Our server costs ~$56 per month to run. Please consider donating or becoming a Patron to help keep the site running. Help us gain new members by following us on Twitter and liking our page on Facebook!
Current time: April 26, 2024, 12:08 pm

Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Amazing, I have the same combination on my luggage.
#1
Amazing, I have the same combination on my luggage.
[Image: job-fails-monday-thru-friday-the-schwart...sident.png]

ROFLOL
Best regards,
Leo van Miert
Horsepower is how hard you hit the wall --Torque is how far you take the wall with you
Pastafarian
Reply
#2
RE: Amazing, I have the same combination on my luggage.
That is some damn funny shit.
Even if the open windows of science at first make us shiver after the cozy indoor warmth of traditional humanizing myths, in the end the fresh air brings vigor, and the great spaces have a splendor of their own - Bertrand Russell
Reply
#3
RE: Amazing, I have the same combination on my luggage.
Your turn to make me spit out my coffee and LOL, Leo.
[Image: Untitled2_zpswaosccbr.png]
Reply
#4
RE: Amazing, I have the same combination on my luggage.
LOL. If 12345 is the second worst password, what's the worst? "Password?" That's why my password is "password1." The combination of the "1" with "password" will totally confuse them.

Oh crap... I just told everyone what my password is. Oh well, no problem. I'll just use "password2."


Here's an interesting site listing the 500 worst passwords of all time. It has 123456 as #1.

http://www.whatsmypass.com/the-top-500-w...f-all-time
Christian apologetics is the art of rolling a dog turd in sugar and selling it as a donut.
Reply
#5
RE: Amazing, I have the same combination on my luggage.
The best password you can have is one that has never been used by anyone before. The longer the better, and don't listen to anyone who tells you you need a mixture of upper / lowercase characters, numbers, and symbols. The passphrase "My purple donkey went to Rome" is far more secure than stuff like "Hw12ebA!", and as a bonus, it's far more memorable too!
Reply
#6
RE: Amazing, I have the same combination on my luggage.
I'm going to be sharing this article with my boss, who happens to be Syrian. Hopefully he sees the humor in it. Big Grin


(February 15, 2012 at 5:58 pm)Tiberius Wrote: The best password you can have is one that has never been used by anyone before. The longer the better, and don't listen to anyone who tells you you need a mixture of upper / lowercase characters, numbers, and symbols. The passphrase "My purple donkey went to Rome" is far more secure than stuff like "Hw12ebA!", and as a bonus, it's far more memorable too!

Tell that to my IT department. They insist that the 41 character passphrase that I was trying to use as a password was insecure.

Reply
#7
RE: Amazing, I have the same combination on my luggage.
IT departments know nothing about actual computer security.
Reply
#8
RE: Amazing, I have the same combination on my luggage.
unfortunately, if everyone followed your recommendation Tiberius, then most brute forcers would try dictionary combinations of words with spacers, like they do now.

You want to do the bare minimum and toss a number in somewhere. I like to denote spaces or other common characters with a number representing the index of that.

So "My purple donkey went to Rome" becomes "My2purple9donkey16went21to24Rome", which is arguably more secure and unpredictable unless you know:
- A space is index in string from first character == 0
- the spaces in the hypothetical password

An improvement would be for the USER to determine what 'salt' or weird 'twist' on the password FROM a pass phrase.

Sometimes I instead use this:
salts = {all the special characters on a standard US 105 keyboard above the numbers} = !@#$%^&*()
samplePassword = {I am a meat popsicle}
item to replace = ' ' (space)
result = I!am@a#meat$popsicle

The magic is:
- not be predictable with everyone else (i.e. be unique)
- use passphrases in conjuction with a salt

And you get most of your power right there in environments that use passwords.
Slave to the Patriarchy no more
Reply
#9
RE: Amazing, I have the same combination on my luggage.
The point is that an attacker doesn't know what your password looks like, or what kind of passphrase you are using.

Your suggestions are all perfectly valid, but they ignore the most common reason people choose short passwords: memorability. People do not want to have to spend 60 seconds typing their password in because they need to remember (or work out) which numbers go where. A far more memorable way of doing it (and the way I currently do it) is to include punctuation in your pass-phrases, and replace letters with numbers/symbols if they make sense (i.e. e => 3, a => @, etc).

In any case, I'd hold that the sheer number of combinations of all possible words is far greater than the number of combinations of letters and numbers. Think about it; there are 52 letters (upper / lowercase), 10 digits, and probably around 20 or so common punctuation symbols. That gives us 82 characters in total to play with, but let's be generous and hike the number up to 100. Brute-forcing an 8 character password would take at most 100^8 = 10,000,000,000,000,000 attempts. How many possible words are there? The OED estimates almost a quarter of a million, but lets assume our attacker takes out a large number of them, and we are left with a dictionary of 100,000. How many words do we need in a passphrase to generate the same level of attempts? Roughly, 3:

100^8 = 100,000^x
x = 16/5
x = 3.2

Source: http://www.wolframalpha.com/input/?i=100...100000%5Ex

Reduce the dictionary further to only 10,000 words and you only need one extra word in your passphrase in order to meet the same exhaustive search requirements. This is all done without the use of punctuation or altering the words in any way.
Reply
#10
RE: Amazing, I have the same combination on my luggage.
The problem isn't making it impossible to randomly guess.

The problem is people -- they chose commonly guessed phrases and passwords. If they bothered to salt it with '@'s and the like, we'd see less hacking because of that 'takes forever to brute force a character' routine. But they don't.

So once again, you run afoul of the user issue.

We need to convince more people to salt their passwords.

Also, your suggestions don't factor in a targeted attack -- in this case, even if they divine the common phrase, they'll be unable to recover it completely if you salt it.

All I'm advocating is one step more -- salting the damn thing.

And if people insist on short passwords, "I like football" is probably going to crop up more often than "The emperor of the old republic smells like crayon farts".

However, if they at least salt the short password (that currently has TOO few words), they've strengthened it significantly at little cost.

I do agree with replacing characters with similar looking ones as a salt, but think that even that is too damn obvious unless you like to add in funky punctuation sporadically.
Slave to the Patriarchy no more
Reply



Possibly Related Threads...
Thread Author Replies Views Last Post
  Is this the same guy? chimp3 8 688 May 31, 2021 at 12:33 am
Last Post: chimp3
  Other forums just aren't the same Violet 18 1405 May 3, 2020 at 6:51 pm
Last Post: Violet
  I am going naked on here to challenge my wife to do the same. funcouple 19 1645 August 31, 2019 at 10:49 am
Last Post: Gwaithmir
  Surreal day on the job...more of the same on the way. arewethereyet 75 5230 March 7, 2019 at 1:50 am
Last Post: Godscreated
  Why do I keep having this same dream or at least a variation of it GODZILLA 13 1678 February 18, 2019 at 2:29 am
Last Post: Godscreated
  Lasers are Amazing!!! chimp3 12 1302 August 10, 2017 at 10:51 pm
Last Post: chimp3
  Have you attended a wedding for a same sex couple? Divinity 17 2054 November 9, 2015 at 1:33 am
Last Post: Thumpalumpacus
  AmAm (Amazing America) rado84 6 1677 July 14, 2015 at 9:43 am
Last Post: rado84
  Do you think that "The Amazing Randy" is burning in hell right now? TeaPartyTeen 30 4539 January 2, 2015 at 4:51 pm
Last Post: robvalue
Lightbulb Do you watch The Amazing Atheist? Big Blue Sky 19 5379 October 7, 2013 at 2:48 pm
Last Post: freedomfromforum



Users browsing this thread: 1 Guest(s)