Showing posts with label encryption. Show all posts
Showing posts with label encryption. Show all posts

Saturday, March 7, 2009

Choosing and using passwords badly

If you want to pick a bad password you have come to the right place.  A password is only useful if it is something you can remember and nobody else can figure out.  Today we are going to discuss as several common password mistakes so that your passwords can be;

  • Easy for hackers and others to guess

  • Easy to disclose


[caption id="attachment_407" align="aligncenter" width="240" caption="Password (flickr credit: Bruno Santos)"]Password (flickr credit: Bruno Santos)[/caption]

For picking a bad password try...



  • Making your password the same as your username

  • Use a meaningful name, like your name, your middle name, your mother's maiden name, or the name of your children, the name of your pets. Basically choose anything someone could read off of your facebook page.  Remember if you are really tricky you can REVERSE the name.  I'm sure nobody would think of that.

  • Use significant numbers like a date.  Your postal code, your birthday, your aniversary, your kid's birthday.

  • Use 0bscenities.  No decent hacker would dare type THAT.  (Most password cracking software will try them early on because they are very common.)

  • Science fiction terms, greek letters and mythology. Like;  "Data," "Spock," "Borg" and "HAL." "Epsilon", "Venus", "Aphrodite"

  • Computer terms: stay away from "keyboard"; "mousepad"; "megabyte"; etc.

  • Line-of-sight terms: e.g., "Gateway" because that's the brand of your computer, or "telephone" because there is one on your desk. Though this can help you remember your password, it is a trick that password crackers are on to. To play it safe, avoid any reference to common objects found in households and offices.

  • Common phrases: in particular, those pertaining to greeting or getting down to work, such as "Good morning," "Wake up", "Hey you" or "Get going."

  • Anything related to your login ID: It's relatively easy for other people to get your login - don't let it provide a clue to your password! For instance, if your login is "basset" don't make your password "doglover."

  • When choosing an ATM PIN, make sure that the (4) numbers you pick spell a word like "Love" (hardly anyone would think of that one... Sorry if I'm giving all your secrets away.)


For bad password management try...



  • Put your password on a note and tape it to your monitor.  This way an unethical coworker could read and use your account pretending to be you.

  • Use the same password everywhere.   This way if someone gets into one of your accounts, like an online email account, they could figure out what other services you use and use the same password to access those other services.

  • Base your password on something that will change over time, like the date.  "MyBrandNewPasswordFor2001" made sense in 2001, but 8 years later you may find yourself trying out all the intervening years.

  • Share your password with people who need to "borrow" your accountt, then don't change the password even after it may have been discovered.

  • Use an unmemorizable password like; awnf65ayr8f9as6df584 as nobody will argue that it is not secure.  This way you will have to write it down.  Maybe in the front cover of your daytimer, or in a file on the desktop called password.txt. 

  • When you forget your password, you can rely on the "security questions" like what is your favourite colour to recover your password.  Choose easy or predictable security questions.  In response to "what is your favourite colour?" choose "Blue" rather than Oceanic815.

  • Type passwords slowly in full view of those around you.

  • Never look around at ATMs for hidden cameras which may be watching the keypad.

  • Do not shield the keypad when using your bank card

  • Don't change passwords on electronic door locks with push buttons so the worn buttons can remind you of the numbers in your combination.

  • Leave Laptop locks and safe combinations "set" so that you can open these items more easily.


There, those should be enough tips to get you started on choosing poor passwords and using them badly.  I hope you found this informative despite the tongue in cheek delivery.  Watch for an upcoming article on "Choosing and remembering really good passwords".

Cheers, and safe computing!

Greg.

Sunday, February 8, 2009

Protect your Passwords with KeePass

Remember all your passwords easily by storing them securely in a password safe.

When it comes to password security, we continue to hear about the importance of choosing passwords;

  • that are too complex to be guessed

  • that are unique from every other  password we use

  • that aren't real words or dates or names


And it works great to keep our accounts safe...  until WE forget our own password.  Then we wish we'd re-used a password, or picked something we could guess.  God help us if the account locks itself after 3 wrong tries.  I am at the point in my Internet experience where I can't keep track of all the places I have accounts (never mind my passwords).  So I needed a tool to help me, because apparently large amounts of fair-trade coffee isn't enough to jog my memory

I needed a place I could keep all my passwords.  I needed a password safe.  It had to hold; passwords, URLs, usernames, comments, the ability to organize those passwords in a hierarchy that would make sense, and it needed to be secure lest it fell into the wrong hands.  For several years I have used PasswordSafe which promises Simple & Secure Password Management.  It worked great, but I had one problem using it.  I could rarely remember which subfolder in the hierarchy contained my entry... I needed search.  Enter Keepass.  Keepass offers all the above features including "search" if you type in some text it will match every entry in the encrypted Keepass database that matches this.

[caption id="attachment_260" align="aligncenter" width="300" caption="way better than a post-it note!"]way better than a post-it note![/caption]

I have been absolutely Loving Keepass, and as long as I'm disciplined to put my passwords in there, they are available to me when I need them.  The Keepass website makes this introduction; "KeePass, the free, open source, light-weight and easy-to-use password manager."

Keepass logo


So there was one more problem I needed to address and it was the question of how do I synchronize keepass databases across the multiple computers that I use in a week.  I don't have a magical 5 minutes every time I'm done using a computer to make sure my database is copied correctly.  So the fear would be that an old copy overwrites a new copy, or that a password is in one location and not the other location where I need it. (What computer was I sitting at when I signed up for that account?).

Dropbox logo

To synchronize files, I turned to Dropbox. The promise of Dropbox is that you can "synchronize files online across computers" .  On the downside Dropbox requires you to install some software on your computer which runs at startup (or else there is little point of automatic synchronization).  It probably uses more memory than it needs, but hopefully someone on the Dropbox team will be working at reducing that memory footprint further.  Essentially you share a folder with yourself via the Dropbox website.  Your application checks every so often to see if the file has been updated, and if so, you get the most recent copy.  For myself there is no synchronizing via this method at work in order to respect policies around automated Internet traffic and not installing unsanctioned software.  So I have ALMOST solved my problem right?  The rest of the solution is provided by Keepass itself which has a handy importing feature.  You can import from another keepass database into a specified folder, and then the passwords themselves have a unique identifier to help make sure that you are truly synching the same password.

I hope this is helpful, let me know how you make out.
What password strategies work for you?
Greg.