Author Topic: short password = bad; long passphrase = good  (Read 4166 times)

0 Members and 1 Guest are viewing this topic.

Offline MP-Ryan

  • Makes General Discussion Make Sense.
  • Global Moderator
  • 210
  • Keyboard > Pen > Sword
short password = bad; long passphrase = good
http://www.popehat.com/2013/09/08/size-matters/

http://arstechnica.com/security/2013/03/how-i-became-a-password-cracker/

This subject has been mentioned before on HLP, but the above two links are excellent examples of why people should use long pass phrases that are easy to remember instead of short passwords that are not.
"In the beginning, the Universe was created.  This made a lot of people very angry and has widely been regarded as a bad move."  [Douglas Adams]

 
Re: short password = bad; long passphrase = good

 

Offline Luis Dias

  • 211
Re: short password = bad; long passphrase = good
Nice. have to update a lot of my passwords I guess.

 
Re: short password = bad; long passphrase = good
Yup.  Now, don't you wish that passwords longer than 8-10 characters were allowed on most of the places where you need them?  About the only place where I have been able to implement a pass-phrase is on my home wi-fi.  Granted that's an important one, but how about my bank?  My log-in at work?  My log-in to SAP?  My log-in to the engineering server?

Argh argh argh...
"…ignorance, while it checks the enthusiasm of the sensible, in no way restrains the fools…"
-Stanislaw Lem

 

Offline Mongoose

  • Rikki-Tikki-Tavi
  • Global Moderator
  • 212
  • This brain for rent.
    • Steam
    • Something
Re: short password = bad; long passphrase = good
I was able to use a longer phrase for a few online retailers like Amazon, but yeah, a lot of password forms out there only go up to 10 characters, which defeats the whole purpose.

 

Offline Klaustrophobia

  • 210
  • the REAL Nuke of HLP
    • North Carolina Tigers
Re: short password = bad; long passphrase = good
my bank password is required to be exactly 6 alphanumeric.  i don't even get all that worried about password security, and that made me cringe. 

work passwords are a little bit better at 8, but they are well and truly completely random and have no hope in hell of having a word list used on them.
I like to stare at the sun.

 

Offline BloodEagle

  • 210
  • Bleeding Paradox!
    • Steam
Re: short password = bad; long passphrase = good
my bank password is required to be exactly 6 alphanumeric.  i don't even get all that worried about password security, and that made me cringe. 

work passwords are a little bit better at 8, but they are well and truly completely random and have no hope in hell of having a word list used on them.

Hey, um.... Which bank do you use?

 

Offline MP-Ryan

  • Makes General Discussion Make Sense.
  • Global Moderator
  • 210
  • Keyboard > Pen > Sword
Re: short password = bad; long passphrase = good
Funny you guys mention that.  I haven't managed to hit a limit on Google's services, but the Microsoft Account for this tablet I'm testing at work is max 16 character password and enforces stupid rules
"In the beginning, the Universe was created.  This made a lot of people very angry and has widely been regarded as a bad move."  [Douglas Adams]

 

Offline deathfun

  • 210
  • Hey man. Peace. *Car hits them* Frakking hippies
Re: short password = bad; long passphrase = good
"Your password requires at least one number, an upper case letter, your mother's maiden name, a sacrificial goat, dancing around a fire and cutting out your heart to burn it in the hellfire pit in the middle of the temple to appease the password gods"
"No"

 

Offline niffiwan

  • 211
  • Eluder Class
Re: short password = bad; long passphrase = good
Banks are interesting.  All I've encountered have quite weak password requirements & they don't ever force you to change your password (although some think changing passwords regularly isn't that important anyway).  They do seem to like 2 factor authentication though, like sending a confirmation SMS to your phone.  While I think that part of this is them just writing off a certain amount of fraud, I think it also shows what's actually cost-effective at preventing fraud.  i.e. if someone enters their password into a keystroke logger, it doesn't matter how strong said password is, and that event is more likely that someone brute force guessing your password.

Personally, I use a password management program (like KeePass) with a long master passphrase to open the file, and I use 16+ random character passwords for any sites that allow it, because once I'm using a password management program there's no reason not to make them as complicated as possible.  I think that having non-trivial separate passwords for every site I use is very important, and worth the risk of having all my passwords in a file that potentially could be stolen & unencrypted.  And there is no way on earth that I can memorise all the passwords that I need, especially for sites that I only need to login to occasionally.
Creating a fs2_open.log | Red Alert Bug = Hex Edit | MediaVPs 2014: Bigger HUD gauges | 32bit libs for 64bit Ubuntu
----
Debian Packages (testing/unstable): Freespace2 | wxLauncher
----
m|m: I think I'm suffering from Stockholm syndrome. Bmpman is starting to make sense and it's actually written reasonably well...

 

Offline Kobrar44

  • On Suspended Sentence
  • 29
  • Let me tilerape it for you!
    • Steam
Re: short password = bad; long passphrase = good
I only use 20-character randomly generated password for my bank account, which is always empty anyways. Everything else has one of 3 passwords I used in the past. I had to change password on my google account since some chineese tried to hack it. Luckily google has some more safeties and only NSA knows everything.
Oh guys, use that [ url ][ img ][ /img ][ /url ] :/

  

Offline BloodEagle

  • 210
  • Bleeding Paradox!
    • Steam
Re: short password = bad; long passphrase = good
I had to change password on my google account since some chineese tried to hack it.

Query: How do you know they were Chinese and how do you know that there was more than one person involved in the attempt?

 

Offline Spoon

  • 212
  • ヾ(´︶`♡)ノ
Re: short password = bad; long passphrase = good
I had to change password on my google account since some chineese tried to hack it. Luckily google has some more safeties and only NSA knows everything.
Same here.
Now my password is like three times as long. (Takes so much longer to log in now)
Urutorahappī!!

[02:42] <@Axem> spoon somethings wrong
[02:42] <@Axem> critically wrong
[02:42] <@Axem> im happy with these missions now
[02:44] <@Axem> well
[02:44] <@Axem> with 2 of them

 
Re: short password = bad; long passphrase = good
best password i ever used was ultraneocontraantidisestablishmentarianism
The good Christian should beware of mathematicians, and all those who make empty prophecies. The danger already exists that the mathematicians have made a covenant with the devil to darken the spirit and to confine man in the bonds of Hell.

 

Offline Kobrar44

  • On Suspended Sentence
  • 29
  • Let me tilerape it for you!
    • Steam
Re: short password = bad; long passphrase = good
I had to change password on my google account since some chineese tried to hack it.

Query: How do you know they were Chinese and how do you know that there was more than one person involved in the attempt?

Google tells you the location so at least the server was chineese. How many people were involved I don't care.
Oh guys, use that [ url ][ img ][ /img ][ /url ] :/

 

Offline Dark RevenantX

  • 29
  • anonymity —> animosity
Re: short password = bad; long passphrase = good
I just use true random passwords of length 12-16 for everything, aside from a master password holding my vault locked under a very long passphrase.

 

Offline Androgeos Exeunt

  • Captain Oblivious
  • 212
  • Prevents attraction.
    • Wordpress.com Blog
Re: short password = bad; long passphrase = good
My blog

Quote: Tuesday, 3 October 2023 0133 UTC +8, #general
MP-Ryan
Oh you still believe in fairy tales like Santa, the Easter Bunny, and free market competition principles?

 

Offline Klaustrophobia

  • 210
  • the REAL Nuke of HLP
    • North Carolina Tigers
Re: short password = bad; long passphrase = good
my bank password is required to be exactly 6 alphanumeric.  i don't even get all that worried about password security, and that made me cringe. 

work passwords are a little bit better at 8, but they are well and truly completely random and have no hope in hell of having a word list used on them.

Hey, um.... Which bank do you use?


hopefully one that will NEVER leak its password lists. 

oddly enough, however, right after posting that i logged on and was greeted with a message saying they are going to be changing the password system soon.  hopefully that means changed rules and not just a new logon page.
I like to stare at the sun.

 

Offline rev_posix

  • Administrator
  • 213
  • I have the password to your shell account...
    • Trials and Tribulations
Re: short password = bad; long passphrase = good
Two-factor authentication FTW.

I turn it on with every system I can.  Twitter will send the one time use passcode via SMS, my bank uses a program called VIP Access from Symantec (formerly done by verisign), then there is the Google Authenticator.  Every login system should include this functionality IMO.
--
POSIX is fine, as is Rev or RP

"Although generally it is considered a no no to disagree with a mod since it's pretty much equivalent to kicking an unpaid janitor in the nuts while he's busy cleaning up somebody elses vomit and then telling them how bad they are at cleaning it up cause you can smell it down the hall." - Dennis, Home Improvement Moderator @ DSL Reports

"wow, some people are thick and clearly can't think for themselves - the solution is to remove warning labels from poisons."

 

Offline Klaustrophobia

  • 210
  • the REAL Nuke of HLP
    • North Carolina Tigers
Re: short password = bad; long passphrase = good
google will never, ever, EVER get my real name or phone number.  they wouldn't even have my email address if they hadn't bought out youtube and inherited it.
I like to stare at the sun.