image
image

Go Back   macosx.com > Mac Help Forums > HOWTO & FAQs

Reply
 
LinkBack Thread Tools
  #1  
Old September 16th, 2009, 09:55 PM
ElDiabloConCaca's Avatar
Registered User
 
Join Date: Aug 2001
Location: San Antonio, Texas
Posts: 12,912
Thanks: 7
Thanked 428 Times in 409 Posts
ElDiabloConCaca is a glorious beacon of lightElDiabloConCaca is a glorious beacon of lightElDiabloConCaca is a glorious beacon of lightElDiabloConCaca is a glorious beacon of lightElDiabloConCaca is a glorious beacon of lightElDiabloConCaca is a glorious beacon of light
How to choose a strong password (for anything!)

This is taken from another thread I posted in, but I believe it contains valuable information about making up a strong password that is not easily guessed (or "hacked," as some like to misrepresent it):

Quote:
I don't mean to come off sounding like a naysayer, but someone guessing a weak password should not and is not considered "hacking," nor does it matter whether or not you use Windows, Mac, Linux, UNIX, DOS, BeOS, or any other flavor of operating system in this case.

Hotmail is available to everyone, regardless of platform, so the type of computer you use has absolutely zilch to do with the "hacking" of a Hotmail account.

A weak password is usually the culprit, as many here have found, and exploiting a weak password is the simplest of "hacking" techniques, though it can hardly be called "hacking." Your Hotmail password was simply guessed by someone -- it was not "harvested" by malware installed on your Mac.

It does sound like Hotmail tech support is handing out canned answers to common problems:

"Someone hacked into my account!"

"Well, that's because more than likely you're infected with malware."

I think, more than likely, that Hotmail accounts that have been compromised have been compromised because people choose extremely poor passwords, or use the same password across multiple sites -- both extremely unintelligent things to do, like using the exact, same key for your house, car, boat, lockbox, safe, and safety deposit box. Once they have one, they've got them all because little to no precaution was taken to protect anything.

This happens quite frequently (in fact, more frequently than it should, simply because of laziness). It's akin to building a fortress, complete with a moat, motion-sensing sensors, motion-sensitive lights, laser beams, crocodiles, sharks with lasers on their heads, spike pits and banana peels strategically placed throughout said fortress, then putting a plastic Fisher-Price lock on the front door -- rendering every other security precaution moot. A weak password is the weak-link "chink" in the armor that the sword passes through without effort: all that protection for nothing.

Lessons learned:

1) Don't use a weak password. Ever. At all. At any time. For anything. Use a password that is at least 8 characters long, and includes both upper- and lower-case letters, numbers, and symbols. The 8-character requirement is because even with the super-est of super computers on the planet, all put together, all working in unison, it would take more years than you will live and your children will live to go through all the possible combinations of letters, numbers and symbols. It is programmatically infeasible to guess a strong, 8-character password in any reasonable amount of time. With 7 characters, you're talking a day -- maybe hours. 6 characters takes minutes. 5 characters would take seconds. You get the drift.

2) Don't use the same password for two different ANYthings. "But I can't remember all those passwords!" Tough titty. Get over it. Get a better memory. Get a piece of paper and a pencil. Get something.

3) Your password should change, at the very minimum, twice a year, and ideally once a month. Yes, it's tough to remember all those new passwords. No, no one has sympathy for you. If that's the toughest thing you have to do to protect your sh*t online, well, I'd say that's a pretty easy life you've got going there.

4) There are no malware/viruses/trojans for Mac OS X that "harvest" Hotmail password nor spies on your keystrokes. At all. In existence. That's not the culprit, no matter what the boneheads at Hotmail tech support say.

A good password is something like, "Gg6y(0!h54".

A horrible password is "JLH_1976". That's my initials and my birth year. An equally pathetic password would be "1J9L7H6", for very obvious reasons. Choose a password that is gibberish -- has absolutely no meaning -- no significant dates -- no initials -- nothing that means anything to you at all. If you can remember the password without having typed it several hundred times, you have chosen an inferior, pathetic and lazy password.

Right now, we should all be hearing each other's feet scrambling out the door to the nearest password-protected website to change our passwords, once again.

[End rant]
__________________
Mac mini 2.0GHz 10.6.2 • 4GB • 320GB • Superdrive • 4 x 1TB USB 2.0 • LED Cinema Display
MacBook 2.0GHz Core 2 Duo - White 10.6.2 • 4GB • 250GB • CD-RW/DVD-ROM
iPhone 3G 8GB • iPod Touch 8GB • iPod Photo 60GB • iPod nano 1GB • AT&T U-Verse 12Mb/1.5Mb
http://www.jeffhoppe.com
Reply With Quote
  #2  
Old September 17th, 2009, 01:24 AM
Giaguara's Avatar
Chmod 760
 
Join Date: Nov 2002
Location: ~
Posts: 8,705
Thanks: 8
Thanked 107 Times in 106 Posts
Giaguara is a jewel in the roughGiaguara is a jewel in the roughGiaguara is a jewel in the rough
The problem with those @##@$ passwords is they are impossible to remember...
Here's some more password advice http://www.schneier.com/blog/archive...ng_secure.html
and secret questions advice http://www.schneier.com/blog/archive..._question.html
__________________
MacBook Pro | Dell Mini Inspiron 9 | Mac Mini | Newton 2000 | iPhone | Other Macs + servers
Twenty years from now you will be more disappointed by the things that you didn't do than by the ones you did do.
~ Samuel Clemens | Rants | Photos
Reply With Quote
  #3  
Old September 17th, 2009, 02:32 AM
chevy's Avatar
Leopardo Da Vinci
 
Join Date: Nov 2001
Location: Inside the black box, CH
Posts: 3,971
Thanks: 1
Thanked 7 Times in 7 Posts
chevy is on a distinguished road
Make sure that you can input your password on any computer... avoid passwords that are impossible to enter on an US keyboard (with éöàä) or one an Asian computer or you may be locked out when you travel.

On Windows, use 9 or more characters. On Unix (including MacOS X) 8 is enough (because of the way the password is encrypted in your computer).
__________________
My current machine is an iMac Core 2 Duo 2.16 GHz 24" and a MacBook Pro 13" with MacOS X 10.6. My oldest Apple was born in 1977.
GS/P/>SS d-(++) s+: a+ C+(C) U* P L+ E--- W++ N- o+ K? w O-- M++ V PS+ PE+ Y- PGP t+ 5 X+ R tv-- b+++ DI++ D+ G e+++ h---- r+++ y?
Time is not changing, I'm just traveling through time.
Reply With Quote
  #4  
Old September 17th, 2009, 02:51 PM
Jesse714's Avatar
Tech In Training
 
Join Date: May 2009
Location: Nampa, Idaho
Posts: 403
Thanks: 6
Thanked 35 Times in 33 Posts
Jesse714 is an unknown quantity at this point
I always use the amount of taxes taken out of my check, and then a word after it, and i change it every time i get paid. Its always easy to remember, and no one will really ever catch on. So for example 190.9o.u.t.


=]
__________________
MacBook 2.16 Core 2 Duo, 2 gigs of ram, 120 gig hard drive Snow Leopard 10.6
PowerBook G4 15" High Res 1.67PPC, 2 gigs of ram 160 gig hard drive Leopard 10.5.8

HTC MyTouch 3G 4 Gigabytes Unlocked, Rooted 2.0 Eclair
Reply With Quote
  #5  
Old September 17th, 2009, 09:00 PM
Registered User
 
Join Date: Jul 2005
Posts: 967
Thanks: 0
Thanked 10 Times in 10 Posts
simbalala is on a distinguished road
Keychain Access has a pretty good assistant for creating passwords and checking password strength.

Go to File -> New Password Item then click the Key. It brings up a password generator with several options and checks the strength.
Reply With Quote
  #6  
Old September 17th, 2009, 10:25 PM
pds's Avatar
pds pds is offline
conf User
 
Join Date: Oct 2002
Location: On the edge.
Posts: 2,317
Thanks: 0
Thanked 3 Times in 3 Posts
pds is on a distinguished road
Keychain access makes very strong passwords, but they are impossible to remember, so just forget them.

Copy and paste a really strong password into a word processor. Set the text color to white and zoom the screen a bit (cmd +). Then select the invisible password and drag it to the desktop. It will show up as a picture clipping and look rather inscrutable if you open it.

Rename the clipping to something cryptic - Buff 1 is my login name for a bank in Buffalo and Buff too is the password. (I don't live in Buffalo so it works for me.)

To login, I go to the page and drag the clippings to the appropriate field and hit return.


I keep them all in an encrypted disk image that I have well backed up so the only time I type a password is to open the disk image.

Only problem is getting them to work on a Windows machine.... but so far I've been able to work around that.
Reply With Quote
  #7  
Old September 17th, 2009, 11:30 PM
Mikuro's Avatar
Crotchety UI Nitpicker
 
Join Date: Mar 2005
Posts: 2,694
Thanks: 6
Thanked 54 Times in 49 Posts
Mikuro will become famous soon enough
There's always a compromise involved in choosing passwords. Convenience and security are opposing forces here, and you need to pick a spot in the middle.

I use many different passwords. Some are very short. Some are simple words. Some have been left unchanged for over a decade now. Some are virtually random, quite long and short-lived. It depends on what I'm securing. I always consider a few factors:

1. What do I stand to lose if the password is compromised?
2. How often do I need to use it?
3. In how many places do I need to use it?

I don't consider web forums, for instance, to be terribly sensitive, and I use them often, and I use them in many places. That tips the scales toward convenience. So I use relatively weak passwords for them. If someone cracks it....well, boo hoo for me. "Oh no! They can change my avatar!" It's not worth the inconvenience to use really strong passwords.

Random characters would be secure, but I say that random words would be even more secure. There are far more words than characters (a few hundred characters vs many thousands of words), so even if someone used a dictionary attack, they'd have a harder time cracking 8 words than 8 characters. And even though the 8 words will be much longer (could easily be over 50 characters), they'll also be much easier to remember. I'll admit it does get tedious typing such long passwords, though. Again, there's always a compromise.

I aim to thwart two theoretical adversaries when I want a "strong" password:

1. A supercomputer using brute-force or dictionary attacks.
2. Someone who knows virtually everything there is to know about me.

If both of them in tandem would not have a prayer or cracking the password, then I think it's quite secure.

My greatest concern is when I use a password on many machines. How do I know none of those machines were compromised? I would recommend changing important passwords the next time you get home after using it ANYWHERE else, EVERY time. But I realize that's incredibly inconvenient. Always a compromise.
__________________
Mac mini — 1.25GHz G4, 1GB RAM — OS 10.5.8

Useful programs: Privoxy, Butler, ffmpegX, VLC, Perian, Tofu, Wcalc
Reply With Quote
  #8  
Old September 17th, 2009, 11:41 PM
Satcomer's Avatar
In Geostationary Orbit
 
Join Date: Jul 2002
Location: Northern Virginia
Posts: 7,117
Thanks: 34
Thanked 190 Times in 185 Posts
Satcomer is a jewel in the roughSatcomer is a jewel in the roughSatcomer is a jewel in the roughSatcomer is a jewel in the rough
Well I have heard that iPassword really like the service since it also has an iPhone version that syncs with the desktop version. This might be a solution for people.
__________________
Mac Pro Dual 2.8 Quad (1st gen), 14G Ram, Two DVD-RW Drives, OS X 10.6.2
Mac Book Pro Core 2 Duo 2.16Ghz, SuperDrive, ATI X1600, 2GB RAM, OS X 10.6.2
2TB Time Capsule
32G iPhone 3GS Black
Reply With Quote
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Forum Jump


All times are GMT -5. The time now is 09:11 AM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.3.2
Copyright 2000-2010 DigitalCrowd, Inc.