Live data from Hacker News

Write your passwords down

blog.jgc.org

111–120 of 125 posts

Re: Write your passwords down

#111
post #58

Earlier quoted context omitted.

Yes, this same thing happens on the ship I work on in the summers. There are about 300 people, and about half have to reset their password when they come on board. There is the arbitrary 8 character, at least 1 #, at least 1 special character, at least 1 capital, can't match a dictionary word, and can't be close to the previous password. Also can't contain their name. Try explaining that to 150 people over and over a…

> just require long passwords, no other requirement. I particularly liked the suggestion (elsewhere) to set passwords to a random combination of three dictionary words. It's hard to remember 7Gw$kW_ws, but I bet I could come up with a meaning for "dog shower flange".

I came up with a similar password for our house router. After a week, I couldn't remember which animals were involved...

Re: Write your passwords down

#112
post #102
post #97

Earlier quoted context omitted.

Your approach is great, I think I'll use it too. My current method for secure passwords on sites that have a max around 8 or 12 or so is to think of some song lyrics I know, pick n words, camel-case them, l33+-translate a couple letters, and add shift+numeral special characters to either side.

Thanks. You can cut and paste the passwords. Write an app like I did or if you trust others, download one. I like it because it's portable (no secret encryption crap) and easy to recall. Also, if one site is compromised, like gawker, and they happen to crack the password, they won't be able to use it anywhere else and won't know what your secret sentence(s) are. Edit: One other neat thing about this approach is that…

Your last point about claiming to not know the password is interesting... If I had a mustache I'd be stroking it by now. ;)

I ended up writing a simple shell script using sha256sum and dicing it several ways, a GUI app seemed a bit clunky for me.

    read -s p
    hash=`echo -n $p | sha256sum | sed -e 's/-//' | sed -e 's/ //'`
    echo '64: '$hash
    echo '40: '${hash:0:40}
    echo '20: '${hash:0:20}
    echo '16: '${hash:0:16}
    echo '12: '${hash:0:12}
    echo '10: '${hash:0:10}
    echo '08: '${hash:0:8}

Re: Write your passwords down

#113
post #107

Earlier quoted context omitted.

http://www.baekdal.com/tips/password-security-usability says that it would take 2,537 years to crack a password with three common words, at a rate of 100 guesses per second, and flange isn't common. That's long enough for me.

Reminds me of when I had to write a front-end for a web search feed. It was easy to test the standard case (millions of results, of which the first 1000 can be paged). But what about the case when there is only one page of results? The solution seemed to be, rather than finding a topic with only a few results, to keep appending common words until the # of results shrunk enough. For example, from Google: "antelope" ha…

This was a concept back around 2004 or so called "googlewhacking". The goal was to form a search query of only two words that had exactly one hit on google.

Re: Write your passwords down

#114

My policy: - lame passwords for sites I don't care about (e.g., 'insecure') - the same password for sites with semi-sensitive information (e.g., facebook) - unique passwords for bank accounts, servers, etc. So I try to strike a balance between difficulty in remembering & security.

The thing that's bitten me on the ass a few times with that strategy is failing to upgrade sites from "I don't care about" status.

I'll use the 'insecure' password to drop a comment on an interesting discussion on a site I've just found - like, say HackerNews or Twitter, then two years later I'm still participating in the community there, and it _could_ have still had the password I used that time to comment on a ValleyWag story. All of a sudden I _do_ care a bit about any reputation I might have. I was fortunate this time not to have any sites I cared about still using the same old password Gawker leaked (mainly 'cause I'd learned that lesson when my twitterstream started spamming acai berry sites when PerlMonks exposed my low-grade password back then.)

I think Schenier's right - the world isn't a place where "remembering passwords" works any more. We need too many of them and we don't have enough control over how other people store them.

A password safe with a strong passphrase backed up by somethig like dropbox or zumodrive is probably a minimum sensible approach now. Some care is needed with the devices you access that password safe on, and awareness of how software like browsers or your OS caches and stores any passwords it sees you use. Even with a properly secured password safe, a fair number of my logins are probably hosed if I lose my laptop... Firefox, Chrome Safari, Mail.app, Twitter clients, IM clients, IRC programs, FTP programs - all of them store credentials for me, _mostly_ in Mac OS X's keychain, but not in a "reliable enough way" to be considered "secure" if the physical hardware is in someone else's possession.

Re: Write your passwords down

#115
post #101
post #18

I always have a question come to mind whenever I read these kinds of guidelines: what percentage of computer users have ever had their passwords compromised? I'm guessing there's no real way to gauge this because I've never seen a study nor heard anyone else touting one and yet, complex password protection guidelines are always being recommended. Why?

I have no idea about the percentages. But I've been hit twice. One by a leak from a sizable gaming website, and the other time by gawker. Neither time I gave a shit because thankfully I was smart about my passwords. There's always a risk, it's not expensive to defend against, so why not?

Those are interesting examples because you didn't lose the passwords, those websites did. So stuffing your password in your wallet, or making sure they were 12 characters long wouldn't do any good.

Re: Write your passwords down

#116

> (I have a second copy of that sheet left with a friend in an envelope) I love jgc but here he's making the same mistake most people make when they speak about security: assuming all readers have the same need for security and run the same risks. They don't. There is no point for my mom to adopt this system, it's way overkilled for her. (I think there's no point for me either). One needs to explain to users two thin…

I somewhat agree, but when mass hacks occur it opens people with poor passwords up to hackers because they've got all the time in the world to see whose accounts they can get into. BTW Do you use the same password on your Gawker account elsewhere?

As long as the password is unique, it doesn't even matter. Sure, it should be unique yet not revealimg a pattern ("goofy" is ok, "gawker" is not) but there is no need for the user to pass crypto 101.

This for those 1.5m that were just A target; Nick Denton, OTH, was THE target and it was just matter of time for him to get pwned.

>BTW Do you use the same password on your Gawker account elsewhere?

I had to check the other day. I opened that account to leave one comment on lifehacker (that was never approved, actually) and then forgot about it. Turns out the password was safe enough but my mistake there was to use an email address I cared about.

Now I have a less important email address and a supergenpass for everything, except gmail/facebook/dropbox and the other things I care about, for which I have better passwords.

Re: Write your passwords down

#117
"Write them down and keep them in your wallet because you are good at securing your wallet."

I'm having a very difficult time articulating just how horrible this idea is. Now if somebody compromises your password list, by either finding or stealing your wallet, they also get all of your personal and banking information as well!

There is a reason that the government advises people not to carry their Social Security cards in their wallet (http://ssa-custhelp.ssa.gov/app/answers/detail/a_id/446/~/ca...).

I use Wallet, a password manager/generator that's available for OS X and iOS, supports encryption, and syncs between devices automatically. I use a different random, strong password for all of my accounts, and it's easier to manage than keeping lists of passwords. Works for me.

Re: Write your passwords down

#118
post #69
post #65

Earlier quoted context omitted.

While my method isn't as secure as your most likely is, I prefer a simpler algorithm based upon the site name. I can perform my algorithm in my head and enter a password quickly and without having to refer to a terminal or another program. Btw, do you ever worry that your command history might be accessed to discover your passwords?

I use an app I wrote to do the sha1 so the sentence is not hanging around in bash history, but I do rely on the cmd prompt at times on computers at my house. Here's a screeshot of the app: http://i.imgur.com/tz255.png No one but me uses it. So it's bare bones.

You mentioned adding a period for special characters but what do you do for passwords that require capitalization?

Re: Write your passwords down

#119

> (I have a second copy of that sheet left with a friend in an envelope) I love jgc but here he's making the same mistake most people make when they speak about security: assuming all readers have the same need for security and run the same risks. They don't. There is no point for my mom to adopt this system, it's way overkilled for her. (I think there's no point for me either). One needs to explain to users two thin…

I like that giving the paper to a friend provides an easy way for a friend to be able to access his accounts in case of a tragedy.

Re: Write your passwords down

#120
post #69

Earlier quoted context omitted.

I use an app I wrote to do the sha1 so the sentence is not hanging around in bash history, but I do rely on the cmd prompt at times on computers at my house. Here's a screeshot of the app: http://i.imgur.com/tz255.png No one but me uses it. So it's bare bones.

You mentioned adding a period for special characters but what do you do for passwords that require capitalization?

I suppose you could get that with base64 encoding rather than a hex digest. Something like:

    echo -n 'Secret sentence Sitename' | openssl sha1 -binary | openssl base64
Post reply on HN