Click here to Skip to main content
15,881,852 members

The Insider News

   

The Insider News is for breaking IT and Software development news. Post your news, your alerts and your inside scoops. This is an IT news-only forum - all off-topic, non-news posts will be removed. If you wish to ask a programming question please post it here.

Get The Daily Insider direct to your mailbox every day. Subscribe now!

 
NewsWe beg, implore and beseech thee. Stop reusing the same damn password everywhere Pin
Kent Sharkey5-May-20 11:30
staffKent Sharkey5-May-20 11:30 
GeneralRe: We beg, implore and beseech thee. Stop reusing the same damn password everywhere PinPopular
Super Lloyd5-May-20 14:30
Super Lloyd5-May-20 14:30 
GeneralRe: We beg, implore and beseech thee. Stop reusing the same damn password everywhere Pin
Kent Sharkey5-May-20 15:25
staffKent Sharkey5-May-20 15:25 
GeneralRe: We beg, implore and beseech thee. Stop reusing the same damn password everywhere Pin
Bernhard Hiller5-May-20 21:12
Bernhard Hiller5-May-20 21:12 
GeneralRe: We beg, implore and beseech thee. Stop reusing the same damn password everywhere Pin
kalberts6-May-20 2:35
kalberts6-May-20 2:35 
GeneralRe: We beg, implore and beseech thee. Stop reusing the same damn password everywhere Pin
MadMyche6-May-20 8:35
professionalMadMyche6-May-20 8:35 
GeneralRe: We beg, implore and beseech thee. Stop reusing the same damn password everywhere Pin
ZurdoDev6-May-20 1:21
professionalZurdoDev6-May-20 1:21 
GeneralRe: We beg, implore and beseech thee. Stop reusing the same damn password everywhere Pin
kalberts6-May-20 2:27
kalberts6-May-20 2:27 
I certainly do not trust password managers never to be compromised. Especially Internet based ones.

So I use a three-part scheme: where - who - security.

'Where' is how I think of the service: The (short) name of the web site, the kind of service etc. Usually masked, like for access to the postal service, I use 'præ' rather than 'post'. 'Who' is my nick or login name, either at the service or locally. 'Security' has one of three values, one for services where a break-in doesn't hurt me (e.g. if they read the local newspaper using my account), one where would like to people not to steal my identity, and the last one is 'secure', e.g. for banking.

Some services require password change every x weeks. Then I append a serial number to the 'who' part.

So I end up with a long (typically 12-15 char) password not suitable for bruteforcing. The merging of three words into one long one prevents dictionary lookups - after my masking (with a strong preference for using our Norwegian vowels, æøå, wherever allowed) it looks like line noise that cannot easily be broken into separate words. I could for example use 'kPnørwaya1tø' for Code [=key] Project, the Norwegian guy, a1tø (a masking of 'alto'; I was singing in a mixed chorus for a many years, so I use vocal terms as tags). I doubt that you would be able to find 'kPnørwaya1tø' by a dictionary lookup. 12 chars is at least 96 bits; that is a little too heavy for brute force lookup. It is also so long that people looking over my shoulder will loose track.

I easily remember not to use 'Code' but 'Key' for CodeProject. I use only a handful nicks, and usually only three different tags. The only part that gives me trouble is the serial number required for sites who inisist on frequent change: For one of them, I recently had a wraparound from 9 to 0 ... but it wasn't accepted, "You have used that password before"! So I extended it to hexadecimal. But I guess that at the next update I will go to two-digit serial no.

If someone picks up my CP password in cleartext (if you consider 'kPnørwaya1tø' cleartext Smile | :) ), they will see my 'private level' tag - assuming that they know the 3-level structure of it - and could use that to try to break in on other accounts of mine. But they would have to know my masking rules and what I consider my identity at the other site, and it would only work for sites at the same security level.

I have been in the habit of using such passwords for years. Even if I have forgotten the password, I rarely have to make more than two or three guesses to hit the right one - when 'CPnørwaya1tø' fails, I easily remember that I had masked 'Code' as 'key'.

The only thing I fear is keyloggers. A couple of years ago, the Norwegian Department of Justice proposed a law change that would give the police the right to infect any PC connected to the Internet (in Norway) with a keylogger, for eavesdropping every single word written by the PCs owner. (I am dead serious now!) Officially, they would not make use of this facility except in criminal investigations, but history shows that they do not always stay within such restrictions. (For phone, they already have the right to eavesdrop not only suspects, but anyone phone that the suspects have been in contact with. They can not, legally, go one step further, bugging all phones that have been in contact with phones that have been in contact with a suspect - they wanted to, but it was rejected.) Fortunately, the parliament rejected the proposed law change.

Nevertheless: Police investigators do not always respect the law. Nor do criminals. Either could have put a keylogger into my PC. So when I open and edit confidential documents, I disconnect from the internet. When I write high-security passwords, I do not type them in one stretch, but take a brief visit to another window where I can type something else - the keylogger won't know which characters go into which window. I know that I am paranoid, but they still may be after me.
GeneralRe: We beg, implore and beseech thee. Stop reusing the same damn password everywhere Pin
Richard Deeming6-May-20 2:44
mveRichard Deeming6-May-20 2:44 
GeneralRe: We beg, implore and beseech thee. Stop reusing the same damn password everywhere Pin
ZurdoDev6-May-20 2:55
professionalZurdoDev6-May-20 2:55 
GeneralRe: We beg, implore and beseech thee. Stop reusing the same damn password everywhere Pin
Richard Deeming6-May-20 3:26
mveRichard Deeming6-May-20 3:26 
GeneralRe: We beg, implore and beseech thee. Stop reusing the same damn password everywhere Pin
ZurdoDev6-May-20 3:32
professionalZurdoDev6-May-20 3:32 
GeneralRe: We beg, implore and beseech thee. Stop reusing the same damn password everywhere Pin
Richard Deeming6-May-20 3:49
mveRichard Deeming6-May-20 3:49 
GeneralRe: We beg, implore and beseech thee. Stop reusing the same damn password everywhere Pin
ZurdoDev6-May-20 3:54
professionalZurdoDev6-May-20 3:54 
GeneralRe: We beg, implore and beseech thee. Stop reusing the same damn password everywhere Pin
kalberts6-May-20 10:15
kalberts6-May-20 10:15 
GeneralRe: We beg, implore and beseech thee. Stop reusing the same damn password everywhere Pin
Richard Deeming6-May-20 23:21
mveRichard Deeming6-May-20 23:21 
GeneralRe: We beg, implore and beseech thee. Stop reusing the same damn password everywhere Pin
kalberts6-May-20 23:49
kalberts6-May-20 23:49 
GeneralRe: We beg, implore and beseech thee. Stop reusing the same damn password everywhere Pin
Richard Deeming7-May-20 0:27
mveRichard Deeming7-May-20 0:27 
GeneralRe: We beg, implore and beseech thee. Stop reusing the same damn password everywhere Pin
kalberts7-May-20 0:53
kalberts7-May-20 0:53 
GeneralRe: We beg, implore and beseech thee. Stop reusing the same damn password everywhere Pin
F-ES Sitecore6-May-20 2:33
professionalF-ES Sitecore6-May-20 2:33 
GeneralRe: We beg, implore and beseech thee. Stop reusing the same damn password everywhere Pin
ZurdoDev6-May-20 3:33
professionalZurdoDev6-May-20 3:33 
GeneralRe: We beg, implore and beseech thee. Stop reusing the same damn password everywhere Pin
Daniel Pfeffer6-May-20 4:31
professionalDaniel Pfeffer6-May-20 4:31 
NewsFree Windows 10, Linux, macOS open-source graphics editor: Inkscape 1.0 is out Pin
Kent Sharkey5-May-20 11:30
staffKent Sharkey5-May-20 11:30 
GeneralRe: Free Windows 10, Linux, macOS open-source graphics editor: Inkscape 1.0 is out Pin
Rob Grainger6-May-20 23:08
Rob Grainger6-May-20 23:08 
NewsNASA confirms work on a Tom Cruise movie to be shot aboard the International Space Station Pin
Kent Sharkey5-May-20 11:30
staffKent Sharkey5-May-20 11:30 

General General    News News    Suggestion Suggestion    Question Question    Bug Bug    Answer Answer    Joke Joke    Praise Praise    Rant Rant    Admin Admin   

Use Ctrl+Left/Right to switch messages, Ctrl+Up/Down to switch threads, Ctrl+Shift+Left/Right to switch pages.