Fix-IT.org - The source that feeds your technological needs.
Header
HeaderGo back to the HomepageHeaderAbout UsHeaderContact UsHeaderHeader
Header
ForumsHeaderReviewsHeaderGlossaryHeaderSite HelpHeader
Header
filler
Image for Ad Block
Image for Ad Block
Image for Ad Block
Image for Ad Block

Go Back   Fix-It Forums > Discussions > Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read


Reply
 
Thread Tools Search this Thread Display Modes
Old 03-21-2005, 11:46 PM   #1
UNCLBEN
Level 2 Support
 
UNCLBEN's Avatar
 
Join Date: Aug 2004
Location: Peoria, IL
Posts: 430
Password security poll/discussion

How do y'all handle password security?

Do you use a different password for each site or one for everywhere?
Are they six-letter dictionary words or a random 16-char string?
Do you write them down anywhere (paper and/or digital)?

I'm wondering more about personal stuff here, not work-related. I have about half a dozen passwords, and variants thereof, that I use for 90+% of the web. I have an encrypted file, in a non-obvious path, with a non-obvious name, that contains hints to help me remember them.

I'm sure we have some post-it-on-the-monitor people here as well as tinfoil hat loonies. To which camp do you belong? Explain below!
UNCLBEN is offline   Reply With Quote
Old 03-22-2005, 12:17 AM   #2
MrDigital
Level 2 Support
 
MrDigital's Avatar
 
Join Date: May 2004
Location: Los Angeles, baby!
Posts: 448
Send a message via ICQ to MrDigital Send a message via AIM to MrDigital Send a message via MSN to MrDigital
I guess I'm closest to tinfoil hat, but not really. I don't keep my passwords anywhere but my head and I always use both letters and numbers and different case in my passwords.

However, none of them take longer than a couple of hours to brute crack. I've also been using the same list of about.. 10 passwords for the last decade.

In areas where I *know* the security will be tested constantly, like wifi, I run a 26 character password and do other things to limit the amount of access.

On the only highly secure corporate network I'm currently involved with, I use RSA SecurID key fobs and IPSec encryption. PGPmail is also used pretty frequently for email that leaves the secured network.

All of this doesn't compare to the real tinfoil hat wearers though, of which there's none on this board, or at least none that have made themselves known. You'd have to go to Slashdot or Defcon to see those folks.

-MrD
MrDigital is offline   Reply With Quote
Old 03-25-2005, 06:02 PM   #3
proxops-pete
Senior Level Support
 
proxops-pete's Avatar
 
Join Date: May 2004
Location: Houston, TX
Posts: 1,378
My passwords are non-dictionary-compliant "words".
If I tell you anymore, I'd have to kill you. Hee...
proxops-pete is offline   Reply With Quote
Old 03-25-2005, 07:19 PM   #4
jester22c
Level 3 Support
 
jester22c's Avatar
 
Join Date: May 2004
Location: TN
Posts: 948
I have about three different passwords that I use for personal use (at work I am one of the guys enforcing proper passwords) and they are all secure enough to keep my piece of mind. I don't write anything down, it's all up in the ol' noggin. As Mr D mentioned I also use a long character unique password for my wireless network. Oh yeah and my paypal account, that pass is one that won't be cracked I'm not overly paranoid but I'm not lax and careless either, so I voted in the middle.
jester22c is offline   Reply With Quote
Old 03-26-2005, 09:59 AM   #5
gurutoo
Level 3 Support
 
gurutoo's Avatar
 
Join Date: May 2004
Location: Houston, TX
Posts: 762
Cool Passwords? We don't need no stinkin' passwords...

Password scmassword...If they're good enough, they WILL get in...so I don't worry about it.

If you want something private, encrypt it-duh.
gurutoo is offline   Reply With Quote
Old 03-26-2005, 04:30 PM   #6
Fnord
Level 1 Support
 
Fnord's Avatar
 
Join Date: Mar 2005
Location: Tennessee
Posts: 19
Send a message via AIM to Fnord
I used to use normal words and then I got a job with Arch and they make you use the whole "strong" password system. So now all of my passwords are "Strong"
Fnord is offline   Reply With Quote
Old 03-26-2005, 09:18 PM   #7
zackbass
Level 2 Support
 
zackbass's Avatar
 
Join Date: May 2004
Location: Rockaway, NJ
Posts: 344
Send a message via AIM to zackbass
Quote:
Originally Posted by gurutoo
Password scmassword...If they're good enough, they WILL get in...so I don't worry about it.

If you want something private, encrypt it-duh.


You really need to cover security from all sides if you want to be secure. Keep incoming and outgoing connections tightly controlled, no suspicious software, regular antivirus checks, keep good physical security, and stay generally aware of suspicious activity. Miss one side and you put yourself at serious risk to any serious criminal.

A keylogger is a dangerous tool.
zackbass is offline   Reply With Quote
Old 03-27-2005, 12:26 AM   #8
gurutoo
Level 3 Support
 
gurutoo's Avatar
 
Join Date: May 2004
Location: Houston, TX
Posts: 762
Quote:
Originally Posted by zackbass

A keylogger is a dangerous tool.

Not if you understand that you are probably having your keystrokes logged and type accordingly...
gurutoo is offline   Reply With Quote
Old 03-28-2005, 11:35 PM   #9
muisejt
Level 2 Support
 
muisejt's Avatar
 
Join Date: May 2004
Location: Nova Scotia
Posts: 459
Send a message via ICQ to muisejt Send a message via AIM to muisejt Send a message via MSN to muisejt Send a message via Yahoo to muisejt
my passwords are not found in the dictionary unless there is one where 4=A, 3=E, 1=I, and 0=O. also when allowed (like in windows passwords) I'll throw in a * followed a number or 2.

so for an example one of my passwords whould look like this:

p4ssw0rd*69

breakable yes but it will many hours to crack with brute force where as it would only take seconds if you just use "password" or any dictionary word
muisejt is offline   Reply With Quote
Old 03-31-2005, 01:50 AM   #10
MrDigital
Level 2 Support
 
MrDigital's Avatar
 
Join Date: May 2004
Location: Los Angeles, baby!
Posts: 448
Send a message via ICQ to MrDigital Send a message via AIM to MrDigital Send a message via MSN to MrDigital
Quote:
Originally Posted by muisejt
my passwords are not found in the dictionary unless there is one where 4=A, 3=E, 1=I, and 0=O. also when allowed (like in windows passwords) I'll throw in a * followed a number or 2.

so for an example one of my passwords whould look like this:

p4ssw0rd*69

breakable yes but it will many hours to crack with brute force where as it would only take seconds if you just use "password" or any dictionary word


You'd be surprised. You should try out l0phtcrack sometime.

I thought the same as you until LC5 destroyed an admin password of !D351gn5 (!Designs) in about 18 minutes.

Tools written by hackers will try to break passwords thought up by hackers.

The only truly hard to brute force passwords are things like ^%#ahyvj^%@8 and whatnot.

-MrD
MrDigital is offline   Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
serious PHPBB security exploit Jeff Security 8 01-07-2009 12:57 PM
Four things you must have for security proxops-pete Security 11 06-10-2004 05:24 PM
ARTICLE REQUEST: WIRELESS SECURITY GUIDE CaTaLyST Security 0 05-30-2004 10:02 PM


All times are GMT -4. The time now is 09:52 AM.

Powered by: vBulletin Version 3.0.7
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Footer
FooterFooterReviewsFooterGlossaryFooterSite HelpFooter
FooterTop of Page
sponsor the site sponsor the site Free Computer Support