Find more Phishing Funda....
Saturday, February 6, 2010
Tips For Creating Strong and Secure Passwords
The first step in information security is creating strong passwords that cannot be easily guessed or deduced. Tips for creating strong passwords include the following: Do not use personal information for your password. Social security numbers, driver's license numbers, phone numbers, birth dates, spouse names, and pet names are all factual information that can be found out by others.
Tuesday, July 1, 2008
Can I Guess Your Password?
But of course remembering all the different passwords can be a headache. And writing them down somewhere isn’t a great deal safer than using the same password again and again.
You can buy software that stores the passwords for you, but do you really want to pay money for another piece of software that performs a solitary function?
Try this simple, two-step, technique that lets you generate an infinite number of passwords, without having to remember any of them.
Step One: Choose a 4-6 letter word or number sequence that you can remember easily. Needless to say, don’t reveal this to anyone. For the purpose of this demonstration, I’ll choose the word "cash"
Step Two: Apply this secret word or number sequence to the name of the program you are setting up the password for.
To accomplish this, invent a couple of easy to remember rules.
Rule 1: Decide which part of the program name you are going to use. It could be the whole name, the first 6 letters of the name, the last 8 letters of the name. It’s totally up to you, be as creative as you like.
eg – For the program TrafficSwarm, I might choose the first 8 letters of the name. This give me: "traffics"
Rule 2: Take the portion of the program name you have selected and merge it with your secret word or number sequence to create a unique password. Again, be as creative as you can with this rule. You could replace every second letter, every third letter, every vowel or every consonant.
eg – If I replace every second letter of "traffics" with my secret word "cash", I get " t c a a f s c h "
or
- If I replace every vowel of "traffics" with my secret word "cash", I get " t r c f f a c s ". The "s" and the "h" are not used as "traffics" has only two vowels, but some words will use all four letters of "cash". Some words might have more than four vowels, in which case just start back at the beginning with "c" and "a" and so on…
You don’t have to worry about making your rules overly complex. Even the best code-breakers would need to see several of your passwords before they could start to guess what you rules are.
As long as you keep your rules safe and sound, your password is secure. But the real beauty of this system, is that you don’t have to remember the passwords you create. You ONLY have to remember the rules.
When you log into the program the next time, just apply your rules to the program name, and you can work out what password you generated. Once you have been using the rules for a while, you’ll generate the password in your head, without even having to pause.
Don’t worry if it seems a little complicated at first. Read this article through a couple more times and then try this technique with just a couple of programs. Once you are happy with it, all that’s left to do is to start working your way through existing programs and update your passwords. It’s time consuming, but for peace of mind you’ll be glad you did.
Sunday, June 1, 2008
Passwords or Pass Phrase? Protecting your Intellectual Property
Much has been said on the theory of password protection for files, computer login, and other network access. In the past we used a combination of letters, special characters, and other techniques to try and prevent unwanted or unauthorized access to our computers, resources, and networks. A new theory on passwords is emerging that may help us remember our access codes, be more secure, and generally keep hackers and thieves out of our networks.
A password is a combination of words, letters, and special characters that only the user knows, allowing access to a computer or other information resources. As humans we have a large number of codes and numbers we need to remember every day – such as the key lock on our apartment entries, national identification numbers, automobile license or tag numbers, telephone numbers – it is a large and confusing suite of items we need to memorize.
When selecting a new password or pass code for access to a computer system, most of us understand how difficult it is to remember complex codes, and thus we select something already know n to us, such as names, birthdays, national identifiers, or other known items, and then place a number or character in front of the name or number thinking it is secure. This is easy to understand, as most of us simply do not have an ability to instantly recall large numbers of complex codes.
In a worst case we simply write down the complex code on a piece of paper, and leave it in a desk, our pocketbook, or in many cases taped to the front of our computer monitor.
However, to a hacker this makes access to your network or computer much easier, at they generally only have to learn a couple things about you, and add a few numbers to the front or ending of your personal data – you would be surprised how often this grants access to computers and networks. Ad some good “cracking utilities” to the hacker’s suite of tools, and you can understand the threat.
PassPhrases are a concept that will help us create more secure, easy to remember safeguards for our computer and network resource protection. A passphrase is a selection of words and/or numbers that are 15 characters or more in length, and are easy for us to remember. A couple examples of a good pass phrases are:
• igotodalaieejdaily
• shehasbeautifulhair
• surfinginhawaiiisgreat
According to Mark Minasi, a noted security consultant, a 15 character pass phrase will require a cracking program the following number of computations to try and break a 15 character pass phrase:
• 15 lowercase letters = 1,677,259,342,285,725,925,376 possibilities
• Try a million a second, it’ll take 531,855 centuries/years to break the code
As you can see, this is a pretty good level of security for your resource.
Another concern with passwords is if you forget or lose the password, and are using a utility like Microsoft’s Encrypting File System (EFS), you run the risk of losing all access to your important files if you require a hardware reset of your password. All EFS encrypted files are linked to your login profile, meaning if you encrypt a directory or file with EFS, and you do a hardware reset on your computer, those files and directories are lost FOREVER.
For Microsoft Windows users you can now also use spaces within your pass phrase, however we would not recommend embedding spaces in your pass phrase, as that actually does allow a cracker better access to getting your code – it may help them crack it in 100,000 years rather than 250,000!
