Time to change your password?

Author
Guitarhacker
Max Output Level: 0 dBFS
  • Total Posts : 24398
  • Joined: 2007/12/07 12:51:18
  • Location: NC
  • Status: offline
2011/07/15 08:27:27 (permalink)

Time to change your password?

This is a fascinating read. Things I have wondered about included the number of possible combinations in a password and this answered it...


So, maybe it's time for me to update my passwords.... and keep a new list of them.... How long should a password be?

My website & music: www.herbhartley.com

MC4/5/6/X1e.c, on a Custom DAW   
Focusrite Firewire Saffire Interface


BMI/NSAI

"Just as the blade chooses the warrior, so too, the song chooses the writer 
#1

16 Replies Related Threads

    bapu
    Max Output Level: 0 dBFS
    • Total Posts : 86000
    • Joined: 2006/11/25 21:23:28
    • Location: Thousand Oaks, CA
    • Status: offline
    Re:Time to change your password? 2011/07/15 10:17:06 (permalink)
    Freddie is right, size (64?) does matter.
    #2
    slartabartfast
    Max Output Level: -22.5 dBFS
    • Total Posts : 5289
    • Joined: 2005/10/30 01:38:34
    • Status: offline
    Re:Time to change your password? 2011/07/15 14:51:21 (permalink)
    Unfortunately, if you are trying to guard against offline attacks, the required length and number of passwords becomes impossible to manage with an ordinary human memory. You can try to use passwords that you "calculate" based on a combination of words and numbers that you remember (the last letters of the names of your seven cousins listed in reverse alphabetical order interspersed with the digits of your social security number adding 7 mod 8 to each digit for example), but with every internet shopping site requiring a password you will quickly find the algorithms as hard to remember as the passwords.
    Using an encrypted  password generator/database on a flash drive may be the only practical solution. Keypass works well for this. Then you only have to remember one long and difficult passphrase or calculated password, and keep the drive nearby.
    post edited by slartabartfast - 2011/07/15 14:53:32
    #3
    SteveStrummerUK
    Max Output Level: 0 dBFS
    • Total Posts : 31112
    • Joined: 2006/10/28 10:53:48
    • Location: Worcester, England.
    • Status: offline
    Re:Time to change your password? 2011/07/15 15:15:29 (permalink)
     
    That's an interesting read Herb.
     
    I have a mixture of 12 and 14 character passwords; and one 10 character password (which I've just upgraded to 14).
     
    Thinking about it, I might even lengthen the 12's to 14's which, using my own little 'code' should still be easy to remember.
     
     
     
     

     Music:     The Coffee House BandVeRy MeTaL

    #4
    Beagle
    Max Output Level: 0 dBFS
    • Total Posts : 50621
    • Joined: 2006/03/29 11:03:12
    • Location: Fort Worth, TX
    • Status: offline
    Re:Time to change your password? 2011/07/15 15:20:07 (permalink)
    SteveStrummerUK


     
    That's an interesting read Herb.
     
    I have a mixture of 12 and 14 character passwords; and one 10 character password (which I've just upgraded to 14).
     
    Thinking about it, I might even lengthen the 12's to 14's which, using my own little 'code' should still be easy to remember.
     
     
     
     

    bapulovesmooch   ?
     
     
     

    http://soundcloud.com/beaglesound/sets/featured-songs-1
    i7, 16G DDR3, Win10x64, MOTU Ultralite Hybrid MK3
    Yamaha MOXF6, Hammond XK3c, other stuff.
    #5
    SteveStrummerUK
    Max Output Level: 0 dBFS
    • Total Posts : 31112
    • Joined: 2006/10/28 10:53:48
    • Location: Worcester, England.
    • Status: offline
    Re:Time to change your password? 2011/07/15 15:22:42 (permalink)
    Beagle


    SteveStrummerUK


     
    That's an interesting read Herb.
     
    I have a mixture of 12 and 14 character passwords; and one 10 character password (which I've just upgraded to 14).
     
    Thinking about it, I might even lengthen the 12's to 14's which, using my own little 'code' should still be easy to remember.
     
     
     
     

    bapulovesmooch   ?
     
     
     

    Bugger, now I've got to change them all
     
     

     Music:     The Coffee House BandVeRy MeTaL

    #6
    bapu
    Max Output Level: 0 dBFS
    • Total Posts : 86000
    • Joined: 2006/11/25 21:23:28
    • Location: Thousand Oaks, CA
    • Status: offline
    Re:Time to change your password? 2011/07/15 15:48:40 (permalink)
    Beagle


    SteveStrummerUK


     
    That's an interesting read Herb.
     
    I have a mixture of 12 and 14 character passwords; and one 10 character password (which I've just upgraded to 14).
     
    Thinking about it, I might even lengthen the 12's to 14's which, using my own little 'code' should still be easy to remember.
     
     
     
     

    bapulovesmooch   ?
     
     
     

    You left out numbers and specal characters.


    #7
    Beagle
    Max Output Level: 0 dBFS
    • Total Posts : 50621
    • Joined: 2006/03/29 11:03:12
    • Location: Fort Worth, TX
    • Status: offline
    Re:Time to change your password? 2011/07/15 15:54:15 (permalink)
    bapu


    Beagle


    SteveStrummerUK



    That's an interesting read Herb.

    I have a mixture of 12 and 14 character passwords; and one 10 character password (which I've just upgraded to 14).

    Thinking about it, I might even lengthen the 12's to 14's which, using my own little 'code' should still be easy to remember.





    bapulovesmooch   ?




    You left out numbers and specal characters.

    sorry.
     
    BapuL0ve$m00cH
     
    better?

    http://soundcloud.com/beaglesound/sets/featured-songs-1
    i7, 16G DDR3, Win10x64, MOTU Ultralite Hybrid MK3
    Yamaha MOXF6, Hammond XK3c, other stuff.
    #8
    bitflipper
    01100010 01101001 01110100 01100110 01101100 01101
    • Total Posts : 26036
    • Joined: 2006/09/17 11:23:23
    • Location: Everett, WA USA
    • Status: offline
    Re:Time to change your password? 2011/07/15 16:17:32 (permalink)
    Length is what matters, not special characters. Requirements to include punctuation and numbers are annoying and not particularly effective, except that they slow down dictionary attacks by a few minutes.

    Think about it: if a string contains a single uppercase letter, there are 26 possible values. If that one-character string can contain either upper- or lowercase letters, that doubles the number of possible values to 52. But if we make it a 2-character string, there are now 676 possible values even with just uppercase characters. Doubling the length of the password has a much greater impact than doubling the number of possible characters.

    If you want a strong password, use long phrases that are easy to remember. Don't worry about special characters, don't bother substituting "4" for "A" and "1" for "L". That just makes it awkward to type and does not make the password significantly more secure. Instead, string several words together that aren't in the dictionary, such as "bapu", "becan" and "eadg".


    All else is in doubt, so this is the truth I cling to. 

    My Stuff
    #9
    bapu
    Max Output Level: 0 dBFS
    • Total Posts : 86000
    • Joined: 2006/11/25 21:23:28
    • Location: Thousand Oaks, CA
    • Status: offline
    Re:Time to change your password? 2011/07/15 16:32:25 (permalink)

    OK, I've got my new password:

    bapulurvesbecanwidstraummynjonbouy
    #10
    Beagle
    Max Output Level: 0 dBFS
    • Total Posts : 50621
    • Joined: 2006/03/29 11:03:12
    • Location: Fort Worth, TX
    • Status: offline
    Re:Time to change your password? 2011/07/15 16:43:31 (permalink)
    bapu


    OK, I've got my new password:

    bapulurvesbecanwidstraummynjonbouy

    sniff....
     
     
    I didn't even get honorable mention AGAIN!!!

    http://soundcloud.com/beaglesound/sets/featured-songs-1
    i7, 16G DDR3, Win10x64, MOTU Ultralite Hybrid MK3
    Yamaha MOXF6, Hammond XK3c, other stuff.
    #11
    Russell.Whaley
    Max Output Level: -47.5 dBFS
    • Total Posts : 2755
    • Joined: 2006/03/01 11:53:45
    • Location: Baja Manitoba
    • Status: offline
    Re:Time to change your password? 2011/07/15 17:04:24 (permalink)
    Beagle


    SteveStrummerUK


     
    That's an interesting read Herb.
     
    I have a mixture of 12 and 14 character passwords; and one 10 character password (which I've just upgraded to 14).
     
    Thinking about it, I might even lengthen the 12's to 14's which, using my own little 'code' should still be easy to remember.
     
     
     
     

    bapulovesmooch   ?
     
     
    Is that "bapu loves mooch" or "bapu love smooch?"  I worried about either...  






    #12
    Russell.Whaley
    Max Output Level: -47.5 dBFS
    • Total Posts : 2755
    • Joined: 2006/03/01 11:53:45
    • Location: Baja Manitoba
    • Status: offline
    Re:Time to change your password? 2011/07/15 17:08:12 (permalink)
    slartabartfast


    Unfortunately, if you are trying to guard against offline attacks, the required length and number of passwords becomes impossible to manage with an ordinary human memory. You can try to use passwords that you "calculate" based on a combination of words and numbers that you remember (the last letters of the names of your seven cousins listed in reverse alphabetical order interspersed with the digits of your social security number adding 7 mod 8 to each digit for example), but with every internet shopping site requiring a password you will quickly find the algorithms as hard to remember as the passwords.
    Using an encrypted  password generator/database on a flash drive may be the only practical solution. Keypass works well for this. Then you only have to remember one long and difficult passphrase or calculated password, and keep the drive nearby.

    I've used KeePass for a couple years - very nice.  I especially like their "entropy" calculator which will create a random passcode based on typing and mouse movements - 256 bits if you like.


    If you want to learn some interesting stuff about creating passwords, check out this page at Gibson Research: https://www.grc.com/haystack.htm




    #13
    philz
    Max Output Level: -50.5 dBFS
    • Total Posts : 2462
    • Joined: 2004/04/11 13:50:46
    • Location: Shrewsbury, PA, USA
    • Status: offline
    craigb
    Max Output Level: 0 dBFS
    • Total Posts : 41704
    • Joined: 2009/01/28 23:13:04
    • Location: The Pacific Northwestshire
    • Status: offline
    Re:Time to change your password? 2011/07/15 17:49:24 (permalink)
    bapu


    Beagle


    SteveStrummerUK



    That's an interesting read Herb.

    I have a mixture of 12 and 14 character passwords; and one 10 character password (which I've just upgraded to 14).

    Thinking about it, I might even lengthen the 12's to 14's which, using my own little 'code' should still be easy to remember.





    bapulovesmooch   ?




    You left out numbers and specal characters.


    Maybe bapulovesmooch2 would work (personally I see two special characters already in there, right?).

     
    Time for all of you to head over to Beyond My DAW!
    #15
    SteveStrummerUK
    Max Output Level: 0 dBFS
    • Total Posts : 31112
    • Joined: 2006/10/28 10:53:48
    • Location: Worcester, England.
    • Status: offline
    Re:Time to change your password? 2011/07/15 17:54:39 (permalink)
    Russell.Whaley

    I've used KeePass for a couple years... 

     That's useless Russell, it's only seven characters long.
     
     

     Music:     The Coffee House BandVeRy MeTaL

    #16
    Russell.Whaley
    Max Output Level: -47.5 dBFS
    • Total Posts : 2755
    • Joined: 2006/03/01 11:53:45
    • Location: Baja Manitoba
    • Status: offline
    Re:Time to change your password? 2011/07/16 17:49:37 (permalink)
    SteveStrummerUK


    Russell.Whaley

    I've used KeePass for a couple years... 

     That's useless Russell, it's only seven characters long.
     
     









    #17
    Jump to:
    © 2025 APG vNext Commercial Version 5.1