Results 1 to 10 of 10

Thread: How to Survive the Password Apocalypse

  1. #1
    Banned

    Join Date
    Feb 2012
    Posts
    2,361
    Thanks
    166
    Thanked 1,206 Times in 607 Posts
    Rep Power
    0
    Reputation
    16631

    Default How to Survive the Password Apocalypse

    The Heartbleed vulnerability clearly again demonstrated that we Internet users massively depend on our passwords. We need an extra password for each account: security experts preach this rule for years. If once a site or a user account is hacked or a vulnerability occurs, as now Heartbleed, then not all your data are in danger.

    Taken from :

    DON’T

    » Reuse passwords. If you do, a hacker who gets just one of your accounts will own them all.

    » Use a dictionary word as your password. If you must, then string several together into a pass phrase.

    » Use standard number substitutions. Think “P455w0rd” is a good password? N0p3! Cracking tools now have those built in.

    » Use a short password—no matter how weird. Today’s processing speeds mean that even passwords like “h6!r$q” are quickly crackable. Your best defense is the longest possible password.

    DO

    » Enable two-factor authentication when offered. When you log in from a strange location, a system like this will send you a text message with a code to confirm. Yes, that can be cracked, but it’s better than nothing.

    » Give bogus answers to security questions. Think of them as a secondary password. Just keep your answers memorable. My first car? Why, it was a “Camper Van Beethoven Freaking Rules.”

    » Scrub your online presence. One of the easiest ways to hack into an account is through your email and billing address information. Sites like Spokeo and WhitePages.com offer opt-out mechanisms to get your information removed from their databases.

    » Use a unique, secure email address for password recoveries. If a hacker knows where your password reset goes, that’s a line of attack. So create a special account you never use for communications. And make sure to choose a username that isn’t tied to your name—like m****n@wired.com—so it can’t be easily guessed.


    Have you already changed your password(s)?

    If not, then immeadiately do so, use a password manager like ...


    -----------------------------



    The comic author illustrated the vulnerability with a stick figure that converse with a server: the male sends a message to the computer to see whether the applicant still connected. It consists of three parts: the question "you still there?", in a word, the computer should respond with the word, and the number of characters of the word. The "Heartbleed" error is that you can send a number of characters the server, which is much greater than that of the desired response. An example: "reply with 'Hat', in 500 characters." To the computer with the word responds "Hat" and another 497 characters that reside in his memory.

    The male reveals so much more information than it should. May also be passwords, credit card details or other secret information about users.
    Last edited by jwoegerbauer; 12-04-14 at 06:07 PM. Reason: img added

  2. The Following 2 Users Say Thank You to jwoegerbauer For This Useful Post:

    pheggie (16-04-14),tristen (16-04-14)



Look Here ->
  • #2
    Junior Member
    Join Date
    Feb 2014
    Posts
    89
    Thanks
    0
    Thanked 23 Times in 12 Posts
    Rep Power
    131
    Reputation
    240

    Default

    Nice post I must say. these days Passwords should be changed regularly. I also say that there should be another way of protecting ourselves rather than just passwords. I have seen some company that was acquired by Google that introduced the concept of voice passwords that we might be implemented soon.

  • #3
    Junior Member
    Join Date
    Jan 2008
    Posts
    38
    Thanks
    283
    Thanked 4 Times in 3 Posts
    Rep Power
    200
    Reputation
    45

    Default

    I was listening to Steve Gibson talking about Heartbleed and security in general, he uses LastPast for his passwords so I downloaded the free one a couple of weeks ago.
    Very impressed atm, well until the Last Past vault is hacked, but then if its good enough for Steve then its for me. LastPast has placed a site ssl checker on their site since Heartbleed.

  • #4
    Banned

    Join Date
    Feb 2012
    Posts
    2,361
    Thanks
    166
    Thanked 1,206 Times in 607 Posts
    Rep Power
    0
    Reputation
    16631

    Default

    Even the online password manager LastPass was affected by the heartbleed gap. Wondering who trusts such an online service furthermore. An offline password manager surely is the better alternative.

  • #5
    Senior Member
    BillyGoat's Avatar
    Join Date
    Jan 2008
    Posts
    2,039
    Thanks
    845
    Thanked 470 Times in 242 Posts
    Rep Power
    341
    Reputation
    3754

    Default

    Quote Originally Posted by jwoegerbauer View Post
    Even the online password manager LastPass was affected by the heartbleed gap. Wondering who trusts such an online service furthermore. An offline password manager surely is the better alternative.
    Yeah it's called a pen and paper. If your mind cant remember all of them.
    Last edited by BillyGoat; 16-04-14 at 01:08 PM.

  • #6
    Banned

    Join Date
    Jan 2008
    Posts
    2,783
    Thanks
    1,262
    Thanked 1,871 Times in 886 Posts
    Rep Power
    0
    Reputation
    27488

    Default

    Does password manager use an offline master password and is the danger your computer dies you've lost all your passwords? or does it back it up to usb drive. Never used a program like keypass.
    Some workplaces don't let you use your own programs or a USB for example Department of Defence civilian workers can't.

  • #7
    LSemmens
    lsemmens's Avatar
    Join Date
    Dec 2011
    Location
    Rural South OZ
    Posts
    10,616
    Thanks
    11,900
    Thanked 7,077 Times in 3,348 Posts
    Rep Power
    3162
    Reputation
    132912

    Default

    A post it note with you password/s stuck on the side of your screen! Nobody ever looks there for passwords.

  • #8
    Premium Member
    Join Date
    Jan 2008
    Location
    Melbourne
    Posts
    855
    Thanks
    246
    Thanked 87 Times in 69 Posts
    Rep Power
    244
    Reputation
    886

    Default How to Survive the Password Apocalypse

    Inside back cover of the 'Spiral Notebook' works a treat too

  • #9
    Crazy Diamond
    Tiny's Avatar
    Join Date
    Dec 2010
    Location
    Tasmania
    Age
    64
    Posts
    6,393
    Thanks
    11,003
    Thanked 5,437 Times in 2,652 Posts
    Rep Power
    2157
    Reputation
    89077

    Default

    I have all my passwords & sign in details in alphabetical order on several pages in a Lotus word pro file that is protected & encrypted by 1 easy for me to remember master password.
    Every time I change passwords for my bank or other website, it's simple to edit my list.

    This can also be done in Microsoft word, however I prefer the lotus format for this.
    Cheers, Tiny
    "You can lead a person to knowledge, but you can't make them think? If you're not part of the solution, you're part of the problem.
    The information is out there; you just have to let it in."

  • #10
    Banned

    Join Date
    Feb 2012
    Posts
    2,361
    Thanks
    166
    Thanked 1,206 Times in 607 Posts
    Rep Power
    0
    Reputation
    16631

    Default

    Quote Originally Posted by pheggie View Post
    Does password manager use an offline master password and is the danger your computer dies you've lost all your passwords? or does it back it up to usb drive. Never used a program like keypass.
    That's exactly what KeyPass (introduced earlier here) does: An offline master password, a database with all your sub passwords, etc. The database of course can be stored on USB-stick.

    If interested in this freeware, here the user-guide:

  • The Following 2 Users Say Thank You to jwoegerbauer For This Useful Post:

    pheggie (16-04-14),tristen (17-04-14)

  • Bookmarks

    Posting Permissions

    • You may not post new threads
    • You may not post replies
    • You may not post attachments
    • You may not edit your posts
    •