands
  • IRC Nick:Jorost
  • Alliance Name:Invicta
  • Nation Link






Posted 07 July 2015 - 10:39 AM

Does anyone else think password requirements have gotten out of hand? It's ridiculous. I just did one that requires a capital letter, a lowercase letter, two numbers, and a special character. As a result I'm forced to create some mess of a password that I will never remember. Write it down, people say, but that strikes me as stupid. The whole point of a password is to provide security; writing it down defeats the purpose. I really wish websites would just let me use the passwords I want to use. I'll check off a box saying I have been warned of the consequences of having a weak one. If I'm so stupid I want to use "1234" that's on me. Because what inevitably happens with all these requirement-heavy passwords is that I forget them, and then I have to go through the hassle of resetting them, which usually means choosing yet ANOTHER new one because most places won't let you re-use old ones.

 

facebook-frustration_full.png





Member Awards ()

#2 The Dark Empire

The Dark Empire

    Lord James

  • Peer
  • 3082 posts
  • Gender:Male
  • Ruler Name:Lord James
  • Nation Name:The Dark Empire
  • IRC Nick:TheDarkEmpire
  • Alliance Name:Regnum Invictorum
  • Nation Link




Posted 07 July 2015 - 10:43 AM

My school makes me change my password every 6 months and it has all the dopey character requirements

Member Awards ()

#3 KiWi

KiWi

    To Be Or Not To be, Just Pick One!

  • Admin: Assistant Webmaster
  • 6060 posts
  • Gender:Other
  • Ruler Name:King William
  • Nation Name:Royal Nine
  • IRC Nick:KingWilliam
  • Nation Link


Posted 07 July 2015 - 10:47 AM

I just have my browser remember them, and I use a master password.

I should get a better master, but as long as that's client side, and I know the password to my email if I ever need to reset a password, I assume it's all fairly safe.

I don't follow practices like I know I should/would encourage others too, but eh.

Member Awards ()

#4 ᗅᗺᗷᗅ

ᗅᗺᗷᗅ

    The Invictan Formerly Known as Jorost

  • Lord Protector
  • 16192 posts
  • Gender:Household pet that walked across the keyboard - male
  • Location:Massachusetts
  • Ruler Name:Jorost
  • Nation Name:Invicta Crownlands
  • IRC Nick:Jorost
  • Alliance Name:Invicta
  • Nation Link






Posted 07 July 2015 - 10:53 AM

I don't like using my browser to remember passwords. It feels unsafe to me. If anyone ever got hold of my laptop all they'd need to do is break that one master password and they'd have access to everything. I know that's probably not likely, but it's how I think. That's also why I don't log into anything important on my smartphone (making email on the smartphone a colossal pain in the ass).

 

Besides, what if you're not on your computer? I was just trying to log into something from work, but I can't remember the damn password because the requirements are so specific.



Member Awards ()

#5 rotty

rotty

    The First 2 time Puppy President

  • President Emeritus
  • 13429 posts
  • Gender:Male
  • Location:West Coast is Best Coast you Bitch
  • BJ Points:69696969
  • Ruler Name:rotty
  • Nation Name:Giggle
  • IRC Nick:rotty
  • Alliance Name:~ Invicta ~
  • Nation Link



Posted 07 July 2015 - 11:04 AM

I never let my browsers save passwords.

I save them in a folder and then hide them in the Wise Folder Holder software on a thumb drive. (haha, not for Macs)   :P



Member Awards ()

#6 He who posts

He who posts

    Intentialy offensive

  • Foreign Diplomat
  • 1444 posts
  • Gender:Sentient artificial intelligence - identifies as male
  • Location: 
  • Ruler Name: 
  • Nation Name: 
  • IRC Nick: 
  • Alliance Name: 
  • Nation Link


Posted 07 July 2015 - 11:28 AM

Does anyone else think password requirements have gotten out of hand?

T8mGuit.png

 

I think that's worse.



#7 Manoka

Manoka
  • Internal Affairs: Writer
  • 6520 posts
  • Gender:Male
  • Location:A place
  • Ruler Name:deadmanszpiper
  • Nation Name:Manoka
  • IRC Nick:Rawrmansz
  • Nation Link





Posted 07 July 2015 - 01:32 PM

Sooner or later they will start requiring double layers of security, then triple, 2-3 passwords, answers about yourself etc. 

 

I think it's designed to make things so hard on you that you have to give real information to keep up with it all, so they can gather more information. :ninja:



Member Awards ()

#8 Infopowerbroker

Infopowerbroker

    Rambo of the Flowers

  • [Redacted]
  • 8461 posts
  • Ruler Name:Infopowerbroker
  • Nation Name:Maggie Walkerville
  • IRC Nick:Infopowerbroker
  • Nation Link





Posted 07 July 2015 - 06:10 PM

There is a lot of "research" back and forth, but the idea holds some merit:

password_strength.png

Long phrases are good. Entropy (length and girth different types of characters) makes it better.

Having different passwords is good. Some folks do a neat thing where they have the same password base [J0r0stIsKing!] and add a different salt [unique suffix] to the end.
The reason this is important, is that many passwords are stored using the same hashing method (think encryption, but the algorithm only goes from text to scramble (cyphertext), there is no way to get back the original pw). The password J0r0stIsKing! would have the hash 5E-22-6C-70-B7-64-0D-6A-31-C9-DC-AF-EA-92-C3-8D when put through the MD5 algorithm.
Example for Pizza hut: J0r0stIsKing!PIZZA has a MD5 hash of B2-D5-7F-FB-30-C4-3E-7E-63-79-94-35-2D-BC-3D-C9
Example for Cybernations: J0r0stIsKing!CYBERNATIONS has a MD5 hash of 56-92-B3-9E-FD-76-27-D7-8F-F8-32-55-16-84-F1-3B
Example For PlentyOfFish: J0r0stIsKing!FISHYFISH has a MD5 has of DA-53-C7-6D-0C-4D-19-ED-44-BC-FA-5C-02-C7-F6-0E

As long as you keep the beginning secret (that J0r0stIsKing!), you can write down PizzaHut = PIZZA, Cybernations = CYBERNATIONS, and Plenty Of Fish = FISHYFISH in your password book, and anyone who snoops through your password book won't be able to get in.

If Plenty of Fish gets hacked and someone knows that your password hash is DA-53-C7-6D-0C-4D-19-ED-44-BC-FA-5C-02-C7-F6-0E, they won't be able to use it to try to get into cybernations or pizza hut.

Plus, it's easy to remember that J0r0stIsKing!, because, well, duh.

Member Awards ()

#9 Redezra

Redezra

    ~>:BAMF:<~

  • Invicta: Knight
  • 7728 posts
  • Gender:Sentient artificial intelligence - identifies as female
  • Location::D
  • Ruler Name:Redezra
  • Nation Name:Jorostopia
  • IRC Nick:Redezra
  • Alliance Name:Invicta
  • Nation Link


Posted 07 July 2015 - 06:34 PM

As a security "expert" (and please, don't consider me any more than a network security researcher on this topic), yes it is out of hand. However, what the XKCD comic does not tell you is that computers guess non-randomly. The first thing I'll do is write a program that tests combinations of real english words, so "correct horse battery staple" is going to get pwnd a shitload earlier than Tr0ub4dor &3



#10 Infopowerbroker

Infopowerbroker

    Rambo of the Flowers

  • [Redacted]
  • 8461 posts
  • Ruler Name:Infopowerbroker
  • Nation Name:Maggie Walkerville
  • IRC Nick:Infopowerbroker
  • Nation Link





Posted 07 July 2015 - 07:04 PM

As a security "expert" (and please, don't consider me any more than a network security researcher on this topic), yes it is out of hand. However, what the XKCD comic does not tell you is that computers guess non-randomly. The first thing I'll do is write a program that tests combinations of real english words, so "correct horse battery staple" is going to get pwnd a shitload earlier than Tr0ub4dor &3


And yes, there are password cracking dictionaries for almost every language in use, including klingon and elvish, but for Jorost's original post, the idea does illustrate the value of entropy. (It was either XKCD or Shannon's Entropy Equation 279431d37dd6295da23d0f8752f3d721.png from NIST Special Publication 800-63 Electronic Authentication Guideline, Appendix A: Estimating Entropy and Strength(.pdf))

:)

Member Awards ()

#11 Redezra

Redezra

    ~>:BAMF:<~

  • Invicta: Knight
  • 7728 posts
  • Gender:Sentient artificial intelligence - identifies as female
  • Location::D
  • Ruler Name:Redezra
  • Nation Name:Jorostopia
  • IRC Nick:Redezra
  • Alliance Name:Invicta
  • Nation Link


Posted 07 July 2015 - 07:22 PM

Yeah, I know~ it's just that it means while it's theoretically effective, it's only effective against idiots. Which is why security on the scale Jorost is disliking happens.

 

Tbh, I do enjoy forcing people to use good passwords. I implemented an application whitelisting regime on my family's machines. That was fun :3



#12 Australia

Australia
  • Foreign Diplomat
  • 60 posts
  • Ruler Name:Wu Ming
  • Nation Name:Austrailia
  • Nation Link

Posted 10 July 2015 - 12:21 PM

That's a misconception actually. I don't think writing it down and putting it in your wallet is insecure. After all, you have to secure your wallet against theft anyways.

#13 slimshadyinc

slimshadyinc
  • Former Member
  • 503 posts
  • Ruler Name:slimshadyinc
  • Nation Name:United Freedom State
  • Nation Link


Posted 10 July 2015 - 05:30 PM

Idk I always make passwords I can remember even with all that stuff so I don't have that problem

Member Awards ()

#14 the rebel

the rebel
  • Former Member
  • 1961 posts
  • Gender:Male
  • Location:Manchester UK
  • Ruler Name:the rebel
  • Nation Name:rebellion
  • IRC Nick:TheRebel
  • Nation Link

Posted 10 July 2015 - 05:53 PM

I've always used the password yahoo email gave on register back in 2000, so its a generic password 14-20 characters long with different variations used over the years...I consider it very strong.



Member Awards ()

#15 ᗅᗺᗷᗅ

ᗅᗺᗷᗅ

    The Invictan Formerly Known as Jorost

  • Lord Protector
  • 16192 posts
  • Gender:Household pet that walked across the keyboard - male
  • Location:Massachusetts
  • Ruler Name:Jorost
  • Nation Name:Invicta Crownlands
  • IRC Nick:Jorost
  • Alliance Name:Invicta
  • Nation Link






Posted 11 July 2015 - 08:56 AM

That's a misconception actually. I don't think writing it down and putting it in your wallet is insecure. After all, you have to secure your wallet against theft anyways.

 

True. But then if your wallet is stolen, you would be that much more vulnerable. Security 101: never write anything down, never leave a paper trail.



Member Awards ()

#16 Redezra

Redezra

    ~>:BAMF:<~

  • Invicta: Knight
  • 7728 posts
  • Gender:Sentient artificial intelligence - identifies as female
  • Location::D
  • Ruler Name:Redezra
  • Nation Name:Jorostopia
  • IRC Nick:Redezra
  • Alliance Name:Invicta
  • Nation Link


Posted 11 July 2015 - 10:11 AM

Security 101: Don't exist, it's easier.



#17 KiWi

KiWi

    To Be Or Not To be, Just Pick One!

  • Admin: Assistant Webmaster
  • 6060 posts
  • Gender:Other
  • Ruler Name:King William
  • Nation Name:Royal Nine
  • IRC Nick:KingWilliam
  • Nation Link


Posted 11 July 2015 - 10:22 AM


That's a misconception actually. I don't think writing it down and putting it in your wallet is insecure. After all, you have to secure your wallet against theft anyways.

 
True. But then if your wallet is stolen, you would be that much more vulnerable. Security 101: never write anything down, never leave a paper trail.
 


Unless you list what it's for, the user name with it, you have no other security measures in hand, you don't report that your wallet is stolen (and are already in panic mode cancelling credit cards and being pissed your shit and money is gone), who's going to take a piece of paper (esp someone who's stolen your wallet, likely then dumping whatever they don't take right then [cash or the credit cards, I guess]) and then think "this is that dudes password! With this I can sign into his [bank account] and steal the rest of his fortune".

Or something like that.

I'm not a screenwriter. I need an editor like anyone else.

Member Awards ()

#18 Orson

Orson
  • Former Member
  • 9 posts
  • Gender:CIA
  • Ruler Name:Orson
  • Nation Name:Great Arcadia
  • Alliance Name:Invicta
  • Nation Link

Posted 11 July 2015 - 05:07 PM

Consider writing down all your passwords once.  Then download a software like KeePass is free and create a database there with all that information.  The app is available for Android and other OS.  You can pass the same file to your mobile and other electronics you own, ex. pen drives, tablets, etc.  You do only one database, it would be your little project but is worthy of doing it.  After that you just share that database with all your electronics.  That way you always have a copy of the database in case you experience criminal event. 

 

Anyhow after that burn the document.  Use a strong password for your KeePass database and learn that one and maybe your main email as well.  Use for a password something you like and some numbers you like as well, ex.  "2008blueBMW".  That method is not unbreakable but it gives a little trouble for a cracker, just a little, you're are not really safe :man_in_love:

 

P.S. Of course a different password for each website.



#19 Infopowerbroker

Infopowerbroker

    Rambo of the Flowers

  • [Redacted]
  • 8461 posts
  • Ruler Name:Infopowerbroker
  • Nation Name:Maggie Walkerville
  • IRC Nick:Infopowerbroker
  • Nation Link





Posted 11 July 2015 - 07:54 PM

So, the real question: Do you have a photocopy of your credit card (front and back) so you have the customer rep phone numbers in a file folder if your wallet is stolen?

Member Awards ()

#20 HordeLorde

HordeLorde

    Precisely

  • Former Member
  • 843 posts
  • Gender:Transsexual Female
  • Location:Covina, CA
  • Ruler Name:HordeLorde
  • Nation Name:Kamigawa
  • IRC Nick:HordeLorde
  • Nation Link

Posted 11 July 2015 - 08:36 PM

Damnit i thought this was going to be a word game thread...... 




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users