How Strong is your Password?

Hacking, cracking and bluejacking. Discussions on how to keep your stuff secure and private here.

Moderators: Andy, fac51, 117

User avatar
fac51
Gaming Guru
Posts: 14526
Joined: Sat Jun 14, 2003 11:00 am
Location: Rapture
Contact:

How Strong is your Password?

Post by fac51 »

Still using a name with a couple of digits stuck behind it? You may be even substituting the odd letter with a number or symbol - no good I'm afraid. God forbid you're using a family name :eek:

Did you know any word in the dictionary used as a password can be cracked easily by running a ?dictionary attack? against it, in other words the hacker runs a small program which checks every word in the dictionary (in any language) against your account. It can take only 30 minutes to do this with speeds of 2.8 million attempts per second on a 1Ghz PC! If this doesn?t work they may well resort to a 'brute force' attack where they run hundreds of word lists as well as substituting letters for symbols and numbers. This again is all automated on freely available programs available all over the net.


Please click on the 'comments' below for more information
Last edited by fac51 on Thu Dec 09, 2004 9:21 pm, edited 5 times in total.
Image
User avatar
fac51
Gaming Guru
Posts: 14526
Joined: Sat Jun 14, 2003 11:00 am
Location: Rapture
Contact:

Post by fac51 »

I have listed a some informative web pages below are both well worth a visit as you may find out you're now as secure as you think you are!


http://www.securitystats.com/tools/password.php

http://www.microsoft.com/athome/securit ... sword.mspx

http://www.sans.org/resources/policies/ ... Policy.pdf
Image
Eamonn
Arse Guru
Posts: 3512
Joined: Sat Jun 14, 2003 1:56 pm
Location: UK
Contact:

Post by Eamonn »

But new security mesures implemented by some only allow a certain number of attempts before blocking access completely to your account.
Eamonn

Image
User avatar
fac51
Gaming Guru
Posts: 14526
Joined: Sat Jun 14, 2003 11:00 am
Location: Rapture
Contact:

Post by fac51 »

yeah of some though eamonn not all. accounts where you only get say 3 attempts are far more secure and infinitely superior but not every account/instance you need to enter a password has that limiting factor.

good passwords always make sense, i thought mine were ok until i read all that :p
Image
User avatar
Vlammetje
Sexy Guru
Posts: 6569
Joined: Sat Jun 21, 2003 12:52 pm
Location: Den Haag
Contact:

Post by Vlammetje »

I use a password that was once created by a very random Finnish computer... consists of letters and numbers that make up no logical word in any language :D

So far so good


My weakest point though: I use the same password for many a thing (all non-sensitive things though, such as forums :P ) so once you crack one you crack all.
www.vlammetje.com
mr mixin
Guru In Trouble When Ed Finds Out
Posts: 3201
Joined: Sat Jun 14, 2003 11:14 am
Location: Notts, uk
Contact:

Post by mr mixin »

You need a password that requires both hands to type in too. Makes it harder for people looking over your shoulder ;)

My password(s) are all rather rubbish really.... Would say my webhosting and bank account have the best :)
117
Lowly Janitor Guru
Posts: 12548
Joined: Sat Jun 14, 2003 12:23 pm
Location: a destination a little up the road

Post by 117 »

I have loads of different passwords for stuff, but they\'re mostly arse except my banking stuff and my lotus notes one at work (coz notes 5 passwords have to be ultrasecure )

Posted from a Sony Ericsson mobile phone
User avatar
Vlammetje
Sexy Guru
Posts: 6569
Joined: Sat Jun 21, 2003 12:52 pm
Location: Den Haag
Contact:

Post by Vlammetje »

Your online banking have a fixed password?? :o

Ours has one that is generated when you want to log in. Need a remote device to generate it.... and the more modern ones for private banking will need your ATM card + a remote device to generate the password.

Impossible to crack from the consumers end.... but then again I guess you'd hack the systems that generate the passcodes to get in... :para: :para:
www.vlammetje.com
mr mixin
Guru In Trouble When Ed Finds Out
Posts: 3201
Joined: Sat Jun 14, 2003 11:14 am
Location: Notts, uk
Contact:

Post by mr mixin »

Vlammetje wrote:Ours has one that is generated when you want to log in. Need a remote device to generate it....
How sdoes that work :?:
I'm intrigued...
Eamonn
Arse Guru
Posts: 3512
Joined: Sat Jun 14, 2003 1:56 pm
Location: UK
Contact:

Post by Eamonn »

maybe a card chip reader thingy?
Eamonn

Image
User avatar
Vlammetje
Sexy Guru
Posts: 6569
Joined: Sat Jun 21, 2003 12:52 pm
Location: Den Haag
Contact:

Post by Vlammetje »

The newer ones identify your banking card and give you a password which will be valid for about 15 minutes.

As I have had one for ages I have an 'older version' which does not require the bank card but 'computes' a password right there and then when you put in your own access code for the device. That password too is valid for accessing your account for about 15 minutes. And unfortunately the bugger runs on a battery so when it runs out your clock and and the system clock are no longer in 'sync' and you can't log in :x

That's happened once in the past 5 years :P
www.vlammetje.com
Eamonn
Arse Guru
Posts: 3512
Joined: Sat Jun 14, 2003 1:56 pm
Location: UK
Contact:

Post by Eamonn »

so basically a synchnonised algorithm device?
Eamonn

Image
mr mixin
Guru In Trouble When Ed Finds Out
Posts: 3201
Joined: Sat Jun 14, 2003 11:14 am
Location: Notts, uk
Contact:

Post by mr mixin »

So you have a bit of hardware? :o
Eamonn
Arse Guru
Posts: 3512
Joined: Sat Jun 14, 2003 1:56 pm
Location: UK
Contact:

Post by Eamonn »

I think it'd be more like a keychain with ticking numbers
Eamonn

Image
mr mixin
Guru In Trouble When Ed Finds Out
Posts: 3201
Joined: Sat Jun 14, 2003 11:14 am
Location: Notts, uk
Contact:

Post by mr mixin »

Like a bomb?
Post Reply