Still using a name with a couple of digits stuck behind it? You may be even substituting the odd letter with a number or symbol - no good I'm afraid. God forbid you're using a family name
Did you know any word in the dictionary used as a password can be cracked easily by running a ?dictionary attack? against it, in other words the hacker runs a small program which checks every word in the dictionary (in any language) against your account. It can take only 30 minutes to do this with speeds of 2.8 million attempts per second on a 1Ghz PC! If this doesn?t work they may well resort to a 'brute force' attack where they run hundreds of word lists as well as substituting letters for symbols and numbers. This again is all automated on freely available programs available all over the net.
Please click on the 'comments' below for more information
Last edited by fac51 on Thu Dec 09, 2004 9:21 pm, edited 5 times in total.
yeah of some though eamonn not all. accounts where you only get say 3 attempts are far more secure and infinitely superior but not every account/instance you need to enter a password has that limiting factor.
good passwords always make sense, i thought mine were ok until i read all that
I use a password that was once created by a very random Finnish computer... consists of letters and numbers that make up no logical word in any language
So far so good
My weakest point though: I use the same password for many a thing (all non-sensitive things though, such as forums ) so once you crack one you crack all.
I have loads of different passwords for stuff, but they\'re mostly arse except my banking stuff and my lotus notes one at work (coz notes 5 passwords have to be ultrasecure )
Ours has one that is generated when you want to log in. Need a remote device to generate it.... and the more modern ones for private banking will need your ATM card + a remote device to generate the password.
Impossible to crack from the consumers end.... but then again I guess you'd hack the systems that generate the passcodes to get in...
The newer ones identify your banking card and give you a password which will be valid for about 15 minutes.
As I have had one for ages I have an 'older version' which does not require the bank card but 'computes' a password right there and then when you put in your own access code for the device. That password too is valid for accessing your account for about 15 minutes. And unfortunately the bugger runs on a battery so when it runs out your clock and and the system clock are no longer in 'sync' and you can't log in