Slashdot Mirror


The Psychology of Passwords

afabbro writes "According to this study, people's password choices put them into four groups: "Family", "Fan", "Self-Obsessed", or "Cryptic". I'm sure we're all good Cryptics here...now if only my users would stop being "Family"." And then there's the category "Stupid" for the zillions who use "Trustno1", "Swordfish", and "Password",

492 comments

  1. But what about ... by Anonymous Coward · · Score: 1

    all those 3733t h4x0r5 out there who use something like "733t"? Does that count as "cryptic", or is it "family" (for being a nickname)? I'd hate to think that the results included stuff as simple as that as "cryptic" - that would mean even fewer people have any security at all on their machines :(

    I rather prefer to use stuff that's over 6 characters in length, and a mix of letters, numbers and symbols, ideally case-sensitive but that I cannot control. It's not uncrackable, but it'll sure take more effort... and, with all the other, more easily-cracked machines out there, I feel pretty safe (but, just to be sure I'm not standing up and asking to be hacked, I'll post this anonymously anyways. I'm not (quite) as stupid as I look).

    1. Re:But what about ... by grammar+fascist · · Score: 1

      ...all those 3733t h4x0r5 out there who use something like "733t"? Does that count as "cryptic", or is it "family" (for being a nickname)?

      I'd call that "self-obsessed." Also in that category are "womanizer," "stud," and "2kewl4u."

      --
      I got my Linux laptop at System76.
  2. Re:my personal favorite... by Anonymous Coward · · Score: 1

    I had a similar experience with an ISP that I no longer use. They required that I give them a password over the phone, so I told them to set it to 'changeme'. Then I found out there was no way to change the passwords except calling them again.

  3. How to be a stupid and obnoxious Sysadmin... by Anonymous Coward · · Score: 1
    True story:

    While working at a place I won't name, I was told to modify a switch configuration by a grossly fat and obnoxious asshole of an NT sysadmin, who, for whatever reason, thought it part of his job to make mine as difficult as possible.

    naturally, since he didn't give me a password I assumed the switch didn't have one. No, he was just being an asshole. Made the long walk back across the building to Fatso's desk, "Uh, could you tell me the password please?"

    "Forget it" he replied. "What?" "Forget it" he repeated. Oh. Just to be sure I asked "No space in that?" "Nope." shithead smirked.

    Okay, stupid password, I though, hiking back to the switch. Password "forgetit" doesn't work. Hike back to Fatso's desk again. "Doesn't work" "Yes it does, he insists..."

    After about 5 minutes of trying to get him to respond like a human being, he gives a great theatrical sigh and writes "4get1t" on a postit, shows it to me and tears it up.

    Duh, I think to myself... and ask "Do you really think dopifying it like that will keep it from being cracked?" Well! Fatty give me a holier-than-thou look and says "You won't get very far working here with that kind of attitude..." Kee-rist...

  4. Re:The passward is electrifing by Anonymous Coward · · Score: 1

    Thats exactly what I did. I stored all of my passwords on my Palm Pilot in a (practically) unbreakable database. No problem with that right?
    Well...then the database program needed a password...and I thought...I have to make this the most complex password of all...Because if it is cracked, they will have ALL my passwords...
    So I made a completely random (yes truly random) password string. Then I was having problems remembering it...so I put it into the database on my palm. The problem is...The password to the database of passwords is in the database of passwords.
    Now I can't login to slashdot, cause I don't know the password.
    -tm

  5. Re:Is there a category for... by Anonymous Coward · · Score: 1
    I agree. I am a special agent, and in one mission, I had to infiltrate a certain building. The main door opened with a biometric hand-print.

    I got in by shooting a lone guard, then by severing his hand. From then on, I had a key to the whole place.

  6. Re:Random is the only way! by Anonymous Coward · · Score: 3

    I beat end users with random flailings of my arms and watch for 'letter-like' shapes which rise as welt on thier bodies. Grab a new user, repeat.

  7. My way by Anonymous Coward · · Score: 4
    The problem with this is that you then need a (secure) password management scheme. Unless you are a Rain Man type who can easily remember a large number of random passwords...

    I develop schemes now and again. I start with something easily recognizable, like 'So Long And Thanks For All The Fish'. Then I turn it into a 'random' password by a bunch of operations. For an example, I might take the second letter of each word (yielding oonholhi), then make characters 1 and 5 upper case, turn 2 and 6 into numbers (alphabetic value mod 10), then turn 3 and 7 into non-alphanumerics based on the keyboard layout. The pass would then be O5$hO2*i.

    That is sufficiently random for 90 day use or so. It would be weakened if somebody somehow guessed my scheme, but I pick a new arbitrary scheme every 90 days when I change all my passwords. Then I just have to remember one scheme and a bunch of key phrases for all of them.

    1. Re:My way by glitch! · · Score: 2

      Unless you are a Rain Man type who can easily remember a large number of random passwords...

      No, actually that is a problem :-) I can always remember my current passwords, but if I want to
      fire up an old system that's been on the shelf for the last year, it's going to be single-user boot...

      After generating fresh random password, I can ususally think of some nmeumonic to make it easy
      to remember. That brings the number of "symbols" down to three or four. What is funny is that the
      real random characters don't seem all that random after all. If I were just making up "random" chars
      off the top of my head, I would certainly not have picked many of the truly random ones. Go figure.

      90 days seems like a good password lifetime. Of course, that is another reason it is impossible
      for me to remember those really old ones.

      --
      A dingo ate my sig...
  8. Re:scooping hollywood by Mark+J+Tilford · · Score: 1

    Spoilers below; look at the link value to see text. /. trims spaces from links, so there are underscores instead. No; what they did was sneakier; pt 1 pt 2 pt 3 That's very good social engineering.
    -----------

    --
    -----------
    100% pure freak
  9. Re:More high school fun... by mosch · · Score: 2

    We got our high-school computer labs admin password the old fashioned way too. By rifling through his desk. Sure enough, we found the words 'lunch' and 'dinner' written on the inside cover of one of the manuals for no apparent reason. Admin password? breakfast. From then on we played a lot of networked doom.

    --

  10. Simple password trick by Phroggy · · Score: 2
    If you have trouble remembering secure passwords, here's a great trick:

    Take a made-up nonsense sound, like "kersplat" or "squish" or "blart" or "shazam" or something.

    Capitalize the first letter, easy to remember because words are often capitalized in English (Kersplat, Squish, Blart, Shazam).

    Pretend you're a l33t h4x0r and start replacing letters with numbers (K3rspl@t, Squ1sh, Bl4rt, Sh@z@m).

    Add some punctuation, either in front or behind (K3rspl@t!, Squ1sh?!?, !Bl4rt, ??Sh@z@m).

    Congratulations, you now have a reasonably secure password.

    One of these is very similar to a password that I used to use. Can you guess A) which password is similar, B) what the real password was instead, and C) which systems that password was used on?

    --

    --
    $x='S24;r)>63/* h@<5+oZ)32"5cz';$me='phroggy'x$];
    $x=~y+ -xz+\0-Tx+;print$_^chop$me for split'',$x;
  11. Re:Encryption by mce · · Score: 1
    I'm talking about using an encryption code when writing a new password on it. One that is simple enough for me to remember and decrypt without a computer (a pen and another "temporary" piece of paper will do).

    But don't count on me explaining it here. The enemy might be reading... The day that I die, the algorithm will die with me. Especially since those who find the paper are unlikely to know what it is.

    --

  12. Encryption by mce · · Score: 2
    I'm currently tracking 25 passwords (two of which are not computer related, actually). Some of them change too often to be sure that I'll remember them when in high need.

    So I've had to write them down "somewhere" bloody safe. As it happens, I ended up encrypting the piece of paper, such that the only thing that I definitely have to remember is the non-trivial decryption scheme. Of course, I also remember the passwords that I need most often, but for the others my encrypted paper has occasionally worked miracles.

    --

    1. Re:Encryption by 4thAce · · Score: 1
      As it happens, I ended up encrypting the piece of paper, such that the only thing that I definitely have to remember is the non-trivial decryption scheme. Of course, I also remember the passwords that I need most often, but for the others my encrypted paper has occasionally worked miracles.

      So how do you encrypt a piece of paper? Are you talking about using an encryption program (scanning in that sheet of paper?) or something like cutting it into little confetti-like bits and hiding them around your neighborhood? Actually, that approach is more like steganography.

      Has anyone mentioned Diceware already? (Another link here to the same site.) It's the system I like the most, especially because I get to real d6s in the process.

      --
      Inventor of the LOLbalrog meme.
  13. Re:simple passwd scheme by Have+Blue · · Score: 2

    Where do you work? :P

  14. Re:what about dates? by Isaac-Lew · · Score: 1
    She doesn't understand why I think it's stupid.

    She should use a 5-digit password like I do.

  15. Re:5 most common passwords!!! by J.+J.+Ramsey · · Score: 1

    "swordfish" is a bad choice for a password in any case because it is a word that can be found in the dictionary. Password crackers use dictionaries as sources of guessable passwords.

  16. Why stop at one? by gavinhall · · Score: 1

    Posted by polar_bear:

    I probably fit into the "fan," "cryptic," and "family" groups - When I make up passwords I tend to start with either something from my early childhood - say, my dog's name - or some obscure reference to something that I'm a fan of like maybe a "supporting" character from the Godfather or whatnot - then add mixed case, punctuation, etc.

    For example, I might pick Luca Brasi from the Godfather, but I wouldn't make a password "lucabrasi" or "LucaBrasi" -- It'd be something like "LuC4Br^$!#" ... something damn difficult for a dictionary attack to crack, but easier for someone like me to remember. (BTW, no, I've never actually used that password.)

    I can't go with a 100% cryptic password, b/c then I'd never remember the damn things - I don't use the same password on all of my systems or for online purchases, so I probably rotate about seven passwords and I change the ones I use with Barnes & Noble or Yahoo! Mail pretty regularly.

    The study is pretty interesting, though.

  17. Re:More high school fun... by bluGill · · Score: 2

    that was popular when I was in school. Every time I came across someone who did that I just did a control-C and then rm -rf (opps, I mean whatever the dos equivelent was. deltree of some such) I always hoped the student has some assignment due the next day that was almost done...

    I always said that when the program catches me like that, I don't trust it not to have logged someone else's password, and so my good dead for the day was to make sure no passwords were stolen.

  18. One time passwords? by drsoran · · Score: 1

    Maybe I missed it, but it seems the obvious answer to stupid passwords is to use non-reusable passwords and two-factor authentication. Either use something like OPIE or tokens like RSA's Securid cards. Then all the user has to remember is to carry their token with them and remember a simple pin number to unlock the passcode on their token. The only problem is it can get expensive with hardware tokens at about $50 a piece.

  19. Re:Does this count? by Danse · · Score: 2

    Wouldn't work these days. If you said "So where's the lead?" and were overhead these days, they'd think you were talking about bullets and expel you.

    --
    It's not enough to bash in heads, you've got to bash in minds. - Captain Hammer
  20. Re:More high school fun... by Ex-NT-User · · Score: 2

    At my old HS they were runnint Novel Netware with one of those butt ugly login screens. All of the student accounts were locked down to a rediculesly low 500K of storage. I "needed" more ( to install wolfenstein ) so I wrote a pascal app that looked "just" like the novel login screen that logged usernames and passwords. Then would give a cookie.."wrong password" message and show the real loing screen.

    After a week of going in just after class and starting it on every pc in the lab I had all of the privlidged account passwords.

  21. Why not write it down and carry it with you? by iabervon · · Score: 2

    If you just write it on a slip of paper and stick it in your pocket, you're probably really safe. It's rather unlikely that someone will mug you for it, and you can make it really hard to guess while not leaving it around the computer. Given the number of people who pick good passwords and then leave them where it's easy for an attacker to get at and obvious what it's for, you'd think people would think to carry them.

    I mean, they tell you not to carry your ATM PIN with you, but that's because you'd have the card and the PIN in the same place. You're probably not carrying your work computer with you...

    Also, you'll probably have memorized your password after using it a bunch of times by looking at the slip of paper, at which point, you can destroy it.

    1. Re:Why not write it down and carry it with you? by loraksus · · Score: 1
      Writing it down is kind of enough, inputting it into a watch that has two buttons to change letters is even better - I kind of did the same thing with a timex (forget the name now) watch and french verb conjugations. Ironically, by the time they were input, they werent needed.

      The slashdot 2 minute between postings limit:
      Pissing off coffee drinking /.'ers since Spring 2001.

      --
      1q2w3e4r5t6y7u8i9o0pqawsedrftgthyjukilo;p'azsxdcfv gbhnjmk,l.;/
  22. Re:npasswd and password nazism by jonabbey · · Score: 2

    That's why we have npasswd configured to not allow password reuse within a one year period. I have already had people tell me that they had picked out five passwords that they intended to rotate as the last used expire away. Those users can rotate if they like, but after a year I imagine they'll be more likely to pick a genuinely new one, especially since npasswd is such a hard ass about approving password choices.

    Ultimately, we hold the users responsible for maintaining reasonable security practices. My job in implementing npasswd was not to force everyone to do the right thing, it was to make it a lot harder to do something stupid. In the end, it comes down to the user.

    We do master a lot of systems from our master account database, so the user's single password gets them email, dialup, UNIX, Windows NT, AppleShare, etc. If our users needed to remember a dozen very difficult passwords, we couldn't do this, but with only one password needed for most of our network services, we hope it is not too unreasonable to require them to use decent passwords.


    - jon
  23. Re:npasswd and password nazism by jonabbey · · Score: 2

    I tried setting my password to 'mypassword1', and it told me 'Password not acceptable, may be derived from word 'mypassword'.

    npasswd may not be able to catch all variants of past passwords, but it is very very picky about what passwords are allowed, and if you choose a password that passes through npasswd, it is going to be a high quality password.

    No, a piece of software can't do anything about a user writing their password down on their forehead. But we have managers, and they can discipline or fire users for putting the lab's security at risk, if they do something truly stupid/negligent.

    Security is a process, and software's just a tool.


    - jon
  24. Re:npasswd and password nazism by jonabbey · · Score: 2

    The npasswd password history files are kept as a dbm of crypted password choices, so an intruder would have to find and crack that file, and by definition all of the passwords in that file would be hard to crack, as such things go.

    The one thing I'm not sure of right now is whether or not npasswd can support the use of md5 passwords or not. If it can, that would add a significant boost to the difficulty of cracking its files.


    - jon
  25. npasswd and password nazism by jonabbey · · Score: 3

    We recently implemented Clyde Hoover's npasswd password validation program, which does all kinds of password quality checks and a password history function, to prevent users from re-using their old passwords. We have incorporated npasswd into Ganymede here, along with a password aging function, and boy, what a change for our users. Users really can't have easy passwords any more, they have to change them regularly, and they can't re-use old passwords. The sysadmins in charge of network security here love it, because the odds that our users are using the same password for our network that they are using for Amazon and Slashdot is now dramatically reduced.

    Npasswd is very good at what it does. Npasswd supports checks against account information and a wide variety of dictionary files, with character transpositions, reverals, etc. No more 'us3rname' passwords for our users. Here's a partial list of the dictionaries that Ganymede with npasswd checks against in our environment:

    • Antworth -- Big dictionary, includes many inflected forms
    • CIS -- Words and names from Current Index to Statistics (partial)
    • CRL-Words -- Dictionary from Center for Research in Lexicography
    • Congress -- Names and nicknames of U. S. Congressmen
    • Domains -- Internet domains
    • Ethnologue -- Words from the "Ethnologue Database"
    • Family-Names -- Common family surnames
    • Given-Names -- Common first names
    • Jargon -- Words from the Jargon File
    • Movies -- Characters, actors, and titles from thousands of movies
    • Python -- Words and names from M. P. scripts
    • Roget-Words -- Words from 1911 R's Thesaurus
    • Trek -- Words and names from Star Trek plot summaries
    • Zipcodes -- Town and city names for all U. S. post offices

    If anyone here wants to make sure your users are using strong passwords, run don't walk and get npasswd, I say.


    - jon
    1. Re:npasswd and password nazism by pubudu · · Score: 1
      Hmmm does it catch this? mypassword, updated to mypassword1, updated to mypassword2 ...ect...

      It's actually amazing how often password changes of this sort actually occur. I used to work for a (now-all-but-defunct) software (later hardware) retail company that required the managers to change their passwords every month: the password was changed simply my incrementing the last number of the previous password. What is really amazing is that we retained the same system even after firing the guy upon whose name the original system (incrementation and all) was based; he was the one who introduced the system.

      Oddly enough, at the time the company abandoned all retail operations, this was not the thing that made me decide that it was headed for disaster. Although, now that I think on it, I do remember receiving an email that their customer database had been hacked...

      --
      ~~~~~~

      under-paid karma whore

    2. Re:npasswd and password nazism by Eil · · Score: 3


      That's what I do at work for all those stupid mandatory 90-day password changes. Of course, being a network run by morons, it keeps a list of ALL YOUR PREVIOUS PASSWORDS to enforce the fact that you your new password must be unique relative to the old ones. In other words, if someone ever cracks the password database, they get not only the current passwords, but the old ones so they can see patterns in the way the user chooses his passwords.

      Dumb dumb dumb. I'm a security-conscious fellow alright, but I do the above scheme of password changing simply so that if their systems ever get cracked, they might immediately see how stupid their enforced-password plan really was.

    3. Re:npasswd and password nazism by jgerman · · Score: 2
      Hmmm does it catch this? mypassword, updated to mypassword1, updated to mypassword2 ...ect...

      I doubt it.

      --
      I'm the big fish in the big pond bitch.
    4. Re:npasswd and password nazism by jgerman · · Score: 2

      In a way that's kind of cool, on the one hand it's a good way to ensure that passwords aren't easily reused. Of course, on the other hand one of the other replies to this post makes a lot of sense, it's definitly a hindrance to maintaining security to keep lists of old passwords around.

      --
      I'm the big fish in the big pond bitch.
    5. Re:npasswd and password nazism by acceleriter · · Score: 1
      People forced to change passwords and to use passwords with a certain distance from old ones (e.g. no "pass1," "pass2," . . . "passN" will just write them down and/or use the same password across systems with varying degrees of security (e.g. intranet for reading the employee manual and Accounts Payable's mainframe). Then where's your security?

      I work in a shop with a system that remembers four passwords. Users routinely change their passwords five times one right after another. You've probably already guessed that the fifth password was the same one the user was using prior to the forced change.

      --

      CEE5210S The signal SIGHUP was received.

  26. Re:Another stupid password trick by Jaeger · · Score: 1
    I did that for a while when I worked as a lab assistant. I typed my password in Dvorak into the QWERTY keyboard and everything worked great, until I wanted to mount my share from my room or something. It took thirty second to recreate the password as I figured out which key I would have typed, figuring out what its QWERTY equivilant was, and typing the key (in Dvorak), which proved to be rather obnoxious.

    Fortunatly, my typing managed to avoid becomming jibberish, and I still use Dvorak, but passwords that aren't quite that obscure.

  27. Re:Is there a category for... by dattaway · · Score: 2

    I tend to configure /etc/issue so that it prints the root password just above the "login:" prompt.

    Nice way to tease crackers. Too bad telnet doesn't allow root to login, but requires su'ing from a user account.

  28. passwords by VAXGeek · · Score: 5

    On some enterprise systems, the administrator has the option to have passwords checked against a dictionary for common words, palindromes or other easily guessed passwords. If you are interested in such "smart" password software, check out npasswd at: http://www.utexas.edu/cc/unix/software/npasswd/
    - -----------
    a funny comment: 1 karma
    an insightful comment: 1 karma
    a good old-fashioned flame: priceless

    --
    this sig limit is too small to put anything good h
    1. Re:passwords by Syberghost · · Score: 2

      Yeah, and because folks with root can bypass this, every single time I survey a new system I find at least one account with "Senior" in the GECOS field and the password set to the userid...

      -

    2. Re:passwords by greenrd · · Score: 1
      Only by a ridiculously tiny amount. Think about it. There are far more non-words than words 8 ASCII characters long.

    3. Re:passwords by idistrust · · Score: 1
      On some enterprise systems, the administrator has the option to have passwords checked against a dictionary for common words, palindromes or other easily guessed passwords. If you are interested in such "smart" password software, check out npasswd at: http://www.utexas.edu/cc/unix/software/npasswd/

      If I'm correct, I believe that Linuxconf has this feature too.

      --

      --Ask a silly person, get a silly answer.

    4. Re:passwords by Trepalium · · Score: 1
      You don't see people putting their 4 digit bank pin on a post it note, right?
      Not on a post-it-note, but I have seen people write it on their cards, or on another place in their wallet or purse. The entire stupidity of password changing regimes comes from the fact that without motivation, users seem to do a piss poor job at choosing passwords. As the IT password policy gets more strict, the users find new ways of subvirting the system to keep their "easy to remember" passwords.
      --
      I used up all my sick days, so I'm calling in dead.
    5. Re:passwords by jfmiller · · Score: 1
      My friend once got a job with one of these. He was at a summer internship with his Co. when sevral of the computers got brokeninto and files deleted by a disgrunteled network tech. the CIO ran one of these on the password file and my friend was the one of only 4 out of 250 who didn't get guessed. he was hired to replace the network tech.

      JFMILLER

      --
      Strive to make your client happy, not necessarly give them what they ask for
    6. Re:passwords by Animats · · Score: 2
      I first solved this problem back in 1984, with the Obvious Password Detector. But it was early, and people didn't realize the problem would be serious back then.

      My old Obvious Password Detector requires that passwords have trigraph statistics not found in the English language. This can be validated with a tiny piece of code and a modest-sized bitmap. The bitmap of trigraphs was built from the UNIX spelling dictionary, so 100% of words in that dictionary will be rejected. But only about 20% of random letter sequences are rejected, so if you choose some junk character sequence, that's usually OK. There's thus no need for a dictionary or any complex code that might contain a leak in the Obvious Password Detector itself.

      If this had been used from the mid-80s onward, brute-force password cracking would have been stopped before it started. And it's been free, open-source since 1984.

    7. Re:passwords by shepd · · Score: 1

      You do realise the result of forcing users to choose passwords that make no sense, right?

      Post it notes with them written on, tagged all over. That and a huge headache for the support department ("I can't come up with a password that works. Can you give me one?").

      That idea, and the idea of forcing password changes every couple of months, are the exact cause of people writing their password all over (remember the big list of different passwords to the school computer written on the desk in Wargames? That part of the movie is real life).

      You don't see people putting their 4 digit bank pin on a post it note, right? Why? Because they set it and that's it -- they never have to come up with a passcode again. If they can keep their mouth shut (and especially with money people do) everything is good.

      Sorry, just a rant I had to get out. :-)

      --
      If you could be told what you can see or read, then it follows that you could be told what to say or think - BoC
    8. Re:passwords by amitv · · Score: 1

      This has been in Debian for quite some time (Not sure about the other major distributions)
      apt-get install libpam-cracklib

      ---
      Can you imagine a beowulf cluster of theese?

      --
      Can you imagine a MOSIX cluster of these?
    9. Re:passwords by MrTilney · · Score: 2

      Or just use most common linux distros with standard configs.

    10. Re:passwords by Popocatepetl · · Score: 1

      The bad thing about systems that do that is they actually reduce the number of possible keys. The implication is there...

    11. Re:passwords by Popocatepetl · · Score: 1

      Point taken.

  29. Re:Is there a category for... by jtseng · · Score: 2

    Is there a category for the idiots that write their passwords on post-its and stick them to the bottom of their keyboards?

    Oh, so THAT's how my wife found all that pr0n on my private share...

    --

    Sanity.html - Error 404 not found

  30. Re:Is there a category for... by armb · · Score: 1

    > severing his hand. From then on, I had a key to the whole place.

    I realise you were joking, but: that's why they make hand and finger scanners that check for a warm hand with a pulse, and iris and retina scanners that check the eye responds normally to light (and has blood moving in the vessels in the case of retina scans).

    --

    --
    rant
  31. I used to use just <CR> by EngrBohn · · Score: 1

    Of course, that was 14 years ago.
    cb

    --
    cb
    Oooh! What does this button do!?
  32. Re:My /. password is... by howardjp · · Score: 1

    So we were joking about the phone system manual which takes 3 pages to
    explain how to dial a number. I was following the mock instructions and
    dialing. "1-8-0-0...I don't know, dial something" so I continued with
    "I don't know" Apparently I dialed more than seven numbers. Well, the
    phone (on speaker) says, "You have not dialed the correct access number,
    please try again." My mananger looks and me and says, "Great, now you
    are going try to break in, aren't you?" "Of course," I say,
    "1-2-3-4-5." "Ring...ring...Hello?" Sometimes, they make it too easy.

  33. Re:Random is the only way! by "Zow" · · Score: 2

    #!/bin/sh
    head -c 6 /dev/random | mmencode

    Much easier & faster, and certainly just as random as your cup of tea (of course, you have to be on a system with a reasonable /dev/random).

    -"Zow"

  34. Re:Random is the only way! by garcia · · Score: 2

    I prefer to take stupid phrases that no one else would think of (something like making a phrase to remember quiz items) and take the first letters and sound out a word for it.

    pretty easy to make up, easy to change, and easy to remember.

  35. Stupid passwords by cluening · · Score: 2

    My winner under the Stupid category is the "admin" when I was in high school. He choose the great password of "none" for his personal account, which was easily cracked with a simple dictionary. Of course, he was really one of the biggest fools I have known in my life, so I am not really all that surprised...

    --
    Posted from the wireless couch.
  36. Re:problem by Art+Tatum · · Score: 1

    Plus, all they really have to do is get you to touch something from which they can lift the prints. It probably wouldn't be too hard to fabricate a surface with the appropriate ridges and valleys.

  37. Re:Link for "Swordfish" routine by Art+Tatum · · Score: 1
    Too bad most people have never heard of the Marx Brothers

    You said it! I get awfully annoyed with people who think that "Friends" is the pinnacle of comedy.

  38. Re:Cryptic == bad by Doctor_D · · Score: 1

    I agree cryptic passwords are bad for users. But when I used to create user accounts I used a random password generator. They still weren't the best passwords, but better than they would choose on their own. And definatley better than the practice of the previous admin used to do... (companyname1) Besides they always changed them anyway, usually for the worse.

    Granted for my user accounts and the root accounts I used passwords that looked like line noise. (Of course I kept a password list in my pilot in an encrypted area...god help if I forgot the password.) I unfortunatley found a problem with the HP9000's that they won't accept characters outside of a-Z and 0-9 on console. Not a great thing when needing to get logged in on console as root.

    I also kept the users in check by once a quarter running john the ripper against the password file and then mailing the IT manager the list of compromized passwords. He then sent a politically correct e-mail to the users telling them to change their password, and gave suggestions on better passwords. Even then we always had the same people with stupid passwords, they usually changed them by adding 1 to the number in their password (ie pass1 became pass2).

    It's one of those basic security principles, yet is sooo hard to get people to follow.

    --
    "If you insist on using Windoze you're on your own."
  39. Re:Passwords are an unfortunate necessity... by mandolin · · Score: 1
    Someone please tell me how the fsck you have a "hint" to remind you the password you selected is "24885sfjsfsjf82's"

    Ok: 2->4->8 is doubling 1 3 times, and 8-5 = 3. followed by s. followed by a 7 letter palindrome. Now think of the B52's, but add that magic number 3 back to the first digit.

    See? Shouldn't be hard to think up a compressed hint for that ;)

  40. Re:Other categories by mandolin · · Score: 1
    www.ugcs.caltech.edu/~werdna/sysadmins.html

    I laughed at the entry that read:

    MANIAC: Writes script that kills all the daemons, clears all the print queues, and maybe restarts the daemons. Runs it once a hour from cron.

    The lpd daemons on the rh linux 6 boxen we had would mysteriously stop talking to the sun print server after awhile. Rather than figure out the problem like a good sysadm I wrote an hourly cronjob that restarted the daemons. I think they're still using it.

  41. Barcelona - shell account by Dogun · · Score: 1

    If anyone would like to hear an song inspired by this same subject, I would reccomend the band Barcelona and their song "Shell Account", a gripping tale of CS major trying obvious passwords and them working.
    Seriously, though, good band, good songs. Ultimate Geek band.

  42. Re:Random is the only way! by general_re · · Score: 2

    Ack! I forgot the best part. For users who are really paranoid, you can, in the next-to-last step, convert the number into triplets instead of pairs:

    633 436

    And then you convert both triplets to their Unicode decimal equivalents. Thus, the high-security password in this case is:



    This may not display properly on non-Unicode browsers/platforms. But those of you who can display them will see that they have the added advantage of not actually appearing on any keyboard, thus exponentially increasing the difficulty for anyone wishing to guess your password.



    BTW, for those who can't display them, decimal 633 is an upside-down lower-case "r", and decimal 436 is described as "Latin small letter 'y' with hook".

    --
    ABSURDITY, n.: A statement or belief manifestly inconsistent with one's own opinion.
  43. Re:Random is the only way! by general_re · · Score: 5

    That is not nearly random enough. You need an algorithmic process that'll give you something really random.

    Here's what I do. First, you take a phrase, famous or obscure. For this example, I'll use a little Shakespeare - "He hath a daily beauty in his life that maketh mine ugly."

    Then, you take the second letter of each word, ignoring any single-letter words, thus producing "eaaeniihaig" in this case.

    Then, you convert each letter to its decimal ASCII equivalent, giving us:

    101 97 97 101 110 105 105 104 97 105 103

    Then squash that all into a single number in that order, producing:

    101979710111010510510497105103

    Then, you take the 5'th root of that number, and drop any decimal places:

    101979710111010510510497105103^(1/5) = 633436.01848182821643020050352705 --> 633436

    Then, you take THAT number, and break it into pairs thusly:

    63 34 36

    Finally, you take the first pair and convert it back to its ASCII decimal equivalent, and that's your password. In this case ASCII 63 is "?", so your password is "?" (without the quotes, naturally).

    And that, my friend, is pretty damn random.

    --
    ABSURDITY, n.: A statement or belief manifestly inconsistent with one's own opinion.
  44. Re:The passward is electrifing by mooman · · Score: 1

    whups. missed a typo in the preview.
    The yahoo example should be 'y5934o' *not* 'y5934a'
    Sorry for any confusion.

    --
    In the Portland, Ore area and like card games? Check out: http://groups.yahoo.com/group/portlandgames/
  45. Re:The passward is electrifing by mooman · · Score: 2

    The answer to this is quite easy by using a (simple) password algorithm:

    1) Take that random number, say 5934
    2) Now for everyplace where you need a password, append/prepend the name of the site/computer to that string. So if you decided something like first and last letters, plus the random number, you'd get:
    yahoo.com = y5934a
    slashdot = s5934t
    etc.
    If that's too short (like for hotmail) use a full-name variant for those like ho59tm34ail.

    For better security, always use caps for one of the ends, and/or tack on some (consistent) non-alpha at beginning or end, whatever rules you want to always use.

    Benefits:
    1) You never need to "remember" a password. Just the numeric bit, which you get to reuse everywhere, and the rule for picking the letters.
    2) Unique password nearly everywhere. Getting one of them doesn't give access to the other sites, and pattern isn't obvious with just one.
    3) If you ever are required to change a password (or just want to be safer anyway), ditch the first random number and select a new one, using the same basic scheme with it for all new passwords. Worst case scenario is you'll have to make 2, maybe 3 guesses, at a site you haven't been to for a while....

    I've been doing this for about 4 years now and it works like a champ. I've lost track of how many times I've suggested this to users when they're griping about having to remember passwords, but they still give me a blank look and use something like their dog's name anyway. Lamers... ;)

    --
    In the Portland, Ore area and like card games? Check out: http://groups.yahoo.com/group/portlandgames/
  46. Re:I just have FPM generate them by tuffy · · Score: 1
    If you're going to use a password manager, why not just make all of your passwords the same anyway?

    All it takes is someone knowing the manager's password to get them all easily enough anyhow.

    If someone other than me has access to the password manager data in my home directory and knows the password to the manager, having my Slashdot password available to them is the least of my concerns...

    --

    Ita erat quando hic adveni.

  47. It's all about tradeoffs, ultimately by tuffy · · Score: 2
    I mean, if I wanted to be really secure, I'd come up with a whole bunch of hyper-obscure passwords, memorize them for weeks on end and use those - secure in the knowledge that nobody can read my mind.

    Of course, that would be silly.

    I have used my PDA for password storage, but it proved somewhat tedious to go back and forth between computer and PDA to input them (whereas FPM can copy straight to X11's cut buffer with the hit of a button). It's not impossible for someone to break into my box, steal FPM's password file and somehow steal the password to decrypt it, but I consider that a possibility remote enough to fall within my level of tolerance.

    I figure so long as the value of the passwords are less than the effort it would take someone to steal them, I'm protected from the most likely attacks.

    --

    Ita erat quando hic adveni.

  48. I just have FPM generate them by tuffy · · Score: 3
    With a password manager, I wind up with lots of passwords like "pXSvs2gQ", "3zRrtjBc" and "UA4urfVx" (to make up some examples). Sure, I have to remember one cryptic password to get into the manager, but then I can forget the rest (which, by my personal count, is 41 different user/password combos to remember - which I don't have time for).

    I recommend a decent password manager for everybody, since there's just too damn many sites that require them.

    --

    Ita erat quando hic adveni.

    1. Re:I just have FPM generate them by maraist · · Score: 1

      Get a PDA. Then the difficulty is bumped up a notch.. First they have to get access to your person.. Then they have to crack the PW-manager password. Then they have to figure out which password goes with which site (hopefully you didn't put all that info together).

      Only trick is if you lose your PDA. So maybe you should have a tape-archive with the info periodically. and put that into a safe where you have the only key.

      -Michael

      --
      -Michael
    2. Re:I just have FPM generate them by The+Flymaster · · Score: 1

      If you're going to use a password manager, why not just make all of your passwords the same anyway?

      All it takes is someone knowing the manager's password to get them all easily enough anyhow.

  49. Re:More high school fun... by sab39 · · Score: 2

    Hey, a bunch of people in my HS did that too.

    You wouldn't happen to be in Surrey, UK would you? ;)

    Stuart.

  50. Re:Writing down passwords isn't always stupid. by Syberghost · · Score: 2

    The advice "never write down a password" dates from back when a secure-enough password could be remembered reliably.

    This simply isn't true anymore. Any password that is easily remembered is likely to be easily crackable, because computer power is so cheap these days.

    Even Bruce Schneier has reversed himself and now recommends that you write your passwords down on a piece of paper, and then treat that paper like it was a significant amount of cash or a credit card; keep it in your wallet, or locked in a safe, and be aware of it's location at all times.

    Of course, people who write down their password on a sticky note and place it on their monitor are still idiots.

    -

  51. Best password creation scheme... by Garion911 · · Score: 3

    A friend of mine came up with a pretty nifty password creation scheme.. He lived on a rather busy street near a stop light.. So he would look out the window and pick out someone's licence plate number who was waiting at the light.....

    --
    Slashdot is like Playboy: I read it for the articles
    1. Re:Best password creation scheme... by Chelloveck · · Score: 2
      I grab two random license plates, concatenate them, and screw with capitalization. I've been using this method since 6th grade and it's always been secure enough.

      And in what situations, exactly, would this prove to be more secure than, say, taking one licence plate and not screwing with the capitalization?

      There's no need for horribly complex password schemes. Really, you can have passwords that are "secure enough" for whatever environment you're in without having to resort to major convolutions or a radioactive decay random number generator. Pick something not in the dictionary that couldn't be guessed even by someone who knows you. If you can work in capitalization or punctuation, that's great.

      Just make sure you eliminate everything that could reasonably be guessed or derived. (Don't use your mother's maiden name, not even backwards.) Once the cracker has to resort to a brute-force attack, any password is as good as any other.


      Chelloveck
      --
      Chelloveck
      I give up on debugging. From now on, SIGSEGV is a feature.
    2. Re:Best password creation scheme... by Sloppy · · Score: 1

      But everyone knows that the NSA sends several cars (with known-to-them plate numbers) to drive by everyone's house on a regular basis, in order to reduce the randomness of people choosing this way.

      And in England, they have street corner cameras watching all the traffic, just so that they can guess the passwords of people who use this technique.


      ---
      --
      As copyright owner of this comment, I authorize everyone to defeat any technological measure which limits access to it.
    3. Re:Best password creation scheme... by AntiFreeze · · Score: 2
      Haha. I can't believe someone else does this too.

      I grab two random license plates, concatenate them, and screw with capitalization. I've been using this method since 6th grade and it's always been secure enough.

      ---

      --

      ---
      "Of course, that's just my opinion. I could be wrong." --Dennis Miller

    4. Re:Best password creation scheme... by bad-badtz-maru · · Score: 1


      That would be the situation where someone is brute-forcing the password. The longer the password, the longer the brute-forcing takes.

      maru

    5. Re:Best password creation scheme... by Feynman · · Score: 1
      A friend of mine came up with a pretty nifty password creation scheme.. He lived on a rather busy street near a stop light.. So he would look out the window and pick out someone's licence plate number who was waiting at the light.....

      This isn't all that secure though. For example in Minnesota--where the standard passenger vehicle plate is three numbers and three letters (e.g., 123 ABC)--there are only (by my reckoning) 17,576,000 possible permutations. A cracking program that could test them one per second starting Jan. 1 would be guaranteed to find the correct one by July 22.

      Cake.

  52. ON KEyloggers by Ex+Machina · · Score: 1

    in a previous academic situation keylogged one of the public labs for about 3months... it was pretty revealing to see what kids had as their passwords. "kill" "boobster", etc.

  53. How did they conduct this survey? by Nate237 · · Score: 2

    The thing that cracks me up, is that they obviously had researchers go ask people for their passwords, and they gave them to them!

    I used to have an app on my PalmPilot that would generate random passwords and store them using IDEA. I was responsible for changing the root passwords at the ISP I worked at, and everyone hated it when I made them change.

  54. swordfish... [slightly OT] by cswiii · · Score: 2

    Wasn't it Sierra's Hero Quest where you had to utter a password to enter a house, or cave, or something? The password, if I'm not mistaken, was "schwertfische"; If you said, "swordfish", it responded with something akin to "Wrong game!" before kicking you back to from whence you came.

    Well, it was amusing... back in those EGA days...

  55. Comment removed by account_deleted · · Score: 1

    Comment removed based on user account deletion

  56. addresses by james_shoemaker · · Score: 1

    Are old addresses cryptic, or family? What about name + old telephone numbers? That way you get Alpha and numeric, and still can remember them.

  57. Re:Related poll by Aphelion · · Score: 1

    And it shows that 4% use "tacosux!" as their password. Riiiight.

  58. stronger passwords aren't by MarkMac · · Score: 1
    The following article makes the point that asking users to pick and memorize cryptic passwords that they must change every 60 days etc. is both unreasonable and usually unnecessary. Different types of accounts require different levels of security (e.g. if shadow passwords are implemented why worry so much about password cracking - be more concerned about keeping the root account secure). Instead, more effort should be expended on securing system rather than chasing down those users who forgot to include a digit in their password. And face it, in the real world a large corporation with thousands of users is NEVER going to get every user to pick a totally cryptic password.

    "Stronger Passwords Aren't"
    http://www.infosecuritymag.com/articles/june01/col umns_executive_view.shtml

  59. All login passwords cracked, except... by jgerry · · Score: 1

    I used to work for a very large US telecom, and one day out of boredom we ran a password cracker on our NT domain controller. Now, out of about 75 people in our department, there were only 2 passwords that could not be cracked... One was mine, the other one was our receptionist's.

    I think we laughed for weeks about that one. But it was also kind of shameful that a group of engineers had such weak passwords.

  60. Re:A few years ago... by Compuser · · Score: 3

    When I worked as an intern in a rather big
    corp which shall remain nameless all
    passwords for all computer were "welcome".
    The sysadmins claimed it made their jobs
    easier because they didn't have to remember
    passwords for all the machines.

  61. Cliff Stoll by sammy+baby · · Score: 5

    I once read an interview with Clifford Stoll, who was speaking about another interview he did on camera in his apartment. Apparently, the camera crew set him up seated in front of his computer. By the time the interview was aired, he realized his monitor - and the Post-It (tm) note with his root password on it - was clearly visible in the shot.

    The obvious retort is, "But anyone can read it!"
    No, the obvious retort is, "But anyone who can get inside the room can read it." At my place of bidnez, our administrative passwords all get written down, then placed in a fireproof safe, which is in our locked operations center. If you're confident that nobody is interested enough to read your passwords, that's fine. Just don't give any TV interviews.
    1. Re:Cliff Stoll by mgblst · · Score: 1

      ... but why did he have to have a copy or root/root on his monitor at all?? Surely he could remember that!

    2. Re:Cliff Stoll by FireWhenRady · · Score: 1

      Any password that you can remember without writing is down is most likely easy to crack.

      People just can't remember a 8+ character random sequence without some practice and anything less is crackable

    3. Re:Cliff Stoll by ysachlandil · · Score: 1

      Try using Passwords that are made up out of sentences, like so: This is a quite difficult passwd, eh? (First letter of each word:) Tiaqdp,e? easy to remember, hard to crack (with a dictionary) --Blerik

  62. Too many passwords by Sloppy · · Score: 2

    But honestly I feel for these people. I have a ton of passwords too. Some are hard some are easy some I don't know thanks to cookies. The point being ther ARE far too many passwords.

    IMHO, this is a very serious problem, and almost everyone has it. It isn't realistic to expect anyone to memorize 20 different randomized passwords for 20 computers, 20 web sites, etc.

    I think the Right Thing to do would be to memorize a single passphrase (that you never use as a real password for anything) and use it as a key, to encrypt the name whatever computer/site you're logging into, then hash the ciphertext down into some password-like form. Thus, the user would only have to memorize one secret, but his local login, Slashdot, and Amazon passwords would all be different.

    Naturally, no person could do this kind of thing in their head, so maybe that's the final excuse for carrying around a PDA or something. (The PDA wouldn't store passwords, it would just be for converting combining the passphrase+identity into passwords. So all you'de have to worry about would be someone compromising the PDA to store/forward your passphrase.)


    ---
    --
    As copyright owner of this comment, I authorize everyone to defeat any technological measure which limits access to it.
  63. Related poll by crow · · Score: 3

    This Slashdot Poll shows that 3% of slashdot users use "password" as their password.

  64. Re:Writing down passwords isn't always stupid. by Teferi · · Score: 3

    Yeah, if they have physical access to your home and box anyway, passwords aren't really going to stop anyone.

    --
    -- Veni, vidi, dormivi
  65. Re:The clueless disease by sharkey · · Score: 3

    He built redundant Cisco router configs for Slashdot until June 23, 2001.

    --

    --

    --
    "Outlook not so good." That magic 8-ball knows everything! I'll ask about Exchange Server next.
  66. Re:my personal favorite... by sharkey · · Score: 3

    Ah, yes. @Home. I get service through Comcast Cable in Indianapolis. In trying to get them to actually provide service, rather than just leaving the modem, I ended up talking to a senior level tech. I had to tell her where I was, so I did:

    @Home: Where are you located?
    Me: 73rd & Hoover.
    @Home: What is that near?
    Me: About 1/2 west of Meridian St.
    @Home: No, what's close to there on the map?
    Me: It's Meridian, US 31, runs down the center of town.
    @Home: I don't know where that is.
    Me: The middle of Indianapolis!!
    @Home: But what is that near?
    Me: Plainfield, Carmel, Avon, it's a big city in the middle of the state!
    @Home: What state is that?
    Me: Huh?
    @Home: What state is that?
    Me: INDIANA!
    @Home: What is that near?
    Me: What the hell are you talking about?
    @Home: We don't have any facilities there. What is that near?
    Me: What? Do you mean what States are nearby? OH, IL, MI...
    @Home: OK. We have service in Illinois. I put in a request for them to finish turning on your account.

    Bear in mind that I called my LOCAL cable company for this support, and ended up, on the same call, talking to this wizard, who apparently flunked 1st grade geography, and was stuck on that asinine question, "What is that near?"

    --

    --

    --
    "Outlook not so good." That magic 8-ball knows everything! I'll ask about Exchange Server next.
  67. Re:Writing down passwords isn't always stupid. by Elwood+P+Dowd · · Score: 2

    No, writing down your passwords is only stupid if all of your enemies will be able to find your written down password.

    Like, if you post their location to a very public place...
    --

    --

    There are no trails. There are no trees out here.
  68. Mine are good by Pope · · Score: 1
    Mix of upper and lower case, non-Alphabeticals, and numbers.

    However, since I can't remember them all, I put them in my NotePad DA (Mac, not Windows)

    No one else has access to my 'puter so I'm not worried... yet...

    --
    It doesn't mean much now, it's built for the future.
  69. My Favorite by Catmeat · · Score: 1

    LOLOAQICI82QB4IP Just say it out loud, and no I no longer use it.

  70. Re:fingerprints by cruelworld · · Score: 1

    Fingerprints are not unique.

  71. users amaze me by double_h · · Score: 2

    The thing that amazes me is when users boast about their passwords just out of the blue. One time I was helping a user who couldn't log in, and it took me about three seconds to spot the caps lock key that had been accidentally engaged.

    "Thanks so much for fixing that," the user told me gratefully. "I couldn't understand why it wouldn't work. I typed in password just like I always do. You know, my niece's name -- 'brittani', spelled with an 'I'..."

    I'm amazed on a daily basis at how differently some people's minds work.

    - HH (proudly using 'lovesexgod' as a password since 1993).

  72. I'm doing this study... by RandomFactor · · Score: 5
    the most common type of password attack comes in the form of "social engineering"

    *cough*

    Like giving your password to someone doing a study on passwords?

    --
    --- Mercutio was right.
    1. Re:I'm doing this study... by canning · · Score: 1
      yeah, I'm doing a study on credit cards......send me yours and I'll include you in it.

      One user was amazed that I knew his password but he had it plastered all over his monitor.


      Murphy's Law of Copiers

      --
      I love the smell of Karma in the morning
  73. Re:Too many passwords? by r2ravens · · Score: 2

    I agree.

    When I used to teach beginning internet classes and manage the student lab at a community college, I made the same suggestion.

    If I picked up that the students/users were savvy or interested, I also suggested adding other modifications to the acronymized sentence.

    Substitute punctuation or numerals for words, suffixes, prefixes, etc.

    @ = at
    contempl8 = contempl(ate)
    4nick8 = (for)nic(ate)
    (Way too obvious, I know)

    Alternate case in the acronymized sentence.

    Now is the time for all good men to = NiTt4AgM2

    If they insisted on using the 'family' category, I had them '1eet 5pe@k' the family name.

    Where I work now, passwords must be changed monthly so I suggest all of the above with alternatingly prefixing or suffixing the two digit month offset by some number they can remember.

    --
    War is Peace. Freedom is Slavery. Ignorance is Strength. - George Orwell or George Bush?
  74. Re:What I want to know. by MindStalker · · Score: 1

    Actually it is, cause I don't give a damn about slashdot.

  75. What I want to know. by MindStalker · · Score: 2

    How many idiots actually gave their real passwords to this study. I hope to god the "cryptics" just gave them an example. Hmm how big was this study? Can I get the "results" hint hint, nudge nudge.

    1. Re:What I want to know. by jhoffoss · · Score: 1

      Damn...just used the last mod point i had today...
      ---

      --
      Linux: The world's best text-adventure game.
    2. Re:What I want to know. by emok · · Score: 2

      What a great scam for AOL chat rooms...

      "Hi. I'm doing a study on the passwords that computer users choose. I was wondering if I could ask you a few questions..."

    3. Re:What I want to know. by 4mn0t1337 · · Score: 1
      Would they really have to give them the password? I think the nature of the categories dictates that you (subject) inform the study of *why* you choose a password (or what it means), rather than what it is.

      For example, if you were given a password of "Marilyn" would that be "Fan" (Monroe, Manson?) or possibly "family"? (Aunt Marilyn) Or what if your Aunt *was* Marilyn Monroe?? (Or Manson?)

      Marilyn, while mostly obvious, is more clear cut than a lot of other potential passwords. I think they probably had a series of multiple choice questions or the researches had to spend enough time with each subject to interview them.

      ______

      --

      ______
      Once: you're a philosopher. Twice: a pervert.

  76. Mr.Root by angst_ridden_hipster · · Score: 2

    Passwords aren't always the limiting defense in security.

    Back in the day, we had all the machines in the research lab have the root password of "Mr.Root" (or "Mr.System" for the VMS machines).

    It was all pretty secure.

    We were not connected to the outside world on a network, and you had to pass through two safe doors to get to the lab. The combination on those safe doors was swiping your badge in the reader and waving your ID to the guys with the guns.

    Never had a single compromised system, either.
    bukra fil mish mish
    -
    Monitor the Web, or Track your site!

    --
    Eloi, Eloi, lema sabachtani?
    www.fogbound.net
  77. Re:I'm with Stupid -- by maeglin · · Score: 1

    Now, it's not necessarily stupidity... Sometimes there comes a point when you just don't care..

    At work I've got database passwords, AIX and Solaris passwords (which the administrators have set up with mutually exclusive password rules), Linux on my laptop and at home, Exchange, VSS, NT and PBX passwords... So, when Novell asks you to enter a new unique password for the fiftieth time (it's obviously more secure to make you change it EVERY TWO WEEKS) security really isn't your top priority... Things like "novellsucks" and "password" start looking reasonable.

  78. Re:Dvorak Rules! by skullY · · Score: 1
    I use the Dvorak layout on my keyboard, and that is a pretty good password protection scheme in an of itself! I'll use easy to remember words, like linuxrules, and convert them to the qwerty layout. So, linuxrules would be pglfbofpd; Plus, it freaks people out to start typing at the machine, so that is a pretty good protection mechanism!
    Dvorak owns. I got a DvortyBoard which swithces between dvorak and qwerty. I just hit Dvorak lock, type my password as normal, and then turn dvorak back on. Of course, I'm screwed on a qwerty keyboard for 5 minutes or so while I remeber the translation.
    --
    When I was able to do my own spam-armoring, you got a chance to email me. Now you can only hope I see your reply.
  79. Re:Systematic is the only way! by iapetus · · Score: 2
    I suppose "western" books only (not asian, russian, etc..)

    Why not? Just stick to a standard (or even better - slightly nonstandard) way of transliterating, and you shouldn't have any problem.

    Of course, the downside of this approach is that if someone discovers your system, all the passwords you ever had are then known to them.

    --
    ++ Say to Elrond "Hello.".
    Elrond says "No.". Elrond gives you some lunch.
  80. Score -1: Off Topic by ConceptJunkie · · Score: 1

    Steve:

    You're the first person I've seen on /. to actually spell "mnemonic" correctly. When I read the horrible spelling and grammar on /. I fear for our future. Thanks for having a clue.

    Rick

    --
    You are in a maze of twisty little passages, all alike.
  81. You're lucky by chryptic · · Score: 1

    My user always try to use passwords that are too simple to warent post-its.

    --
    The two most common things in the Universe are hydrogen and stupidity. -- Harlan Ellison
  82. Re:Random is the only way! by chryptic · · Score: 1

    I use sections from product keys on software. Those things look pretty damn random to me.

    --
    The two most common things in the Universe are hydrogen and stupidity. -- Harlan Ellison
  83. Re:More high school fun... by tulmad · · Score: 1

    Bah, I think we had the same system at my school. Except we just sorta reverse-engineered the encryption on the password system. We already knew one of the passwords, all it took was getting the password file and determining how the encryption worked. Turned out to only be a simple ROT- system. How pathetic.

    --
    "In case of emergency, break glass. Scream. Bleed to death."
  84. Re:problem by GregWebb · · Score: 2

    This is the advantage of iris recognition. It's reliant on there being blood flowing through the eye when it's checked.

    --

    Greg

    (Inside a nuclear plant)
    Aaaarrrggh! Run! The canary has mutated!

  85. Re:Random is the only way! by Garin · · Score: 3

    Dude, who cracks passwords any more? These days, it's far more likely the bad guys will get a root shell on a particular box before they'll crack passwords. Then it doesn't really matter any more, does it?

    IMNSHO, picking ridiculous passwords is a major waste of effort. All that is necessary is to "beat" all password guessers by a reasonable margin -- ie, stay well out of their dictionaries. As long as you'll make it so that dictionary attacks are no good, you'll have pushed the weakest link in your security on to something else.

    This means that pseudo-random passwords are easily good enough. No, "s00P3rS3kr1t" isn't a good choice for a password, but "SdN4N.Stm" will probably foil any dictionary.

    Heck, these days if someone manages to get a shadow file, then they're almost to the point where they don't need it any more.

    --
    In any field, find the strangest thing and then explore it. -John Archibald Wheeler
  86. Re:My (easier) way by MrNixon · · Score: 1

    What, when someone bludgeons you with a dictionary until they tell you your password?

  87. Another "what we did in high school" by AntiFreeze · · Score: 2
    Okay, I'm particularly proud of this one.

    In high school, someone managed to get a copy of /etc/passwd when it was accidentally unshadowed for a day [NIS went down and it was a quick fix and no one realized it broke shadow until too late].

    So we ran john (I think that's what it was called) on the password file to see what it could decrypt. All the important accounts had secure passwords, but lots of users had really stupid passwords. The most common ones were "password" and "hello123".

    So what we did was hash each of those, and then hash the hashes. We then ran the program to brute-force the double hash, and lo and behold, it said the password was "password" or "hello123". But neither password nor hello123 would be valid.

    I just really liked that method, because it's a sneaky way of creating a pseudo-random password, and if you use it correctly, you can screw with people's minds. Of course, as soon as someone realizes that this is what you've done, it's very easy to get around. But that's not the point =]

    P.S. if you can't figre out what I'm talking about, I'm sorry for the incoherent babbling, I barely got any sleep.

    ---

    --

    ---
    "Of course, that's just my opinion. I could be wrong." --Dennis Miller

  88. wats wrong with ********* by Unknown+Poltroon · · Score: 1

    Works wvery time, wasy to remember, noone can read it over my shoulder.....

    --
    All Troll + "offtopic" mods are meta moderated as "Unfair", because you abused the system.
  89. Re:Is there a category for... by Voxol · · Score: 1

    'Post-its'?

    My Dad writes them on the monitor itself, or infact anywhere in reach. The computer room is decorated by thousands of passwords written in strange locations on the walls of the room.

    One example is a list of a hundred-or-so seemingly random letters, which are in fact the passwords to Lemmings on the Amiga version.

  90. my personal favorite... by GoNINzo · · Score: 3
    One of my favorite password stories is my recent subscription to @Home from AT&T. I called to complain about my cable modem dying (I apparently was querying the DHCP server every second, for an hour or to every week. Stupid crontab...). I am used to 'security questions' like 'can you verify your address' and things like that. but after the usual, the conversation went like this:

    The Guy: 'What is your @home password?
    Me: 'excuse me?
    TG: 'Oh, we have to make sure it's you.
    Me: 'But I havn't set a password.
    TG: 'Yes, you have.
    Me: 'Um, I don't remember TELLING anyone my password.
    TG: 'Oh wait, you do have the default. Do you want to set a password?
    Me: 'What?!
    TG: 'You tell me the password, i'll put it in for you.
    Me: 'I don't really feel comfortable with that.
    TG: 'Just give me any old password.
    Me: 'Okay. F. &. 9..
    TG: No, do you have a regular word you could use?
    Me: What, like 'bob'?
    TG: Okay i've set it to 'bob', how can I help you?

    I was about ready to kill him at that point. Slight alterations in the passwords, but that's pretty much how it went. I was not happy.

    --
    Gonzo Granzeau

    --
    Gonzo Granzeau
    "Nothing the god of biomechanics wouldn't let you into heaven for.." -Roy Batty
    1. Re:my personal favorite... by CBravo · · Score: 1

      It's alice, right? Tell me it is alice.

      --
      nosig today
    2. Re:my personal favorite... by staplin · · Score: 1

      I had exactly the same experience with a Denver based ISP!

      First you feel silly spelling a cryptic password out for some clueless tech person over the phone, and then you find out you can't change it without calling them back and spelling out that one.

      This ISP just couldn't figure out why I didn't want them to know my password... They most likely had root access anyway, making knowing my password a moot point! And if this person on the phone didn't have root, I don't want them having my password either!

      It wouldn't bother me so much, if I could change it the first time I logged in, but having no secure way to change it really bothered me.

  91. Random passwords by deacent · · Score: 1

    One of my more clever friends who was a skilled pianist used to pick a bar from a familiar piece of music for his passwords. I remember one time he needed to give his password to a trusted friend and he really couldn't remember it. All he knew was the manner in which his fingers moved over the keyboard.

    -Jennifer

  92. Re:Foreign Language Passwords by Mike+Van+Pelt · · Score: 2

    Ha. When I was sysadmining, I added Hindi, Mandarin, and Cantonese dictionaries to my regular Crack run. I caught quite a few.

  93. Re:My /. password is... by cornjones · · Score: 1

    ok, but you forgot something, as I recall:

    Roland: 5
    Helmet: 5

    (slams up visor) 1 2 3 4 5!! that's the stupidest combination I have ever heard. it is the kind of thing an idiot would have on his luggage.

    (snip couple seconds/minutes)

    President Spaceball: What is the combination?
    Helmet: 12345
    PS: Amazing! that is the same combination I have on my luggage

    I know I missed some details but at least it is a bit closer to the original.

    ej

  94. Re:You mean... by generic-man · · Score: 1

    I'm afraid not. It's a bad idea to use dictionary words as passwords.

    --
    For more information, click here.
  95. In Washington by Marillion · · Score: 1

    I think I've figured it out! Welcome to Whitehouse.gov login: jennabush password: budlight Login accepted yada, yada ...

    --
    This is a boring sig
  96. Re:"swordfish,' for those who don't know.... by rufus+t+firefly · · Score: 1

    > ...comes from a marx brothers movie. it's the password to get into the speakeasy. how it became
    > a completely unrelated travolta title, I'll never know...

    I'll second that.

    Harpo, the silent Marx Brother, says "swordfish" by pulling out a large fish and inserting a sword into it.

    If only we could enter our passwords in a similar fashion...

    ---

    --
    "He may look like an idiot, and talk like an idiot, but don't let that fool you. He really is an idiot." - Duck Soup
  97. Link for "Swordfish" routine by rufus+t+firefly · · Score: 2
    And now, for a little bit of gratuitous link karma whoring, http://www.earthstation1.com/Horse_Feathers.html is a page with lots of clips from the Marx Brothers' "Horse Feathers", including the famous (or is that infamous?) swordfish joke.

    Too bad most people have never heard of the Marx Brothers, or at least they don't *think* that they have ever heard of them. (Think Bugs Bunny for a moment...)

    ---

    --
    "He may look like an idiot, and talk like an idiot, but don't let that fool you. He really is an idiot." - Duck Soup
  98. Re:Is there a category for... by CBravo · · Score: 1

    Essentually I think you are more right then you might realize. Think about it, security is a as good as the physical access level. When someone has physical access to your keyboard it can get bugged since your keyboard is a trusted machine (always take your keyboard with you!!!).

    --
    nosig today
  99. Re:Too many passwords? by gorilla · · Score: 3

    You can make the case mixing in the mnemonic device too. For example, if you were to think the Too Many was loud, it could be mshTMp2d.

  100. Yet Another Password Scheme... by slackergod · · Score: 1

    One scheme I heard of (I don't use it :) )
    is a semi-Cryptic mnemonic system:
    it's based off an old program called
    Alien Names, which would generate
    scifi-ish sounding names out of english letters.
    They were designed around english phonetics,
    so you could pronouce them, but they
    were still pretty much random line noise.

    Strangley enough, it works quite well...
    Though I only saw it used in one place,
    when I was setting up some free shell accounts
    someone gave my HS, their default password
    was 'qedovako', which I _still_ haven't forgotten.
    Yes, that's the password. If they haven't changed
    it by now, they deserve what they get.

    (why didn't _I_ change it?
    prohibited by School Officials. Gotta love'em.)

    anyways, just wanted to share that scheme.
    Me, I use a chant... say a word,
    and chant a series of numbers that fit the word's
    intonation. All I have to remember is the word,
    intersperse the numbers.

    -Slackergod

  101. Re:Password Methodology by Peter+H.S. · · Score: 2

    Here's what I use: [snip] ...3. Use a person's last name (like Rucker) and 4 digits (say 3120). In your DayTimer or PDA, record it as a name and phone (Bill Rucker 275-3120)...

    Hm. This method is quite common, but perhaps not so secure. Banks in my country have issued warnings about using this method for storing PIN codes for ATM cards, since "all" pickpockets seems to know this scheme, and therefore scans all dayplanners for "fishy" name and number entries. Apparantly quite a few bank accounts have been emptied this way.
    Another problem with this scheme is, that it is "easy" to verify what is real names and telephone numbers.

  102. Re:BOSCO by EnderWiggnz · · Score: 1
    how about
    ]305] ?

    its late in the day on a friday... give me a break

    --
    ... hi bingo ...
  103. Re:Back in high school... by HerrNewton · · Score: 1

    *cough* And then Robby banned you from the system. ;-) Hmmmm... I wonder how many of the passwords were "sendit2me", corresponding to the password used to get into the account registration system.

    ----

    --

    ----
    Am I the only one who thinks Microsoft is a misnomer? Perhaps Macrosoft would be a better fit?
  104. Sales Department by Talisman · · Score: 5

    "The Internet domain name registry CentralNic who commissioned the study, claims that the most common type of password attack comes in the form of "social engineering", when a cracker poses as technical support, and contacts someone in a different department within a big corporation claiming that there is a network problem, and asks for the user's password."

    Brrrnnnggg!!!
    Brrrnnnggg!!!

    "Good morning and thank you for calling the sales department at ACME Widget Corporation. My name is Janet. How can I help you today?"

    "Good morning, ma'am. This is the tech support department. We're currently installing quizzards for the loopstep stabilizers on your PC and we need your password."

    "Oh, OK. My password is J-A-N-E-T."

    (tapping sounds)
    "Ummm... No, ma'am. That's your login name. We need your password. The thing that you type in after your login name."

    "You mean that box underneath my name?"

    "Yes, ma'am. The box that says "Password" next to it..."

    "Oh it's B-U-S-T-E-R. That's my puppy's name."

    (tapping sounds)
    "No ma'am, that isn't it either."

    "Yes it is. When the 'Password' box comes up I type that in or else I can't get my e-mail."

    "That's the password to your e-mail account, Janet. When you FIRST turn the computer on, a box comes up that has a text entry field... err... I mean a little white rectangular box that you can type in, underneath your login name. What do you type in that box?"

    "Nothing."

    (silence)

    "What do you mean 'nothing'?"

    "I kept forgetting my password so one of the boys from the IT department set it to Auto Save so I wouldn't have to type it in."

    (silence)

    "Janet, can you please transfer me to the accounting department?"

    "Don't you want to place an orde..."

    "SILENCE, DUNCE! TRANSFER ME NOW!!!"

    --

    "Study your math, kids. Key to the universe." -The Archangel Gabriel
    1. Re:Sales Department by Tackhead · · Score: 1
      > "Erols technical support, may I have your userid?"

      "clickity-click".

      All hail the BOFH!

    2. Re:Sales Department by vbrtrmn · · Score: 5

      I'll trump that one...

      I used to work for an ISP in Virginia, called Erols Internet.

      We had to answer the phone with:
      "Erols technical support, may I have your userid?"

      Half the People who called answered with:
      "Is that my password?"

      Soon after I started working there, I changed my username to IsThatMyPassword, basically as a geeky joke.

      It has been about 3 years since I quit, I called up support, because I didn't pay my bill.

      A nice man answered and asked me for my userid, and I said, "IsThatMyPassword".

      After I explained it to him, he laughed for a few minutes and said that I had been his best caller ever :)

      --
      microsoft, it's what's for dinner

      bq--3b7y4vyll6xi5x2rnrj7q.com

      --
      it's a sig, wtf?
    3. Re:Sales Department by sowalsky · · Score: 1

      Well, not as much as they used to. New phones in corporate environments display who the caller is, and have little arrows next to specific buttons if the call is from outside the office, transferred from a switchboard (or someone else), or direct from within the office. I work in the MIS department of a company and have never had such an issue arise. Now, the problem with the lack of documentation and the absence of a password on the Primary Domain Controller -- that annoys me.

    4. Re:Sales Department by Erasmus+Darwin · · Score: 2
      "Good morning, ma'am. This is the tech support department."

      Or even better: "Good morning, ma'am. We're taking a survey on what passwords people use. What's your password?"

    5. Re:Sales Department by underpaidISPtech · · Score: 1
      ROFL! Too true! (wipes tear from eye)

  105. Re:Is there a category for... by Calcbert · · Score: 1

    Where I work, I've seen it written directly ON the monitor.

  106. Re:You're insane by p3d0 · · Score: 1

    If someone finds the password to one of your root machines, then the rest are all toast.
    --

    --
    Patrick Doyle
    I mod down every jackass who puts his moderation policy in his sig. Oh, wait a sec....
  107. Re:Passwords are an unfortunate necessity... by Thalia · · Score: 2

    Biometrics is coming... and it's going to replace passwords. You can kiss your privacy goodby... but you will never be embarrassed by having a crappy password or even worse, forgetting your password.

    Thalia

  108. Does this count? by Monthenor · · Score: 3

    Back in high school, when SNES was big-time, my favorite password was "PotassiumIodide". See, Killer Instinct was one of my favorite games, and abbreviates to KI (all the chemists out there are shaking their heads at me)...
    ------------------------

    --
    Co-founder of GerbilMechs
    1. Re:Does this count? by friedo · · Score: 3
      Heheheh. When one of my grade school buddies would sneak one of his dad's Playboys into school, we'd ask him, "So where's the lead?"

      (Lead = Pb = Playboy)

    2. Re:Does this count? by andy@petdance.com · · Score: 2
      Heheheh. When one of my grade school buddies would sneak one of his dad's Playboys into school, we'd ask him, "So where's the lead?"

      (Lead = Pb = Playboy)

      For us, PB was peanut butter, and Penthouse was Preparation H.
      --

    3. Re:Does this count? by tomknight · · Score: 1

      And all your teachers were scared by the prevalence of piles among the students...

      --
      Oh arse
  109. More high school fun... by Monthenor · · Score: 5
    We got our computer lab's admin password the old-fashioned way: we watched over our teacher's shoulder. Turned out to be a "cryptic", so he didn't suspect anything for a looooong time. This was on a bunch of PowerPCs with Mac OS8, and normally the account menu in the menu bar would say "Student"...and if it said "Administrator" when he walked by, we were busted. The solution? With our newfound administrator access, we created an account called "Student " and gave it privileges :) He didn't catch on until after I graduated; he even tried changing passwords once, to another "cryptic", but by then we had keystroke-loggers and our own accounts...

    So many people neglect the meatspace security.
    ------------------------

    --
    Co-founder of GerbilMechs
    1. Re:More high school fun... by Tackhead · · Score: 3
      > We got our high-school computer labs admin password the old fashioned way too. By rifling through his desk. Sure enough, we found the words 'lunch' and 'dinner' written on the inside cover of one of the manuals for no apparent reason. Admin password? breakfast. From then on we played a lot of networked doom.

      Setting the Wayback machine for 15 years ago...

      We shoulder-surfed our teacher's r00t password. It didn't change for the next two years.

      We had access to 40 megabytes of space for our use (some legit projects, but mostly warez), of which we only used about 5-10, so nobody notice.

      On graduation day, we changed the "Mail Waiting" prompt to "Whale Mating", brought in portable tape players, each with an identical copy of a tape cued up to the same point, left the headphones hanging around our necks and volume cranked, and hit "Play" at a predetermined time according to the classroom clock.

      The classroom was then filled with the faint strains of "Batman", seemingly coming from every direction.

      Teach was confused for a minute about where the music was coming from, but then he put two and two together and started laughing harder than we were.

      Confused the hell out of the non-geek students, that's for sure.

    2. Re:More high school fun... by PurpleBob · · Score: 2
      In middle school, the Macs were all set up in such a way that all security would be disabled, so you could actually save stuff to the hard disk, if someone (presumably a teacher) hit F1.

      This was not too hard for students to catch on to.

      The next year, they had wizened up and set up their software differently. Now if you hit F1 you got a user/password prompt, and each teacher had a different password.

      Needless to say, all the teachers promptly forgot their passwords, and another method of getting out of "secure mode" was added to remedy this - hitting F6.
      --

      --
      Win dain a lotica, en vai tu ri silota
    3. Re:More high school fun... by brunes69 · · Score: 2

      Me and a friend of mine did the exact same thing at our university.

    4. Re:More high school fun... by Creepy · · Score: 1

      But macs are so easy to hack... for a long time I used the programmers key and 'es' to shut down Easy-something (Open? - the program the preceded Launcher, whose name I've forgotten). Later on in college I brought a jaz drive with a boot OS on it and rebooted the machines using Cont-Opt-Shift-Delete. I then systematically removed all the boot security on the Macs (Foolproof and sometimes the file replacer RevRDIST). College PCs were even easier when running Win 3.1 since they had DOS boot security, easily replacable from a clean version of DOS on a diskette. Win95 meant using a CD, diskette, and some generic CD drivers, but worked fine. Usually removing the security was trivial after getting open access. SGI was my UNIX of choice for a while due to ease of getting root, but I didn't have anywhere near as much luck on most flavors of UNIX (I discovered packet sniffers a few weeks before graduation, but really didn't do much hacking anymore).

    5. Re:More high school fun... by Creepy · · Score: 1

      Oops - I meant Command Option Shift Delete. Silly me - I was thinking how bad the PC I'm typing on needs a boot and got confused :)

    6. Re:More high school fun... by arunkv · · Score: 1
      Actually we did this with AIX as well. That was at a university about 6 years ago.

      Another "stupid password scheme" was also in place at the same univ. Every one was given accounts on all the common systems. Ofcourse some people, esp. faculty, never used all the machines - they had their own personal "workstations". The initial password for all the accounts - the user IDs themselves! Unlimited privileged accounts. Those were the days when everybody used or rather "abused" the .rhosts file and an account one system meant an almost unlimited set of accounts on other machines including at other universities where the profs. collaborated.

      The profs and admins never got of a whiff of ituntil one day one of the profs actually tried to access one of his dormant accounts. And guess what! He found a good old undergraduate programming class assignment complete with those beautiful program headers every programmer is taught to include in code - including Author! Took a whole semester for the uproar to die down and for me to get out of that mess. I was the big idiot who spread the good cheer about the open accounts.

    7. Re:More high school fun... by jayhawk88 · · Score: 1

      The year I was a senior in high school, my school got a "network" up and running, which was basically a file server with a few wired computers in select classrooms around the building. Some IBM system, don't remember exactly what.

      Anyway, the login to get on the system was an ASCII generated screen. So one day when left to our own devices in class, we whipped up a BASIC (yes, BASIC!) program to reproduce the login screen, and in theory capture someone's (read, our teachers) admin username and password. We had it set to simply redraw the screen when you hit enter to login, which made it look much like there was just a login problem of some kind.

      It worked great too, right up to the time when our teacher would always reboot the computer to try and fix the "login problem". See, none of us were smart enough (or motivated enough) back then to figure out how to write BASIC variables to a permanent file. It's just as well I guess: who knows what trouble we would have gotten into with unfettered access to the power of the grades database and the typing tutor program.

    8. Re:More high school fun... by commodoresloat · · Score: 1

      This doesn't prove macs are easier than anything else to hack. If the attacker has physical access to a machine, it is not secure. Period. If you can attach a drive and reboot with your own software, does it really matter whether the OS is Windows, unix, or MacOS?

    9. Re:More high school fun... by guinsu · · Score: 4

      I think everyone in a hs pascal class wrote the fake novell login screen.

    10. Re:More high school fun... by SurgieGuy · · Score: 1

      We had something similar called Fortress, just go into Word and you can open explorer or just about anything else you did. Also they didn't bother setting up any good security on it so we could read/write anywhere as well. About 2 weeks later we found out how to bypass it with a simple win95 cd, and many wasted class hours playing games ensued.

    11. Re:More high school fun... by moksliukas · · Score: 1
      When I was at school, we also used to have such tricks to find out passwords. It was amazingly low security: we managed to get ALL (that's right, ALL - ftp, web server access, administrator for the WinNT server, bios bootup passwords, you name it. We even had the passwords for the server that had our grades in, but we couldn't use it because it was in the teacher's room). The way we did it was to look at our admin typing his normal (not admin account) password (btw, it was as simple as "sony"). on his account there was a plain text file with the list of all passwords. It was even named something like passwords.txt.

      Of couse he probably kept all the passwords there because they were cryptic and difficult to remember. That's why he chose to remembe only one password from his own account. Of course, I informed him about our "discovery" and he has changed his account password, but i remember that some of the passwords we discovered that day were valid even after a year has passed. Obviously noone bothered to change them.

      This shows some points such as:

      • there are too many passwords to remember and the more difficult they are, the lesser they are secure as people will choose other options as sticking post-it notes or having password lists in a simple text file.
      • there are a lot of admins (especially at schools, etc), that are still not aware of the possibility that someone might get the passwords. (sort of a "god, we are an elementary school, so who's going to hack us?" attitude)

        ------------- My doctor says that I have a malformed public-duty gland and a natural deficiency in moral fibre and that I am therefore excused form saving universes

    12. Re:More high school fun... by BillX · · Score: 2
      Heh...at my high school (ah, the memories) they used Win95 machines with some kind of security app to keep people from doing much of anything (right-clicking the desktop, etc...stupid stuff.) I don't remember the name of it, but it's the one that gives you a password prompt if you shift-click the start button. Trouble was, MS Word's (and most other programs) Open/Save dialogues would let you go anywhere in the filesystem, including the networked drives(!) which had a directory for every user, including students, teachers, etc. Suffice it to say that they were not passworded, and every dir was read/write for every other user. The ol' schoolyard bully's jaw dropped when I asked him about his English report on the relative merits of different brands of garbage bags, as did those of a couple teachers when I pointed out ambiguities in their upcoming quizzes. Needless to say, their network came under new management shortly...

      --

      --
      Caveat Emptor is not a business model.
  110. Re:Cryptic == bad by Steve+B · · Score: 2
    It's no good to have a cryptic password unless it makes some sort of sense to the user. If it's too complicated, the user has to write it down, thereby breaching security.

    There are mnemonic tricks to help (e.g. first letters of the words of an easily-remembered phrase, perhaps with a few complications thrown in along the lines of "capitalize the letter if the word is a noun; take the number of letters in the word if the word is a verb"). For instance, "Not all the water in the rough rude sea can wash the balm off from an anointed king" keyes the reasonably cryptic "natWitrrS34tBofaaK" -- which can be keyed in at close to normal typing speed with a bit of practice.
    /.

    --
    /. If the government wants us to respect the law, it should set a better example.
  111. Re:Oops... by EasyTarget · · Score: 2

    Everybody just needs to email their slashdot username/password to me

    Sure! Just put your email, unfudged, in a reply to this and I'm sure lots of people will be emailing you real soon, with emails that will 'CHANGE YOUR LIFE BY MAKING $MILLIONS WHILE SVCRATCHING YOUR ARSE'.


    EZ

    --
    "Oops, I always forget the purpose of competition is to divide people into winners and losers." - Hobbes
  112. multi-lingual speakers are extra cryptic! by haledon · · Score: 1
    I guess I fall into the cryptic area. I speak an old language, with less than 3M speakers world wide, and less than 10,000 speakers in countries with latin-based alphabet/character sets.

    I specifically choose old, archaic, non-signifigant words in my native language, that are very hard to pronounce. (My language is tone-based.)

    I then mix in alphabetic and numeric characters, along with non-alphanumeric characters, and mix the case-- but I use a pattern.

    The advantage is this: I'll never forget the word, becuase it's a word from my language.. I can easily speak the word out loud, and becaue my language is tone-based, no one will ever crack it, and despite the mixture of all the characters and cases, because there is a pattern, I won't forget the password.

    For example, let's say that I was using the word "carpet" (but in my language, obviously)....

    but the time I was done with it, the pass word would look something like:

    _C7arpE7t_

    see the pattern?

    pretty nifty, eh?

    --
    i want to live life, not just go through the motions
  113. You're kidding, right? by tosderg · · Score: 1

    Wasting your time burning up cycles for some moronic activity?

    ????

    The difference between Joe User and yourself, or myself for that matter, is that we often use our computers for nothing other than the actual use of them. Tweaking our operating system, working on new programming projects, and just general geekotry.

    Joe User uses his machine as a tool. I really can't help but think that you're a troll (despite your current modded up status) if you're saying that we should just forget about Joe User and return computers back to the "One, True, and Rightful User, namely ME and those just like me". Sorry bub, ain't gonna happen.

    Your choice is either:

    A) Continue with the current password scheme and have Joe Users forever abuse it, for Joe User will never, as a whole body of Joe Users, learn better practice. Never ever.

    B) Think up a better scheme for Joe User to identify himself to his machine so that he can get his work done. Whether that be check up on medical records, enter standard secretarial work, or do research for a paper. You know, typical Joe User things for which the actual operation of the computer and its security paradigms should be invisible.

    1. Re:You're kidding, right? by tosderg · · Score: 1

      I think there's a big difference between someone selecting a common dictionary word or, worse, an easily identifiable word with associations to them (ie, a girlfriend's name) as a password for an account or system, and someone taking an active role to convince someone that it is in their best interests to use the priveledges related to that password for evil intent.

      One is simply a case of asking more of Joe User than can be reasonably expected of him (maintain a database of GOOD passwords, often changed, in his head), the other is a case of someone manipulating Joe User's lack of common sense for their own benefit.

      Though choosing a bad password COULD be indicative of a lack of common sense, it isn't always. In fact, it isn't usually. Choosing a bad password is the majority of the time a case of Joe User simply selecting something he will be able to easily remember, not taking into account the fact that if it pops to his mind as second nature, it will probably be able to be discovered without TOO much prying by an outside source.

      Make sense what I'm saying?

      There's a technological cure for one (not depending on one's mnemonic abilities for authentication), there is no technological cure for the other (a user abusing the priveledges the password gives him).

      Not the same issue.

    2. Re:You're kidding, right? by crucini · · Score: 2

      OK, so you invent the luser-proof authentication scheme. Implant a crypto chip in Joe's belly and have it talk to the keyboard. Hooray! Nobody can social-engineer Joe's password, because he doesn't know it. But someone will email him an executable and tell him to run it. Or phone him and SE him into using his privs to do something he shouldn't. You are only shifting the impact of cluelessness around, not reducing it.

    3. Re:You're kidding, right? by jgerman · · Score: 2
      Luckily, I don't have to care about Joe User's needs anymore than Joe User has to care about being responsible. I'm not saying that there is one true user, all I'm saying is that when people are willing to take responsibility for their actions they shouldn't participate in that activity. And when they get burned, it's too bad for them.

      On a tangent, I find it amazing how again and again opinions that differ from the norm are marked as flamebait.

      --
      I'm the big fish in the big pond bitch.
  114. Passwords are an unfortunate necessity... by tosderg · · Score: 4

    if you ask me.

    It's amazing to me that people in such an intellectually demanding field as programming computers have for YEARS relied upon what could possibly be the most inefficient form of personal security available: a secret word. I mean really.

    Complaints aside of "stupid users!" and "idiots deserved to have their account cracked with a foolish password like that!", what do you expect? It's the same thing as the whole "Well duh, to use Linux well you need to LEARN it, it's not my fault if you're too STUPID to learn something NEW!" argument; it just doesn't hold water when applied to the general populace.

    You or I may be capable of mastering every arcane command our operating system affords us, memorizing every minor inconsistancy between BSD flavor or Linux distribution, programming in fixes when we need them, etc, but JOE USER NEVER, EVER WILL. It's the same with passwords. You or I may realize the importance of a unique alpha-numeric password for each of our important sites, and have a nice table of "xreF249sfj2r43's" and "248sT358ugtds's" memorized in our head, but JOE USER NEVER EVER WILL.

    So when confronted with that box that says "Choose a password, and CHOOSE ONE YOU WILL REMEMBER, PASSWORD RETRIEVAL IS VERY DIFFICULT, please enter in your password hint in case you forget it", Joe User is not only inclined, but DIRECTED to select an easily-rememberable password.

    Someone please tell me how the fsck you have a "hint" to remind you the password you selected is "24885sfjsfsjf82's"?

    So Joe User sees that box, thinks "oh cool" and types in for the hint "Mom's maiden name" and his password ends up being "johnson", and that's that. It works for him, he remembers it, and even if he does forget it, it's right there for him to retrieve via his hint. Joe User doesn't realize that someone with half a brain will probably guess his mother's maiden name as his password within the first ten attempts to break into his account/machine/whatever.

    Also notice Microsoft and countless third parties developing programs to auto-remember and auto-insert passwords on sites you've visited before. One wonders why they don't just tie access to a unique browser hash if it's going to be that straightforward.

    An example of the type of thing I'm referring to: One time I had a few friends over spending the night with me, and when we got up the next morning we all had logged onto our messengers of choice to talk to friends and see what the plans were for that day. One friend had logged off of his AOL IM account to go to the bathroom (for he knew that if he left it up, we all would've lunged at his machine to enter the standard requisite "Sup, slut?" messages to his girlfriend and mother and etc etc ;), well, just to be a nuisance I told another friend of mine to try a password to see if we could log in when he was away.

    To my astonishment, it worked. My FIRST GUESS. It just goes to show that most "regular people" pick a password that is so easily rememberable (a word? is now.) by them and so related to who they are that those who know them well can probably pick it out just as easily. Another one of my friend's passwords, discovered via the same method, is simply his girlfriend's name with an "i" replaced with a "1".

    (btw, the password for the aformentioned friend was "bigblack", he'd been a fan of that character on the Howard Stern show)

    So please, someone more intelligent than I, come along and invent a better personal identification system that doesn't rely on the good practices or intelligence of the end user.

    -Chris

    1. Re:Passwords are an unfortunate necessity... by jgerman · · Score: 1

      I'm tired of pandering to Joe User. If he can't pick a decent password and remember it, he's doing nothing but wasting my time burning up cycles for some moronic activity or another.

      --
      I'm the big fish in the big pond bitch.
  115. Re:You're insane by Simon+Brooke · · Score: 2
    I'm really getting fed up with the need to memorize giant lists of passwords, pins, etc.

    If you have giant lists of different passwords, you're insane. I have (at any one time, changed regularly) just three:

    1. Root password on machines I'm responsible for
    2. Personal password on machines I trust implicitly, where that password never passes over the network in unencrypted form
    3. Personal password for machines (like slashdot) where the password will pass over the network in unencrypted form, and/or where I don't trust the conpetence of the admins
    --
    I'm old enough to remember when discussions on Slashdot were well informed.
  116. Re:Systematic is the only way! by Simon+Brooke · · Score: 2
    So a dictionary attack will destroy every password you've ever used. Nice.

    Sure. There are something over 2,000 natural languages, with an average of 250,000 words in each. That's 5*10^8, which will take you a while. And, although the method I gave is analogous to my method, this attack still won't get you any of my passwords.

    --
    I'm old enough to remember when discussions on Slashdot were well informed.
  117. Systematic is the only way! by Simon+Brooke · · Score: 4
    In fifteen years you will be 30. And you will remember the day when you had forgotten a password for the first time.

    Amen to that. I remember a time when I was phoned up by a former employer nine months after I had left their employ, what the root password for a particular machine was (because the person I had handed over to had also left and was unreachable).

    You need a systematic way of generating passwords, where the key knowledge is the system, not the individual password. Then, if you forget a past password, you can work progressively back through the system until you recover it.

    As an example, you might choose a particular book, ideally in a foreign language, and use the longest word in the fifth line of each successive right hand page as successive passwords (that isn't my system, but it's analogous to my system). If you forget your current password, just look in the book. If you forget an earlier password, work progressively backwards though the book.

    You can, if you want, substitute some letters with some numbers in a systematic fashion known to yourself, but IMHO that trick is now so well known as to add little extra value. I know some good geeks who always systematically replace all vowels with numbers... so if you were trying to crack their passwords, you would do the same.

    And yes, I was able to tell my former employer their password, there and then on the phone, although I had changed all my passwords several times since then. Systems are good provided only you know the logic of the system.

    --
    I'm old enough to remember when discussions on Slashdot were well informed.
    1. Re:Systematic is the only way! by loraksus · · Score: 2
      damn... got to write that one down... just have a lot of books I guess... I suppose "western" books only (not asian, russian, etc..)

      The slashdot 2 minute between postings limit:
      Pissing off coffee drinking /.'ers since Spring 2001.

      --
      1q2w3e4r5t6y7u8i9o0pqawsedrftgthyjukilo;p'azsxdcfv gbhnjmk,l.;/
    2. Re:Systematic is the only way! by swillden · · Score: 2

      There are something over 2,000 natural languages, with an average of 250,000 words in each. That's 5*10^8, which will take you a while.

      I think you're overestimating the difficulty here. 5*10^8 is a little less than 2^29, and a 29-bit keyspace should be considered ludicrously weak. Running an MD5 hash on every one of 5*10^8 entries and comparing against a shadow file will take less than 2 minutes on a fast PC.

      And that doesn't even consider the fact that your estimates of the number of words in the world is very optimistic. Most of the world's languages aren't written, and the majority are only known to a very tiny handful of people. Chances are very, very high, that you use books out of one of a dozen or so languages.

      And, although the method I gave is analogous to my method, this attack still won't get you any of my passwords

      Again, be careful. Small, systematic variations on dictionary words don't increase the required level of effort very much. You're basically betting that the attacker isn't inventive enough to come up with the set of alterations that you make. If he has a room full of PCs, he can test variations just as fast as he can think them up. And you're almost certainly sunk if the attacker ever manages to see one of your passwords in cleartext (not hard, if he cares).

      It's unlikely that any dictionary-based password generation system can achieve password spaces that reach even the size of 2^40.

      OTOH, if you're like most people, the really important thing is that you don't need secure passwords, because no one cares enough to mount the kind of attack I'm talking about. In that case, your system's main purpose is ease of use, not security.

      --
      Note to ACs: I usually delete AC replies without reading them. If you want to talk to me, log in.
    3. Re:Systematic is the only way! by swillden · · Score: 3

      As an example, you might choose a particular book, ideally in a foreign language, and use the longest word...

      So a dictionary attack will destroy every password you've ever used. Nice.

      Systems are a very good way to generate and manage passwords and passphrases but they must generate good passwords.

      Here's another system, one that generates great passwords on demand but requires that you carry a piece of paper with you:

      Create a 6x6 grid full of random letters. Pick 8-10 letters at random from the grid, and then memorize the pattern of your selections. It takes a little effort to memorize the pattern, but not as much as you might think.

      Then, you can create new random grids as often as you like, giving you all the high-quality passwords you need without requiring you to memorize them. Of course, if you lose or forget your current grid you're sunk, but it's even fairly safe to keep lots of copies of grids lying around, as long as you use a large enough grid and a long enough password. Even if someone got hold of your grid, brute forcing a 6x6 grid with a 10-character password means testing 9x10^14 passwords; the same effort as brute-forcing a nearly 50-bit key. Feasible but expensive to attack. For really strong security, use a 10x10 grid and a 12-character password. This gives an attacker an 80-bit work factor, which is probably infeasible even to government agencies.

      For the truly paranoid, this method also offers a way of permanently destroying a password. If a judge were to threaten you with contempt if you refused to divulge your password, you could simply explain your system and that you had destroyed that grid (non-toxic ink on rice paper would be an obvious way...).

      --
      Note to ACs: I usually delete AC replies without reading them. If you want to talk to me, log in.
  118. Office Workers? by QuantumG · · Score: 2

    pfft. Here's a tip, no-one is guessing passwords on your Microsoft domain server, except maybe the guys who are always standing in the kitchen drinking coffee and giggling. Back when I used to see a lot of passwords I noted two types. Dictionary words with numbers or punctuation replacing vowels and totally random passwords of the cryptic variety. Of the later, almost all of them rhymed. Ie, the 4th letter would rhyme with the 8th letter or the 3rd with the 6th. I believe these types of passwords are attacked by Crack quite effectively.

    --
    How we know is more important than what we know.
  119. Other password insanity. by QuantumG · · Score: 2

    Are you the type who refused to ever say a password out loud, or even subvocalise it? Remember the BBS days when everyone was warned "Never use the same password for two BBSes cause the Sysop can read your password and log into other BBSes as you"? Remember Remote Access was the first BBS to implement hashed passwords (actually they were CRCed which is easier to crack) and every Sysop added an extra question to the registration procedure to make people enter their password again which would be stored in a file as plaintext?

    --
    How we know is more important than what we know.
  120. Re:A few years ago... by QuantumG · · Score: 2

    Of course, anyone who has 'swordfish' as their password deserves to have their account cracked.

    Head cracked more like it.

    --
    How we know is more important than what we know.
  121. Re:Random is the only way! by wurp · · Score: 1
    Uh, and this is insightful? What are the moderators smoking today, I want some!

    Bobby Martin aka Wurp
    Cosm Development Team

  122. Re:Too many passwords? by raynet · · Score: 1

    Sure you can write uour passwords without any errors, just practive it a bit. It's easy.. And it also looks cool when you have a 35 chars longs password and you log in with it :) and this message is really written blindfolfed :P

    --
    - Raynet --> .
  123. Re:Random is the only way! by glitch! · · Score: 1

    Uh, and this is insightful?

    Not especially so. I just figured someone might like a tip on how to produce a password that is actually random.

    As I mentioned in a different reply, the truly random passwords have patterns that can actually
    make them easier to remember than something you make up that seems random.

    --
    A dingo ate my sig...
  124. Random is the only way! by glitch! · · Score: 5

    For all my passwords (and I have a lot of them), the only acceptable way is to pick them randomly.
    And I don't mean pseudo-random, like a computer generated password, or "sounds random", from just
    making up letters and digits out of my head.

    I have a cup full of small squares, each one with a letter or digit on them. Pull one out, put it
    back in, shake, and repeat 7 or 8 times.

    --
    A dingo ate my sig...
    1. Re:Random is the only way! by precize · · Score: 1

      Or, you could figure out a pretty easy password, memorize the keystrokes, then shift the pattern to another location (changing case, of course).

      For example, "password" becomes "0qWw294E"

    2. Re:Random is the only way! by precize · · Score: 1

      I hate to break this to you, but probably neither of the people who use the Dvorak layout will see this tip. As for the rest of us, we don't know the Dvorak layout, or we'd be using it...sorry.

      (Joking)

    3. Re:Random is the only way! by Che+Guevarra · · Score: 5



      I have a cup full of small squares, each one with a letter or digit on them. Pull one out, put it back in, shake, and repeat 7 or 8 times.

      I have a bottle full of small pills, each one with a small letter on it. When ever I get that obsessive-compulsive I pull one out, swallow, and repeat 7 or 8 times.

    4. Re:Random is the only way! by skarab13 · · Score: 1

      Phooey!

      I decided to get a geiger counter (Aware RM-60) and a small piece of relatively radioactive uranium. I threw together a little app that runs through letters of mixed case, numbers, and other assorted characters and stops when the meter hits a certain reading.

      Every few days, I used to generate a good 12 character password using this method, but lately I've been getting these headaches ...

    5. Re:Random is the only way! by timmyd · · Score: 1

      mcookie | mkpasswd -s

    6. Re:Random is the only way! by tandr · · Score: 1

      ... and usualy choose the wrong one ?

    7. Re:Random is the only way! by Sven+Tuerpe · · Score: 2
      For all my passwords (and I have a lot of them), the only acceptable way is to pick them randomly.

      In fifteen years you will be 30. And you will remember the day when you had forgotten a password for the first time.

      --
      http://erichsieht.wordpress.com/category/english/
    8. Re:Random is the only way! by deathscythe257 · · Score: 1

      In the end, a random or cryptic password could be just as easy to crack as BritNeYSpEARsFan if you think about it...

      I mean, if they are trying to break into someone's computer who is a B.S. fan, what's the point?

    9. Re:Random is the only way! by elinde · · Score: 1

      Sven! You're my new hero! Sometimes I feel like the only geek on the Net over drinking age.

      --
      "I love deadlines. I love the whooshing noise they make as they go by." -Douglas Adams
    10. Re:Random is the only way! by RetsamYthgimla · · Score: 1

      Yep, getting rid of all those 1-5 character passwords really saved you some time. And getting rid of anything in the dictionary I bet saved you a bunch too.

      Let's see, 62 letters and numbers (case sensitive), let's call it 2**6. Assuming 8 or 9 digits, that's 2**54 + 2**48. 2**44 more than covers the 2**42 7-character passwords, 2**36 6-char passwords, etc., and all the "word-like" passwords. So congratulations, you've eliminated about 0.1% of your searchspace by using the hints that were given. Yep, "that information was very helpful". Have fun going through a 2**54 keyspace.

  125. Swordfish? by Milican · · Score: 1

    Whats the swordfish password all about? From the movie? Or is there more history?

    JOhn

    1. Re:Swordfish? by Moses+Lawn · · Score: 1
      It's from the Marx Brothers movie "Horsefeathers", the one where Groucho winds up as the dean of some jerkwater college. The bit comes from a scene where the boys are trying to get into a speakeasy, whose password is "swordfish". You know the deal - knock on the door, the bouncer opens a slot, you say "Joe sent me" and he says "What's the password?"

      As you can imagine, much hilarity ensues.

      --

      What if life is just a side effect of some other process and God has no idea we exist?

  126. my password by thomkt · · Score: 1

    My password is *******

    http://ars.userfriendly.org/cartoons/?id=1999081 4

  127. Other categories by Bilestoad · · Score: 3

    Are there also categories for systems administrators?

    Like...

    Life's Lance Corporal: Makes sure that nobody uses any software or operating system other than that used approved by the CTO. Zealously enforces the use of anti-virus software on every boot. In marketing, his tread is greeted with trembling... in engineering, with stifled laughter.

    Just a Sad Bastard: Has such a pathetic life that he needs to reaffirm his own cleverness by making lists categorizing those sheep-like lusers. Not quite competent, but it's too difficult to fire him because he won't tell anyone else the root passwords of the systems he controls.

    :-)

    Any more?

    1. Re:Other categories by wumingzi · · Score: 1

      Yes there are.

      Are there also categories for systems administrators?

      www.ugcs.caltech.edu/~werdna/sysadmins.html

      I like your names better, but the descriptions of sysadmins in the article above are precious.

    2. Re:Other categories by aidoneus · · Score: 1

      Yeah, there is already a fairly detailed guide, although I think it could use some revising. Know your sysadmin at the FSFs humor archive is what you're looking for. I just discovered it myself a few weeks ago while looking for some rather obscure bit of EMACs trivia (is there any other kind?).

      The link is http://www.fsf.org/fun/jokes/know.your.sysadmin.ht ml if slashdot garbles it.

  128. Re:Oops... by theonetruekeebler · · Score: 2
    PAM 0.72 will let you use asterisks but will ding you on all-asterisks if you're using pam_cracklib.so (too primitive).

    Some Unices have problems with certain characters, such as the octothorpe. You can put one in your passwd, but /bin/login uses a very primitive terminal profile under which # translates into a backspace, which means you can't enter the character at login time, effectively locking you out of the system. This problem exists in HP-UX at least as recently as 10.2.

    A good habit after resetting one's password is to telnet localhost and try it on for size. This has kept me from losing the root account at least once--on an HP-UX box where I'd tried to use a hashmark in the new pw.

    --

    --
    This is not my sandwich.
  129. Bruce Schneier.... by babbage · · Score: 2
    ...had an interesting observation about this in the May issue of Cryptogram.
    Passwords. You can't memorize good enough passwords any more, so don't bother. Create long random passwords, and write them down. Store them in your wallet, or in a program like Password Safe. Guard them as you would your cash. Don't let Web browsers store passwords for you. Don't transmit passwords (or PINs) in unencrypted e-mail and Web forms. Assume that all PINs can be easily broken, and plan accordingly.

    Keeping a strong enough password is an uphill battle that really can't be won, because the cracker's tools are going to keep getting better at a rate faster than users can be reasonably expected to remember them. Even your elite haxxor mixed case alpha / numeric / symbolic max length password can't stand up to the scrutiny if someone with the right tools wanted it badly enough.

    Your best bet is to make it reasonably obscure & just try to prevent the casual cracker from getting it. The casual cracker had meant someone enterprising enough to look for a post-it note, but with the tools getting better the barriers to entry are falling, to the point that you don't know that some little snotnosed 13 year old with a downloaded rootkit (or Back Orifice, or whatever) couldn't count as "casual" these days.

    "You can't win, but there are alternatives to fighting..."

  130. Which brings up a question... by Ungrounded+Lightning · · Score: 2

    the most common type of password attack comes in the form of "social engineering"

    *cough*

    Like giving your password to someone doing a study on passwords?


    I figured someone would catch that. B-)

    Which brings up the question of how many "cryptics", confonted with such an obvious piece of social engineering as asking you to disclose your password for a survey, would lie, masquerading as one of the other categories.

    It's just like someone asking for information about whether you own a gun, what kind, where you keep it, etc. in a situation where the person giving the answer can be identified. Even if you are otherwise scrupulously honest, the canonical thing to do is to lie. No one else has a right to that information, revealing it reduces your security, anyone asking is suspect, and refusing to answer leaks part of the information you want hidden (because people who DON'T own one generally won't refuse).

    Pollsters asking how you voted/will vote is a similar situation. B-)

    --
    Bantam Dominique roosters crow a four-note song. Once you've heard it as "Happy BIRTHday" you can't NOT hear it that way
  131. My Password by vbrtrmn · · Score: 1

    I don't know about you, but I always use secretpassword. Nobody would guess that, right?

    --
    microsoft, it's what's for dinner

    bq--3b7y4vyll6xi5x2rnrj7q.com

    --
    it's a sig, wtf?
  132. Re:Stop demanding "strong" passwords by mrBoB · · Score: 1

    Strong passwords like all other secure-business practice, if for no other reason, provide a legal basis to fire someone. If an employee writes down their password, neglects to lock or logout of their workstation, or tells other folks their password(s), they are in violation of company policy and it possibly is putting the companies clients at risk. Every person who reads this site knows damned well that a lot of users don't give two shits about IT policy, at least until they lose their job because of it. If you as a user have a problem with strong-password policies, you need to find a job that doesn't tax your brain so much.

  133. Re:problem by ostiguy · · Score: 2

    Also, if accounts get hacked, and your biometric becomes known, do you have have a new thumb grafted on to get a new password?

    ostiguy

  134. Times change, people never do.. by ucblockhead · · Score: 2

    In my high school computer class, we all wrote fake TRS-80 command prompts.

    --
    The cake is a pie
  135. Password Methodology by AppyPappy · · Score: 2

    Here's what I use: 1. Use obscure brand names like Caldera. They don't appear on the naughty lists. Then add your area code. 2. Write them down in a DayTimer or the like but don't write down the login id. This only works if you can remember the login id. 3. Use a person's last name (like Rucker) and 4 digits (say 3120). In your DayTimer or PDA, record it as a name and phone (Bill Rucker 275-3120). The older you get, the worse it gets.

    --

    If you aren't part of the solution, there is good money to be made prolonging the problem

    1. Re:Password Methodology by Spire · · Score: 1

      So use the last four digits of the actual phone number of an actual person listed in your PDA. Someone I know does that.
      --

      --
      begin 644 .sig22&%I;"P@9F5L;&]W(&=E96 LA`end
    2. Re:Password Methodology by ichimunki · · Score: 1

      I think I am into this steganographic approach to secure password storage in either hard form or on a Palm. I know it's security through obscurity, but it's a lot better than having a memo file with them all written in it-- those "private" records are certainly not private to even mid-level hackers.

      --
      I do not have a signature
  136. Re:Is there a category for... by The-Pheon · · Score: 5
    ...the idiots that write their passwords on post-its and stick them to the bottom of their keyboards?


    Bottom of their keyboards?


    My users stick them on their monitors!

  137. Re:Social Engineering at it's best? by dodobh · · Score: 2

    Hehe, You know the algorithm. The entire strength of my password lies in the private keys.
    good luck getting those, because I don't even remember them. Those goddamn uptimes.

    --
    I can throw myself at the ground, and miss.
  138. Re:My /. password is... by idistrust · · Score: 2
    What kind of idiot would... :-)

    Mike.

    --

    --Ask a silly person, get a silly answer.

  139. Another way of making cryptic passwords... by wumingzi · · Score: 2

    One trick I was taught many years ago is to (if you can) put your passwords in a language other than English. This not only makes the password cracking programs work harder, but it tends to confuse shoulder surfers as well.

    Thus, an example password I might use would be

    yUEh@lIAng

    (Mandarin speakers may notice the full moon in the middle of the password)

    Another trick which was used in a shop where we had to issue passwords to users (thus we had to make passwords the users could remember, not just the admins) was to use close-by keyboard patterns. An example might be frdU*8 .

  140. Re:Cryptic by pubudu · · Score: 1
    Yeah, God forbid if someone broke into my slashdot account and posted a message as me. I use easy to guess passwords intentionally. This way, if I ever post something I regret, I can just say my password was stolen.

    This opens up a whole new realm of moderation. In addition to Troll, Redundant, Flamebait, etc., we could have a 'Hacked' option for those comments which we feel should have been posted by an Anonymous Coward, but have somehow been ascribed to a real account. (and just for the mod-down ...) You know, for those posts coming from that Jon Katz fellow? (God, what was his password? /.4ever?)

    --
    ~~~~~~

    under-paid karma whore

  141. Effect on basic etiquette by pubudu · · Score: 4
    The most annoying thing about most people's casualness with passwords is that they not only do not know even the most basic rules of etiquette, but they actually get offended when you try to enforce them. When I'm at a friend's computer and I need him to type in his password, I get up and move away. When someone is at an ATM in front of me, I stand back and stare at the wall.

    But when I ask people to back off when entering my password/PIN, they stare at me as if I'm a madman! Then they grumble something about 'paranoia' as they finally back away.

    It would appear that their own lax security affects how they think everyone else should act. I don't much mind their own obliviousness, which is what this article is about, so much as the creation of social norms around it.

    --
    ~~~~~~

    under-paid karma whore

  142. Re:Too many passwords? by binner · · Score: 1

    I encourage song lyrics...think of a favourite song, take memorable phrase, first letter of each word in phrase. This gives you the basics, then make one or two letters upper-case, add at least one number, and one punctuation, and presto!...half-decent password. Most people I've suggested this to are willing to do it, because it's still easy to remember, but more secure at the same time.

    -Ben

    --
    Say what you mean, mean what you say! But please know what #$@% you are talking about!
  143. Re:My /. password is... by DoomHaven · · Score: 1

    LOL! That made my day!

    --
    "Don't mind me cutting myself on Occam's Razor"
  144. I've done this before... by jason_z28 · · Score: 2

    On my network. I found it quite humorous that one of the heads of the companies password was "womanizer". For you network admins on NT networks, all you've got to do is use the handy dandy L0phtcrack and dump them from you PDC. I guess NT is good for something(password auditing surveys)
    Jason

    1. Re:I've done this before... by harborpirate · · Score: 1

      Back when I was working in the IT deparment at Montana State, we ran this crack to audit our passwords overnight..

      As I remember, it cracked 50% of the passwords in less than 4 hours. Names and dictionary words comprised a very large percentage of passwords. A mass mail was sent out to scold everyone for having such easy passwords. Of course, anyone who has ever been in IT knows that scolding doesn't work. We ran it a month later with similar results. I guess once an easy password, always an easy password. The psychology of trying to descibe oneself with a password goes a long way to explaining that, I think. Still, why not add a number to your word, like the year of your birth? Instant (semi)cryptic password...

      Luckily, none of the admin passwords were cracked by it. Cryptics all, I suppose.

      - harborpirate -

      --
      // harborpirate
      // Slashbots off the starboard bow!
  145. Re:what about dates? by jhoffoss · · Score: 1
    For work I use the three-letter abreviation for a month and the four number year, both offset by a certain number of months/years with mixed caps and the pass is changed monthly so it's relatively decent, I think.

    An example for June of 2001 being "aPr19(9" or apr1999 with the caps, the scheme being two months and two years ago. (Obviously not the one I use...) I've also split the month abreviation before, something like "jU19%7Ly" would be july 1957, for another example.
    ---

    --
    Linux: The world's best text-adventure game.
  146. Re:A few years ago... by mbauser2 · · Score: 1

    Two "stupid password system" stories: one work, one school

    The work story:

    I used to work for a retail company where who used the same root password for the POS (cash register) LAN in every store. Not only was it easy to dictionary-attack (a single five letter word), they published it in the employee newsletter whenever Daylight Savings Time switched, so employees in the store could reset the system clock.

    Keep in mind, each local network is storing 30 days worth of sales receipts, including customer's names, credit card numbers, and expiration dates. An employee with the password could have dumped the whole mess to a floppy. Fortunately for that company, most retail employees aren't that clever.

    (The primary terminal on each LAN had a password-protected "manager menu" that was used for payroll and staffing functions. With those, you could add or subtract hours on people's timecards, give individual passwords to employees, or even delete other employee's payroll records. Every manager in the company was assigned the same password, and there was no userid.)

    The college story:

    My alma mater didn't use individual userids for most "paperwork" accounts, like the system the registration department used to adjust student's schedules, or the one librarians used to look up people's library fines. The department userids for those accounts were all exactly three letters long (and based on the department name, like REG), and the passwords were all exactly four letters long (usually English words like "book").

    All of these systems were available by dial-up. As you can imagine, the students who figured this system out had a much easier life than the rest of us, because they always got the classes they wanted, and they never had overdue library books.

    --
    Proud to be / Smiley-free / Since Nineteen / Ninety-Three
  147. "swordfish,' for those who don't know.... by AugstWest · · Score: 5

    ...comes from a marx brothers movie. it's the password to get into the speakeasy. how it became a completely unrelated travolta title, I'll never know...

    1. Re:"swordfish,' for those who don't know.... by Madthio · · Score: 1

      The one place swordfish did *not* come from is the lighthouse keeper in Return to Zork, he tried it last week, but it didn't work . . . so he knows it's not that . . .

      Sorry, couldn't resist.

    2. Re:"swordfish,' for those who don't know.... by ebbomega · · Score: 1

      It became a Travolta movie based on a blatant Marx Brothers reference. I figured that out whilst wandering around our local McMall and saw a poster that said "Password: Swordfish" for the movie, suddenly I realized... "Hey! That's a Horsefeathers reference." I love being a geek.

      --
      Karma: Non-Heinous
  148. Re:Too many passwords? by Zach · · Score: 1

    Nah, nah. I never liked my computer teacher in school, so I made my password: mrdinnagefeastsdailyondonutsandrockseverynight.

    Rather difficult, I believe.

  149. You're insane by MemeRot · · Score: 2

    Every 90 days? ALL your passwords?

    If I was to try this, it would eat up a good day of work.

    "Then I just have to remember one scheme and a bunch of key phrases for all of them"
    Yeah - those key phrases? That's what us normal people use AS passwords.
    As much as I hate the idea of biometrics, I'm really getting fed up with the need to memorize giant lists of passwords, pins, etc. just to identify that I am in fact me. Nothing is more random or harder to produce than your thumb print or iris pattern - perfect, non-stealable, unique identifiers.

  150. Re:Is there a category for... by Eil · · Score: 1


    This is similar to what happens where I work...

    1) Each password must have at least four letters, two numbers and one symbol, or else the system will not accept it as a valid password. Err, maybe I'm not so good on statistics, but doesn't enforcing a policy like this actually make it easier for password scanners?

    2) You must change your password every 90 days. That wouldn't be so bad, if not for the fact that:

    3) Every time you attempt to change your password, it is checked against a list of your previous passwords. To make sure, of course, that you actually are following the 90-day rule. Mind you that this is on a 100% Windows network, so the relative chance of security intrusions is high enough without storing all current and previous passwords in a database somewhere.

    To put it simply: boneheads. Absolute boneheads. As if security weren't awful, the network is usually down anywhere from one to four hours every day, causing a work stoppage for most of us. It might as well be admined by monkeys.

  151. My password storage solution by Eil · · Score: 2


    Except that you have to get a PDA password app that sports decent encryption, or else all those passwords are backed up onto your desktop everytime you sync.

    I personally store my passwords on my TRGPro with a program called Cryptopad. It has an interface identical to MemoPad except that it uses blowfish encryption.

    And, to be on the even-safer side, I went ahead and bought a 32-MB CompactFlash card to back up the PDA so I never have to sync my data to a PC. If I want to add a program to my TRGpro, I simply employ that nifty $10 CompactFlash -> PCMCIA adapter. Long as the OS has PCMCIA support, it looks like a regular IDE drive! :)

    If I ever lost the TRGpro itself, well I guess I'd be up a creek. But then, I'd be much more saddened by the lost of my $350 geek toy than a couple dozen seldom-used passwords.

  152. Re:Is there a category for... by Eil · · Score: 2


    Hey thanks! I'd been looking for something like this that was "free." The closest I got was a (very nice) app called CyptoPad which is just like Palm's MemoPad except it's got really decent encryption.

  153. Do what Bruce Schneier says... by fawadhalim · · Score: 1

    in his book 'Secrets and Lies'. Use random password, write them down on a piece of paper, and keep it securely in your pocket.

    I kinda agree with him. For those who're saying 'what about people looking over your shoulder?', I think you'll automatically memorize the password after you've typed it 3-4 times.

  154. Re:The passward is electrifing by Moonshadow · · Score: 1

    It's not that hard at all.

    I use them all over. You just have to repeat them enough to remember them. I used to use my CueCat (Cracked, naturally) to scan barcodes on common desktop items for my passwords. Eventually, I gave up on that and moved to just typing in the numeric string. I have yet to forget one of the 7 passwords I use in this method.

  155. Re:Back in high school... by blogan · · Score: 1

    Actually, Robby didn't ban us for that. A few weeks later he said that the password file would be shadowed. So I waited a few weeks and then went to check the file to see if it was done yet before I changed my password and that's when I got banned. Then Robbie divorced Tommy's sister and then he just became a jerk from that point on.

  156. Back in high school... by blogan · · Score: 3

    Back in high school (6 years ago) we got the password file for a BBS we were on. Took a cracker program and gave it a list of common first names, sports teams, cheezy stuff (opensesame, secret), and all the previous with '1' appended (because you always here people say to put a number, so people think they're sneaky and put a 1 at the end. Never a 2 or 48). Doing that, I'd say we got about 60% of the passwords. Also, "catLight" was one of them because when you sign up, it said to use a combination of words, such as catLight.

    1. Re:Back in high school... by Telek · · Score: 1

      I remember the same. I hacked into our central board office's novell network, grabbed the bindery, and obtained about 380 of 520 logins with a simple dictionary attack running on a 486 computer. Christ, I even had 3 sysadmin accounts (of 8) cracked. It was pretty pathetic. The guy who was in charge of the whole IT department (and hence a sysadmin) had a password of "greece". I phoned him up, got his voicemail, and said "Hey, I'm from XXX school and I think that we need to talk about the security of your computer system. By-the-way, I hear that Greece is lovely this time of year". I got a phone call back REALLY QUICKLY. ;)

      --

      If God gave us curiosity
  157. The Dogwalker by Noer · · Score: 2

    The comment about "So many people tend to subconsciously believe that their password has to sum up the very essence of their being in one word," reminds me of the Orson Scott Card short story, The Dogwalker. Basically, a password thief discovers by psychoanalysis of sorts what a password is... it is basically derived from someone's personality.

    Kind of interesting, I think. The story's at http://www.frescopictures.com/movies/dogwalker/sho rt-story.html if anyone's interested.

    --
    -- "Those who cast the votes decide nothing. Those who count the votes decide everything." -Joseph Stalin
  158. Best Funniest paswords by phunhippy · · Score: 2

    I've found that where i work the new important passwords everymonth is usally the hax0rized version of someone who quits, name. IE.. Colin would be (0|_||\|

    pissed the hell out of our NOC when they gotta remember that crazt stuff :)

  159. Re:My /. password is... by graniteMonkey · · Score: 1

    Hey! That's the secret code I use on my luggage!

    --

    This is a manual virus. Copy it to your sig and help me spread!
  160. Uh Oh... by Greyfox · · Score: 2
    Maybe I should change my root password from MrNipples...

    Oh! Did I say that out loud, or did I just think it?

    --

    I'm trying to teach myself to set people on fire with my mind... Is it hot in here?

  161. Re:Writing down passwords isn't always stupid. by randombit · · Score: 1

    but I really prefer rot13!

    I would recommend double-rot13 for extra security.

  162. Re:Writing down passwords isn't always stupid. by randombit · · Score: 2

    Somebody hacks my machine across the internet and I'm toast.

    Of course:

    A) You can always encrypt something stored on a computer with GnuPG or simliar, and keep that password either in your head (preferable), or written down somewhere, or maybe write down a hint for yourself on paper but keep the actual password only in your head.

    B) If someone cracks you're machine, they probably won't need anything else. They can trojan your /bin/login and ssh/sshd to email the passwords you use to log in to wherever (bonus points to those who replace Mozilla/Netscape with a trojaned copy that sends transcripts of SSL sessions too) to some address at hotmail, they can obviously copy any files you have on your home machine, they can probably do a lot of other nasty things.

    It's tucked in a relatively obscure location in my files.

    This obscure location isn't "it's taped onto the side of my monitor", is it? If you're keeping it someplace hard to find (or better yet, a safe), then no problem. However, most people who write down passwords don't do that. I live with 3 non-techie people, and they do things like use their birthdays as passwords (literally). These people are well educated (in their fields) and certainly no fools. But people just don't get security. That's all there is to it. For every one person writing down their passwords in a safe place, there are 100 putting it on the side of their monitors.

  163. Another stupid password trick by sg3000 · · Score: 3

    For a while I learned how to type using a Dvorak keyboard layout. So what I'd do is use a common phrase for me, but type the letters in the Dvorak sequence on a Qwerty keyboard. Or the reverse. Bingo, a relatively simple passphrase became jibberish.

    Unfortunately, it was too hard to switch back and forth between Dvorak and Qwerty, and my regular typing became jibberish as well. So I quit doing that, and went back to the slow ol' Qwerty way.

    It was a cool system while it lasted.


    --
    Insert simplistic political, ideological, or personal proselytization here.
    1. Re:Another stupid password trick by aethera · · Score: 1

      Dvorak is a lovely level of added security. Wost of my passwords are from a dead language. I look for a word that is decently long, *memorable* translation, and preferably uses several easy to type (with Dvorak layout) keystrokes/letter combinations. Spice with numbers and punctuation to taste. And then remember that my passwords really aren't that important anyways.

  164. opt out by arban · · Score: 1

    I wonder what percentage of those polled refused to participate out of fear that it would give out too much information.

    I probably would have (I fear I may be getting to paranoid).

    --

    "You like Chinese food." -Fortune Cookie
  165. not allowed to be cryptic by arban · · Score: 1

    You know what I hate? Sites that don't allow cryptic passwords. Especially the ones that hold precious data. Just yesterday I went to get a login at banks webpage, but it didn't allow "special characters" (this site also didn't allow a user name less than 6 chars, but that's another story).

    And there are those that restrict the number of characters in the password. I figure they don't want you filling up the database with 100 char passwords (not that would), but limiting it to 8 ... I think that is rediculous.

    \end rant

    --

    "You like Chinese food." -Fortune Cookie
  166. problem by god_of_the_machine · · Score: 1

    Nothing is more random or harder to produce than your thumb print or iris pattern - perfect, non-stealable, unique identifiers.

    When is the last time you have ever heard of someone getting their thumbs or eyes stolen?? If all you need to get at someone's bank account is a thumbprint, muggers would start ripping off people's thumbs. Personally, I would prefer it if someone just mugs me and gets me to tell them my PIN.

    -rt-

    --

    -rt-
    ** Evil Canadians are taking over the world. Learn about the conspiracy
    1. Re:problem by Steeltoe · · Score: 1

      Also, if accounts get hacked, and your biometric becomes known, do you have have a new thumb grafted on to get a new password?

      Of course! With rebates!

      - Steeltoe

  167. Re:Oops... by dunkelfalke · · Score: 1

    huh... thats exactly the same thing i use... another good one is "iwontsayit" hehe

    --
    "It's such a fine line between stupid and clever" -- David St. Hubbins, Spinal Tap
  168. Keyboard password by magi · · Score: 1
    I often make up passwords just by typing them. For example:

    d7f8g8h9
    j9f4h8g5
    ascg6888

    Can you see the logic?

    Just put your hands on the keyboard and find something you can type quickly, and that's it. Very useful for root passwords and such, which you need to write often. Just don't use qwer1234 or any other trivial combination, and you're probably safe.

    I'm not sure how easy it would be to make an algorithm to create such patterns. I hope not too easy.

    In any case, I usually try to force nonregularity by deliberately making a word that has some crypting meaning. For example, bo0bsiii (self-explanatory) or vivaiv111 (long live IV beer !!!).

    Sure, using a password generator would be safer, but those passwords are horribly slow to type.
  169. Cryptic == bad by BierGuzzl · · Score: 1

    It's no good to have a cryptic password unless it makes some sort of sense to the user. If it's too complicated, the user has to write it down, thereby breaching security. Considering most security breaches are from inside sources, guarding against your co-workers should be a priority for most people (unless they enjoy getting framed). So go with a password that is simple and easy to for you to remember, and make sure that it's really hard for anyone else to guess it.

    1. Re:Cryptic == bad by SecurityGuy · · Score: 1
      Cryptic != bad.

      I've remembered up to 20 or so at a time that were in the "random pronouncable" category (application generated). 10 or so of the "truly random" category work fine, too.

      Of course, I have to admit there have been times I had no idea what the passwords actually were. I just knew how to type them. :) There was even one occasion, early in my SA career where I had to give the password to someone who had paged me (yes, I knew absolutely who he was). I called back from a pay phone, and on finding out what he needed to do, told him I'd have to call him back from somewhere with a keyboard. :P

    2. Re:Cryptic == bad by Xibby · · Score: 2

      Not really, when I have a new cryptic password I write it down and stick it in my pocket for a few days, just incase. Change the password when I get in in the morning, and by the end of the day I've got it memorized. Once memorized, the paper with my password is subjected to digestive juices to destroy it completely. :)

      --
      I'm going to go back in my box and will think within the limits of my box: MS Sucks Linux Good I read too much Slashdot.
  170. Password Accepted by Mr+Fodder · · Score: 1

    I was under the impression that Swordfish was the only password I needed to go anywhere.

  171. Re:Competition time. by Creepy · · Score: 1
    Swordfish

    but at least Tron and War Games had an excuse - in the early 80s -I- could hack into most systems, given some effort. Nowadays I'm lucky if I can hack into my desk drawer.

    Hackers. Sneakers. any other 1 word title.

  172. Mine by Tayknight · · Score: 1

    I'd tell you how I came up with mine. But then it would be easier for you to guess. Then I'd have to change it in the 200 places where it is the same. I'm gonna learn some day.

    --
    Pair up in threes. - Yogi Berra
  173. Re:Writing down passwords isn't always stupid. by mindriot · · Score: 1

    Well it's not always stupid, but maybe unnecessary. Basically all you need is a secure (4096-Bit) PGP Key with a long and very secure password. Then make a list of all other less important passwords and gpg-encrypt them. So all you need to remember is that one password. In case you're a little more paranoid, get the int'l kernel patch and create an AES or RC6 encrypted loopmount, and put the gpg-encrypted password list on that. Should be safe enough for most cases.

  174. Why use passwords? by stickytar · · Score: 1

    Can't we all get along and trust that even those really moronic people who shouldn't alter cfg files should have ROOT ACCESS! If you love something (your cfg files) set them free.

    --
    believing the big bang requires a certain amount of supernatural faith
  175. Re:A few years ago... by Animgif · · Score: 2

    This can be a good thing...I am a sysadmin who practices this...but ONLY, and I repeat ONLY if only a select group of people know the machine password. In the Universtiy we don't allow Faculty/Staff to have admin priviliges on boxes unless they need it. We hold the local admin account and rename it. Also, you should just make sure that it is not held by anyone who would give it out... *cough, cough* look up *cough, cough*. In my organization you must have been there for 6 months before you get it.

    --
    ------ This has been provided as a public service! ------
  176. Hmmm... by SIGFPE · · Score: 2

    Which of the 4 categories does "old D&D character name" go into?
    --

    --
    -- SIGFPE
  177. Re:fuck cryptic passwords by Legion303 · · Score: 1
    If you're someone who goes to SF conventions every year dressed in a Star Trek uniform, "picard" would be a lame ass password.

    (*putting on flameproof suit*)

    If you go to SF conventions every year dressed in a Star Trek uniform, poor passwords are the least of your problems. :)

    -Legion

  178. Re:My Random Method by Legion303 · · Score: 1
    Dictionary attack.

    -Legion

  179. Re:Hello, by Legion303 · · Score: 1
    uh hi my names joe, my AOL (k-l33t!) password is ROFLMAO, do i get a prize? thx d00d

    -Legion

  180. Family Guy by Viking+Coder · · Score: 1
    Peter Griffin : Oh, my God - there's a message in my Alphabits - it says, "Oooooo"!

    Brian Griffin : Peter, those are Cheerios.

    --
    Education is the silver bullet.
  181. Here's what I always did: by psxndc · · Score: 1
    Pick a certain "vocalbulary" like say planes. Choose only certain ones like F-14, F-16, A-10, etc. Then make up a password based upon them like f14a10f4. Then if you _need_ to write it down to remember you can use tomcat-thunderbolt-phantom on a sticky (that you keep on your person). That way people can't find the sticky and instantly know your password. Best of all, if you stick with a set vocabulary, you can rearrange them without too much confusion. Crap, my password isn't f14a10f4. Lets try a10f14f4. Tada! Of course I really use something a lot more obscure than airplanes, but you get the idea.

    psxndc

    --

    The emacs religion: to be saved, control excess.

  182. Re:The passward is electrifing by jgerman · · Score: 2

    Those numbers are kind of low, are you sure you're a geek?

    --
    I'm the big fish in the big pond bitch.
  183. Best method I have found by jallred · · Score: 1

    is to use a combination of family, fan, whatever + cryptic. That is, Come up with a sentence such as "my 2nd Sister was Born on April 23rd" and then take the first letters/numbers of each word like this "m2SwBoA23" to create a cryptic password. This makes it easier to remember the password while also creating a mixed case and combo letter/number password. I've found that the key to remember which letters are uppercase is to make those words which are "more important". In this example I consider "Sister, Born, and April" to be of greater importance than "my, was, and on". Anyway, works for me!

  184. Re:Is there a category for... by kirby697 · · Score: 2

    Yeah, they're called MY BOSSES :-)

  185. innermost secrets? by Barahir · · Score: 1
    Millions of Britons reveal their innermost secrets through their computer passwords, making their office PCs incredibly vulnerable to attack according to a recent study.

    If a password is based on your innermost secrets, doesn't that make it hard to guess?

  186. Dilbert Password by JojoLinkyBob · · Score: 1
    Reminds me of a really funny dilbert comic, I can't quote it exactly but it went something like this:

    Dear Personnel, our security department has exhaustively analyzed our password usage, and determined that most of them are high risk, in that they are easy to crack. For example, words in the dictionary, family member names, numbers, etc. Because of this, we have created a list of ten passwords which we believe will provide the utmost security. From now on, you are required to use one of the following passwords. Please forward this around, so that the message gets out.

    1. jfkasjdfa23r@#$@#
    2. aFAWJF@#F23jkf3f23
    3. FJsdafj23ifj23fjfe
    4. if23F@#Jf23fj2i3fji
    5. @#F23kfjfjdkfjdfkj
    6. afj28fjfsdFAJSDffd
    7. F@j3fj8dsjfasdflkjf
    8. jaF@#FJdkfjalofiwed
    9. aAJSDFIEifjefijefiej
    10. FJAIEFKfjdfojiaejfoije

    Thanks,
    Human Resources

    heheh

    --
    -jc
  187. passkey by Khopesh · · Score: 2

    "'I don't want to have to remember 18 different passwords.' You don't Genuis, give the same password if you must, but make them tough."

    my general password is some really cryptic (l33t) phrase. that's my password for everything not linked to $$$. my trick is that I add a hash of the site I'm at (using a common scheme) to make the password unique. I've got something hard to crack, unique per site, and if somebody gets ahold of one password, they have no others. my scheme is complex enough that they shouldn't find it even with three or four passwords (or so I'd like to think).

    --
    Use my userscript to add story images to Slashdot. There's no going back.
  188. Re:Too many passwords? by Fesh · · Score: 2
    Favorite one I heard from a friend(and I hope to god he doesn't use it anymore) was "^inmy:"...


    --Fesh

    --
    --Fesh
    Kill -9 'em all, let root@localhost sort 'em out.
  189. Groucho on social engineering by e7 · · Score: 2

    Yeah, it's from Horse Feathers:
    CHICO: You can't come in unless you give the password.
    GROUCHO: Well, what is the password?
    CHICO: Aw, no! You gotta tell me. Hey, I tell what I do. I give you three guesses. It's the name of a fish.
    [...]
    CHICO: You can't come in here unless you say 'swordfish.' Now I'll give you one more guess.

    (Harpo gets in by displaying a mounted swordfish trophy.)

    --
    Corollary to Moore's Law: The IQ of new computer owners is declining.
  190. Re:Passwords :: We need a better way by jfmiller · · Score: 1
    My office has also looked into this. Most of our users fall into the Family security zone. Our biggest problem is that the state run system requires that passwords be changes every 38 days. This is too often. it causes too many passsword to be used and leads otherwise responcible users to use simple password rotatations (pass1,pass2,pass3,etc...) that defeet the hole purpose.

    I have looked for a system that would use cards, fingers, eyes, etc... to idintify users to the system and thus make our office more secure, but ther doesn't seem to be anything out there the fit our criteria. If any R&D folks are reading this and think they can make a system like this theres a wide oben market.

    JFMILLER

    System requirements:

    Cost no more then $250 per user plus $5000 start up cost
    Use a single form of ID for all logins. (i.e. no passwords)
    Compatible with tetrminal emulation software and configurable to current system. (i.e. We can't change the state system)
    Compatible with Lotis Notes, Win2k, Novell and Web.

    If you can do this You can make a lot of money.
    --
    Strive to make your client happy, not necessarly give them what they ask for
  191. Re:Wow! by bad-badtz-maru · · Score: 1


    I am doomed, I can never remember to click on the "No Score +1 Bonus" message and thus keep posting drivel at +1.

    maru

  192. Re:Wow! by bad-badtz-maru · · Score: 2


    The post to which I was replying essentially asked why a longer password was more secure. My reply was obviously noninformative for most of us, who already knew the answer. Not sure why you couldn't figure that out.

    maru

  193. Good password system I got from a slashdot poster by bad-badtz-maru · · Score: 3


    About a year ago there was some sort of discussion here about methods of password generation. Someone had the best system I have seen, and I have been using it ever since. It's based on the use of simple math formulas, such as 8+7=fifteen or 24/8=three . It has many advantages. It's relatively long, uses shifted characters, and isn't hard to remember. Another advantage I discovered after we started using it regularly is that you can verbally relay the password to another admin who might have forgotten it and that admin (who knows that the answer to the equation is spelled out) can then use it but others within earshot who heard it will not understand how to use it.
    A tip of the hat to whomever it was here that originally posted that method a year or so ago.

    maru

  194. Re:My /. password is... by DarkHelmet · · Score: 1

    Ugh, that's the kind of password that an idiot president would have.

    --
    /^[A-Z0-9._%+-]+@[A-Z0-9.-]+\.[A-Z]{2,4}$/i
  195. Re:The passward is electrifing by RFC959 · · Score: 1
    10 phone numbers
    Thank you! I do wonder how people can whine "I can't remember w@ltz3r without writing it down, it's too hard!" but they can remember a ton of people's completely arbitrary phone numbers.

    Of course, I'm reminded of a manifesto which said something to the effect of "If we wanted to make the crappiest communications protocol imaginable, we'd give people random numeric addresses and force them to be at a specific physical location to send or receive messages..."

  196. Too many passwords? by AMuse · · Score: 3

    Users, generally, have too many passwords to remember. And no one wants to subscribe to MS Passport. Writing down the password, as well, is equally foolish.

    However, to be a good SysAdmin, you really need to try to find SOME way for your users to have both a secure password, and one the can remember. (OR you'll be resetting it constantly).

    I advise my users to think of a sentence to use as a mnemonic device, and make their password off that. ie, "My Sysadmin Has Too Many Piercings Today" - their PW would be mshtmp2d. I know, it's not as good as, say, "54kaSgHJ3", but most crack programs will take a hell of a long time on a NICE computer to break it, and the users feel more comfortable with it.

    Really, the point is to make the password not easily guessable, not write it down, but easy for the user to remember.
    --------------------------------------- -----------

    1. Re:Too many passwords? by rgmoore · · Score: 1

      This is a reasonable point. I guess that I just didn't think about that because I can touch type and can use moderately long passwords that contain upper and lower case and punctuation without too much trouble. I can see that it might be a problem for other people, though. OTOH, I think that it's probably easier to type in a whole sentence blind than it is to remember a jibberish password- and I think of myself as having a pretty good memory. Of course if you're really serious about security you'll just give everyone a personalized smart card that generates time sensitive passwords anyway.

      --

      There's no point in questioning authority if you aren't going to listen to the answers.

    2. Re:Too many passwords? by rgmoore · · Score: 3

      Of course on a modern system that uses MD5 passwords, it would be fine to use the whole sentence as the password (passphrase) instead of abbreviating it. Typing out something that long could get really annoying after a while, but if you're really interested in security it would be worth it. If the goal is to increase the keyspace, the simplest way to do it is to allow longer but still memorable passphrases, not to force people to remember gibberish.

      --

      There's no point in questioning authority if you aren't going to listen to the answers.

    3. Re:Too many passwords? by jrockway · · Score: 1

      Yup! People laugh at my password, it's at least 20 characters. I show them, though. My g/f had a nice screensaver password that I needed to circumvent. Failing social engineering :), I guessed. My first attempt was correct...it was 'jon'... she uses my name to protect her system from me... *sigh*

      --
      My other car is first.
    4. Re:Too many passwords? by markmoss · · Score: 3

      use the whole sentence as the password That's fine if you can type a whole sentence blind without any errors. Most people can't.

  197. Re:Foreign Language Passwords by Robert+Borkowski · · Score: 1

    Mine does, to my users' surprise. Don't assume that crackers are less clever than you are. My crack list has all sorts of bizarre things in it, and it gets permuted by 'John The Ripper'.
    If the language has a dictionary, then do not use that language. I think this falls under not using published materials for passwords...

    --
    This .sig intentionally left blank
  198. Foreign Language Passwords by Logic+Bomb · · Score: 2

    Most everyone has to learn the basics of a foreign language in school. I've always just used a handful of easy-to-remember words from one of the ones I studied. No automated cracking scheme goes through foreign dictionaries too. :-)

    1. Re:Foreign Language Passwords by Logic+Bomb · · Score: 2

      Ok, forgot the little line saying I was being (or attempting to be) funny. Never mind. ;-)

  199. Or what about.... by [ella] · · Score: 1

    some other stupid ones
    change_on_install
    manager
    blank

    And I see these a lot at customers, for whom I have to sign a contract that all information, especially passwords, is confidential.

    --
    Mike
  200. Re:My /. password is... by susano_otter · · Score: 4

    The Internet domain name registry CentralNic who commissioned the study, claims that the most common type of password attack comes in the form of "social engineering", when a cracker poses as technical support, and contacts someone in a different department within a big corporation claiming that there is a network problem, and asks for the user's password.

    Another option is to pretend to be doing a study of such things, and ask thousands of companies for their user's passwords.

    --

    Any sufficiently well-organized community is indistinguishable from Government.

  201. Re:The passward is electrifing by SuiteSisterMary · · Score: 2

    I use Secret, myself, because it has a desktop companion app.

    --
    Vintage computer games and RPG books available. Email me if you're interested.
  202. Oh, my by vanza · · Score: 1

    when a cracker poses as technical support, and contacts someone in a different department within a big corporation claiming that there is a network problem, and asks for the user's password.

    Are you sure this is not some reprint of a BOFH episode?


    --
    Marcelo Vanzin
    --
    Marcelo Vanzin
  203. Re:Stop demanding "strong" passwords by cryosis · · Score: 1

    determined hackers will get in the system, yes. most of us have accepted that fact. who we don't want on the systems are those joy riding skript kiddies. they make large messes and don't even do anything all that interesting. at least with a determined hacker you can watch and be amused/amazed/not notice until you main competator was an identical product as your's out.

    Life is a disease, sexually transmitted and fatal.

  204. My method for easy to remember passwords... by Gogl · · Score: 2

    Relatively simple really. Pick two words that are related, but unrelated to you. For example, I'm not into fishing. I could pick the words "bait" and "tackle". Now that you have those words, stick them together. But wait, there is more....

    Okay, now you have baittackle. Here are the other things you can do to it. Capitalize the first letter of each word. You have BaitTackle. Capitalize the last letter too if you like, for BaiTTacklE. Or just the last letter, or whatever. But then, the real cincher is add some sort of unusual symbol between the two words, such as + or = or - or / or whatever. Not all systems allow all symbols, but chances are you can figure out at least a few good unusual symbols your system allows.

    The end result could be something like BaiT+TacklE. Easy to remember, hard to crack.

  205. Re:Is there a category for... by Colz+Grigor · · Score: 2
    Sounds familiar, but when this was a common thing in my past I was working at an Internet-based streaming media company, where live webcams were placed on pan/tilt mounts that could be controlled from a public web page. Took them months to figure out why people from all over the net kept hacking into the web server.

    I got a kick out of it.

    ::Colz Grigor

    --

  206. Stick a fake password on the monitor by YIAAL · · Score: 3

    I have post-its with fake passwords scattered all over my office. I figure anyone who tries to hack my machine will waste a lot of time trying them, and will be so absolutely sure that one of them must work that in the end he will be too emotionally exhausted from frustration to try a more intelligent approach.

  207. but why bother? by whizzird · · Score: 1

    Why bother with a decent password on your account, when sysadmins all over the world make all the workstations have the same easy password?
    _ALL_ of the NT workstations where I work have the administrator password 'password'. Fortunately my NT is a vmware install running under Debian...maybe I should change my root password from password tho...

  208. Cryptic by aozilla · · Score: 2

    Yeah, God forbid if someone broke into my slashdot account and posted a message as me. I use easy to guess passwords intentionally. This way, if I ever post something I regret, I can just say my password was stolen.

    --
    ok then your [sic] infringing on my copyright! Could you as [sic] me next time before STEALING my comments for your own?
  209. Re:I'm with Stupid -- by rgmoore · · Score: 1

    If your system is really that valuable, though, you should invest some money in better security than passwords. Try as you may, passwords are never going to be really, really secure because users tend to subvert them. If you want real security you're going to need to add an extra level to the system, like smart cards or biometrics. Doing otherwise is like locking up your valuables with a skeleton key.

    --

    There's no point in questioning authority if you aren't going to listen to the answers.

  210. Re:How to choose a password by SilLumTao · · Score: 1

    A trick I use keep track of all my passwords is to combine a local and global pass phrase.

    My global pass phrase is common to all my passwords. For example: "A big blue monster ate all my cookies" becomes "Abbm8amc". When I log onto a site like slashdot, I create a simple association with the site. For example: "Slashdot is news for nerds" turns into "$dinfn"

    If I concatenate this local pass phrase with my global pass phase, I get "$dinfnAbbm8amc".

    This is a much easier way to remember multiple passwords so you won't be tempted to use the same one on different sites (not that I don't trust CmdrTaco).

    BTW, this is NOT my slashdot password.

    --
    "He was a wise man who invented beer." -- Plato
  211. My favorite is by Frequanaut · · Score: 1


    2b|!2b

    (Don't bother, I don't use it for web sites)

    1. Re:My favorite is by Plague+You · · Score: 2
      Hah! I had on a Netware 3.12 box:

      oh! for a muse of fire that would ascend the brightest heaven of invention

  212. Re:5 most common passwords!!! by CptnHarlock · · Score: 1

    yes, 1337 w0rdz are in the passwd dictionaries... so are a lot of Star Wars, Toliken and Star Trek terms, names and variations.. wonder why.. :)
    --
    $HOME is where the .*shrc is

    --
    $HOME is where the .*shrc is
    -- silver_p
  213. Is there a category for... by Ron+Harwood · · Score: 5

    ...the idiots that write their passwords on post-its and stick them to the bottom of their keyboards?

    1. Re:Is there a category for... by Martin+Blank · · Score: 1

      Could be worse. I went to help a user a few months ago, and asked her to put her password in to log into the network. (I have a personal policy of not asking for user passwords. I don't know them, I don't WANT to know them. Security starts with me.) She simply said, "It's right there." I looked to where she pointed, and there was her logon and password. Underneath it was listed the name of three banks with whom we have accounts, account numbers for them, as well as access IDs and passwords, with little notes like "Payroll account" and "Capital account" next to each one. Now, I work for a Fortune 500 company.

      It strikes me as slightly dangerous that someone has this information in OPEN FREAKING VIEW. I asked her to put the information in a safe place, and she argued, saying she referenced it too many times each day. I told her that it was a massive security problem. She finally backed down when I got her boss's boss involved (her boss didn't see a problem with it, either).

      It's a wonder support people don't go on murderous rampages more often...

      --
      You can never go home again... but I guess you can shop there.
    2. Re:Is there a category for... by lpontiac · · Score: 2
      At school, for example, valid passwords can not contain any symbols and passwords must be sent over telnet (no ssh). Therefore, I can't use my primary password since I have to keep that secure for online banking, work and such. So I am forced to come up with some new, throwaway password that won't compromise the rest of my stuff if it gets out.

      I don't use a password at uni that I use anywhere else, because I don't trust the uni admins.

    3. Re:Is there a category for... by swillden · · Score: 2

      get biometrics if you need to change your password every 3 days.

      If you really need such high security that you have to change passwords every 3 days, then biometrics are a terrible idea. There are many problems with the security of biometrics, but perhaps the largest one is that you can change your password but you can't change your finger. Once a biometric reading is digitized, it is just a password, one that can be sniffed, stored, redistributed, etc. -- but not one that can be changed. Once your finger is compromised it's always compromised.

      Biometrics can provide strong authentication, but they should be used as one factor of a multi-factor authentication mechanism, and the scanning, storage, transmission and comparison of the biometric data must be carefully secured.

      OTOH, they're also a convenient solution for environments that require low security -- as long as you don't plan on using that finger for high-security applications.

      --
      Note to ACs: I usually delete AC replies without reading them. If you want to talk to me, log in.
    4. Re:Is there a category for... by linzeal · · Score: 2

      get biometrics if you need to change your password every 3 days. the last place i worked we figured that up to 1/3 of the helpdesk calls were password related and it was costing 12 helpdesk salaries time to do it. so someone suggested biometrics and they layed off 2 people from helpdesk.

    5. Re:Is there a category for... by LionKimbro · · Score: 2

      I attach my passwords to my monitor, and have no problem with it. I feel safer, since I now have hoards of passwords, a different one for each web site.

      The obvious retort is, "But anyone can read it!"

      Is that so? If anyone can read it, and presumably you are somebody, just tell me what my passwords are... C'mon, it's easy: They're right on my monitor. Go on then.

      ...

      I'm waiting...

    6. Re:Is there a category for... by KurdtX · · Score: 1

      Listen to this:

      After reading the story I sent it to my dad, because I know his passwords are rather unsecure. (Coincidentally, he also holds the record at his old company for having the most files infected by an email worm when he opened one before heading to a meeting) He emailed me back to tell me he felt he was in the cryptic category because he used capitals and numbers at work. Turns our his "capitals" are capatalizing his name and the number was a '1' appended to what otherwise was his login.

      I haven't told him yet.

      Kurdt

      --

      Kurdt
      I'm not anti-social. Just pro-technology.
    7. Re:Is there a category for... by kenthorvath · · Score: 3

      I did that, and checked my log files. Apparently people DO check for things like post-its under the keyboard. My login: gullable, password: penii.Sure enough I saw a login attempt for user "gullable". I wonder if they got it...

    8. Re:Is there a category for... by ManDude · · Score: 5
      Part of the problem is stupid admins. They want strong passwords changed every 3 days for internal joe average accounts. What else can they do but post it to their keyboard?

    9. Re:Is there a category for... by skt · · Score: 1

      Well, it sucks because I can't remember 15 different passwords. I started keeping a hint list in a safe place a few months ago, but balancing all of my usernames / passwords for various online apps, work, school, and home has become difficult.

      At school, for example, valid passwords can not contain any symbols and passwords must be sent over telnet (no ssh). Therefore, I can't use my primary password since I have to keep that secure for online banking, work and such. So I am forced to come up with some new, throwaway password that won't compromise the rest of my stuff if it gets out. And to make matters worse, school also uses some kind of Microsoft authentication system that, much like the previous comment, keeps a list of all passwords that you have used in the last X number of months and then adds those to the invalid password list. Bleh, so I just came up with an increment that I add to my throwaway password.

      I think that the biggest problem is a lack of standards when it comes to password restrictions. For example, at work we use "three out of the five classes of characters" must be in your password, and then that password must be at least five characters long.. Then when I looked into online banking the other day, it requires a password five characters or less. NECXdirect won't accept symbols. Some systems only accept numbers. Of course, usernames are a completely different problem. they are almost like a secondary password now...

    10. Re:Is there a category for... by GeckoX · · Score: 1

      Just a little brainpower would bring you to the conclusion that one password for your local stuff and one dummy for anything that doesn't really matter.

      --
      No Comment.
    11. Re:Is there a category for... by dasmegabyte · · Score: 2

      I stick my password on the bottom of my keyboard. I do it in protest to the draconian IT policy which states that we need to choose a new, secure password containing four different character classes (one each of lower and upper case characters, numbers and control codes), be at least 9 characters long (which makes it absolutely impossible for our macs to connect, dumb IT fucks [ one can counter with "dumb mac fucks," but we need those macs to do our jobs of TESTING WEB APPS USED 80% BY MAC USERS]) AND BE CHANGED EVERY FIFTEEN DAYS! Now of course, you can still crack these passwords in a day and a half with l0phtcrack, but apparently we're making the world more secure.

      The whole concept is so unbeleivable stupid that I loudly say, whenever IT is within earshot, "YES, MY PASSWORD IS UNDER MY KEYBOARD. YOU CAN CHECK IT IF YOU LIKE."

      In retrospect, the domain admin password, which everybody fucking knows anyway, hasn't been changed in a year, and the sa password to our SQL servers, passed to four or five dba candidates when they were given their shakedown, HASN'T BEEN CHANGED IN FIVE YEARS.

      So let's review: our user accounts, tied down so that we can't shit in the corner without an admin password, are rotated every fifteen days and given extreme scruitiny, even though you can hack them in an instant, anyway. Our most important access password are never changed, and are so unbelievably simple that you can pretty much guess them.

      I can't believe you people spent two whole years in college for this!

      --
      Hey freaks: now you're ju
    12. Re:Is there a category for... by PYves · · Score: 1

      are-ay ey-thay itten-wray in-ay ig-pay atin-lay?

      Of course unbeknowest to you, your janitor is using your account to play yahoo! bingo.

      -PYves

    13. Re:Is there a category for... by Avinoam · · Score: 1

      ...and the bonus is that if you're going to drag around your keyboard, you might aswell stick your passwords to the bottom.

      --
      Today is probably not a good day to die.
  214. joke by sik+puppy · · Score: 2

    I like the cartoon of this smartass sitting at a computer - "Enter Password"

    Penis

    "Password not long enough. Please enter another."

    --
    The first thing we do, let's kill all the lawyers. Shakespeare, Henry VI, Part 2, Act 4, Scene 2
  215. Re:People! by FnH · · Score: 1

    As if cracker programs don't try their entire wordlist with the A replaced by a 4, the o by a 0, ...

    Passwords can get safer tham that and should ... p455w0rd is about as safe as ncc1701 ...

  216. Password security lessons from pop music by Jonathan+Blocksom · · Score: 1

    The band Barcelona has an entertaining song about password security entitled "I Have the Password to Your Shell Account". Find it at http://www.barcelonadc.com/frame.asp?p=sounds.

  217. Re:My /. password is... by Andrewkov · · Score: 1
    You're making me feel bad, my license plate says "3L337"

    ---

  218. I know of the _PERFECT_ system. by Com2Kid · · Score: 1

    Easy actualy, something that dictionary attacks are almost compleatly useless against, and that you will be able to remember no matter how many passwords you may have! Of course constant PW rotation can make this more difficult, but. . . .

    Take your favorite class, perferably _NOT_ from a major collage or such, pick a high school or middle school class that you took in the past.

    Abreviate the subject if necciary or depending on the length needed of the PW. So WorldHistory could become WrldHis. Now then, append the room number that you took it in, say you took it in portable 14.

    WrldHisP14 Add the teachers name. WrldHisP14Smith

    Tada, NOBODY would guess that password, ever. Not only is it long, but a dictionary attack would have a bitch of a time going through it even if it was programmed to use abbreviations. The more obscure the refrence and class of course, the better the password.

    ChmySci278Tugure.

    Soot, who'd guess something like that, eh? Hell, notice the cutsie abbrevation of chemistry, instead of the obvious chem or chemi, replace the 'i' with a 'y'.

    Once again, such passwords are easy to remember because that are CLOSE TO YOU, but they are something that almost nobody would guess. Shoot, even if they know what scheme your using for your passwords, not only have you taken alot of courses in your life, but there are MANY ways to abbreviate them. Granted if your scheme is known it signifigantly reduces the number of words that a person has to try, and if they get ahold of your class transcripts then they would have a listing of teachers names and such to go along with the class, and the only thing protecting you would be odd spellings and abbrevations, but shit. . . .

    If somebody can get ahold of ALL your personal information, then your fucked anyways :)

    I myself of course have a few added twists to that scheme, and I use more then one scheme to come up with my passwords (depending on the security of the site, and my own box of course has a compleatly different PW then anything else that I ever use :), but the method that I just outlined above is highly useful for those sites that want insansly long passwords, and for ones that want immensly short passwords. You can easily use a shorter class/teacher name for the shorter less security required sites, and longer class/teacher name for the more secure sites.

    Or hell, you can implement this as part of your 1337 u/\/#@ck@b13 password scheme and append a few dozen other phrases to the end of the ones created by my idea. As it is, easy to think up of, easy to remember, and easy to generate new ones as you need to change your passwords. And a total bitch to break :) Granted, alot easier then if it was a purly random sequence, but shit, with random sequences, ya got the post it note thing going against ya :)

  219. Password=Password? by langed · · Score: 1

    This reminds me of an old security program I used to use (way back in my MS-DOS days.) It was called PC-LOCK, and the default password was "PASSWORD". Installed lightning fast--even considering all it did was rewrite the partition IDs, update the bootsector on the active primary partition, and add a TSR device driver to config.sys (which allowed you to hit the shift key 3 times in rapid succession to lock the system.)

  220. It takes a team of trained IT professionals... by mdavids · · Score: 2

    I used to work for a hulking great multinational company; let's call them CompanyName Limited. I was not in the IT department, I hasten to add, but was let in on the top-secret root/NT domain administrator/whatever you call it on that platform password.

    You guessed it: CompanyName

    After I wiped the tears from my eyes, and my sides stopped hurting, I let some other people in on the secret and it was hastily changed. It's amazing what you won't learn in the process of getting your MCSE.

  221. Passwords :: We need a better way by ellem · · Score: 3

    --As a Sys Admin I have a sort of love/hate relationship with passwords. My users are required to remember no less than 3. (NW, Notes, Sabre.) Some of the savvier have managed to use the same password everywhere. Recently an edict was passed down from the PHBs to make everyone's password the same. Mostly so the PHBs could access anything. I showed them the error of this thought process.

    --"Then they can get eachother's stuff and yours!"

    --"But, they're not me, how could they get in?"

    --"If I have the keys to your house I could get in to it."

    --"Oh. But they'd have to sit at my desk!"

    --"Not really." (Of course I could restrict where users can log in from but they don't need to know that!)

    --But honestly I feel for these people. I have a ton of passwords too. Some are hard some are easy some I don't know thanks to cookies. The point being ther ARE far too many passwords.

    --I have been trying to envision a swipe card system wherein all a user's passwords are stored yadda yadda. Clearly theft of this would be bad, but so is losing your work ID swipe card. Perhaps this is coupled to a typed password for the card. (Which my users would write onto the card with a Sharpie.)

    --Of course the promise of fingerprint recognition (lop off the finger trick?) and retinal scans would make this idea obsolete in several years but something has to be attempted to lessen the password load.
    ---

    --
    This .sig is fake but accurate.
    1. Re:Passwords :: We need a better way by Timodious · · Score: 1

      I am working on deployment of a product called "P-Synch" which synchronizes passwords between NT domains, Unix systems (NIS/YP included), Oracle, and anything else you can write a script for. It will be wonderful when users can go to a web page and reset all of their passwords, or the help desk can change a user's password on all machines at once.

  222. Man, I finally have a category.... by woody_jay · · Score: 1

    It seems I am a self-obsessed, cryptic, family password creator. Life is good.

    --
    Of course, that's just my opinion, I could be wrong.
  223. False Password by orfeo · · Score: 1

    I wonder what percentage of people who were security conscious enough to use cryptic passwords were also security conscious enough to give them a false password. How many people reading /. now have another idea for a method of social engineering? "I'm doing a survey. What's your password?"

  224. Staples.ca by BigASS · · Score: 1
    Legal ramifications aside..

    No lie, the manager of the store had all employee login passwords to our AS/400 server changed to "swordfish" the same week the movie with the same title came out. Also, attached to the terminals in plain view is the entire login information for anyone to use. If that isn't sad enough, he gets paid more than us too.

    A password technique I enjoy to throw off over the shoulder reading is to use capital and lowercase letters side by side that are hard to visibily distingush like "iIlL0oOxX", "0Oo" being my favorite.

    --
    - Don't anthropomorphize computers, they don't like it.
  225. Re:The passward is electrifing by Martin+Blank · · Score: 1

    Phone numbers are memorable because people can associate simple patterns to them. They remember that a number has a repeating sequence, except for one number. One friend remembers my phone number because part of it is like a cross, only one of the numbers is off the cross. My passwords are memorable because I know the patterns that my fingers cover on the keyboard, and I know from the simple feeling of the placement of my fingers that I mistyped something.

    One of my users was an amateur astronomer, and used *1t in her password. She remembered it as "starlight". Phoneticization is an old trick, but I was impressed that she (a simple secretary and not very good with computers) used it.

    --
    You can never go home again... but I guess you can shop there.
  226. Re:My /. password is... by _xeno_ · · Score: 4
    Google "translation Fithos Lusec Wecos Vinosec" and feel lucky about it, and you'll be rewarded with:
    [W]hat Uematsu did was rearrange the letters in "Succession of Witches" and "Love" to make something that sounded truly Latin. Try it for yourself. All of the same letters are in there!

    Fithos Lusec Wecos Vinosec
    Succession of Witches Love

    I think it's cool that he did that because that also portrays the prevalent theme of Final Fantasy VIII.

    More information (like the words) can be found elsewhere.

    My mod points, please :)

    --

    --
    You are in a maze of twisty little relative jumps, all alike.
  227. Re:How about choosing based on ease of typing? by simetra · · Score: 1

    Yep, that's what I do. I found a really good one too. I used to make up cryptic ones, but after discovering ones that type quickly and easily, and are still reasonably obscure/secure, I'm not going back.

    --

    "Would it kill you to put down the toilet seat?" -- Maya Angelou
  228. Re:Writing down passwords isn't always stupid. by kirkb · · Score: 1

    Two words: House fire.

    --
    Slashdot: come for the pedantry, stay for the condescension.
  229. easiest password by bigbadbuccidaddy · · Score: 1

    This friend of mine had Pabst Blue Ribbon memorabilia all over his room -- signs bottles, etc. He wouldn't shut up about how great PBR is. This other friend of mine guessed his password in exactly two tries -- first try: 'pabst'. second try 'pabst1'. He couldn't figure out how in the world someone guessed his password. Heinekin!? Fuck that shit! Pabst Blue Ribbon!

  230. Webpages as Password Generators by eric434 · · Score: 1

    Eric's Method of Generating Random, Easy-to-remember Passwords: 1. Start surfing the web. Find something arcane (ring-tailed lemur mating habits, for example). 2. Scroll down so the screen is as full of text as possible. 3. Point your finger at a random point on the screen that isn't the middle. 4. The word or phrase that is closest to the chosen point and also closest to your desired password length is your new password!

    --
    This .sig temporary until a better .sig can be constructed.
  231. fuck cryptic passwords by AndyChrist · · Score: 1

    If you are one of the people who has to help people when they forget their password, you wouldn't be suggesting people do that.

    I always tell people "use the name of a dead pet." Easy to remember, hard for anyone but MAYBE ...MAYBE their close friends and family to guess.

    Otherwise, I tell people to do "fan" passwords. That's pretty stupid, though, if you pick something EVERYONE KNOWS YOU ARE A FAN OF. Like my friend who liked to wear Georgetown shirts and hats, and whose password was "hoyas." Moron.

    If you're someone who goes to SF conventions every year dressed in a Star Trek uniform, "picard" would be a lame ass password.

  232. ...from the website... by dbolger · · Score: 3
    "Computer passwords reveal workers' secrets

    login: dbolger
    pw: StalkingNataliePortman

    ;)

  233. what about dates? by emok · · Score: 1

    My mom uses the same 4-digit year for all her passwords: PIN, AOL, hotmail, etc. She doesn't understand why I think it's stupid.

    1. Re:what about dates? by jrockway · · Score: 1

      would that be "33137"?

      --
      My other car is first.
    2. Re:what about dates? by jrockway · · Score: 1

      9 digit numbers are pretty easy. 100,000,000 combinations... the program that runs crypt on all of those to compare to /etc/passwd takes about a second to run :(

      --
      My other car is first.
    3. Re:what about dates? by tb3 · · Score: 2

      My mom uses her WWII id number. She says she learned it when she was five and will never forget it. I think it's an 8 or 9 digit number, so it would take a little time to crack.

      "What are we going to do tonight, Bill?"

      --

      www.lucernesys.comHorizon: Calendar-based personal finance

    4. Re:what about dates? by .+O+_Malaclypse_+O+. · · Score: 1

      My Mom works at a large bank, where they do the same for the ENTRANCE CODE!!! (But you also need a key)

  234. Same password, many years by dada21 · · Score: 1

    I still use my same password from my BBS days for a LOT of stuff I shouldn't. It's just SO hard for me not to type basic1992 whenever prompted for a password.

  235. Re:Oops... by PopeAlien · · Score: 4

    Uh.. yeah.. there *have* been some problems at OSDN lately, but don't worry we're working on the problem. Everybody just needs to email their slashdot username/password to me and I'll check to make sure it hasn't been 'compromised'.. Have a nice day!

  236. Ran-Dumb passwords by Carlk · · Score: 2

    As ManDude said "Part of the problem is stupid admins. They want strong passwords changed every 3 days for internal joe average accounts. What else can they do but post it to their keyboard?" In 2 years I went from 0 to >10 pisswords. Most are written in my brainbook. [Bound, holds pens, no battery failures!] In case. My answer is to partition them into several parts: WHERE [eg: osU, TR]. WHAT [eg: unIversity, business]. DIGITS/SYMBOLS [314 (pi), 1414(sroot2, 981 (mm/s^2)]. So the Thomas Register password might be "TrBusi2718". The Windos NT5 Server at the college forces change of >8 char pw every 6 wks, and remembers up to 24 for uniqueness. All I gotta do is remember the few new digits, and apply them as I visit the sites. Since June the field orders are different.

  237. Re:I'm with Stupid -- by 2Bits · · Score: 1
    Hey, I'm a technical recruiter. You mind giving that password? :)

  238. Suggested Password Scheme by Elentar · · Score: 1
    An old coworker of mine had a scheme he suggested to users with problems using complex passwords - he would recommend that they use the serial number from their mouse, keyboard, monitor, or some other piece of equipment on their desk. It's long and cryptic, not as obvious as a post-it note, and if someone is sitting at the console they can break into your computer anyway.

    --
    The wheel it turns, around and around, with an ancient rumbling sound.
  239. Hello, by EvlPenguin · · Score: 2

    I'm with ZDnet. We're conducting a survey to discover the hidden meanings behind a person's password and what it reveals about that person. Please post your password as a reply to this thread. It's for science.

    Thank you.
    --

    --

    --
    #nohup cat /dev/dsp > /dev/hda & killall -9 getty
  240. My /. password is... by Psmylie · · Score: 5

    1... 2... 3... 4... 5...
    I specifically chose it because that's what I have on my luggage.

    --

    psmylie's dictionary: Godzillion (noun) Any number large enough to destroy Tokyo

    1. Re:My /. password is... by An+Onerous+Coward · · Score: 1
      Okay, it's clear that they're just posting this story to get people to reveal their passwords. Cmdr. Taco didn't even have to kidnap this guy's daughter and threaten to give her back her original nose. I can't believe how many are falling for it!

      Speaking of your sig (okay, so we weren't), does anyone know what the translation for "Fithos Lusec Wecos Vinosec" is supposed to be? Babelfish choked on it last time I tried. Fifty billion moderator points for anyone who tells me the answer (or invents a plausible-sounding one).

      --

      You want the truthiness? You can't handle the truthiness!

    2. Re:My /. password is... by kenthorvath · · Score: 3
      King Roland: Alright, alright I'll tell you the password to the air shields, just don't harm her!

      Dark Helmet: You have my word...

      Roland: 1
      Helmet 1

      Roland: 2
      Helmet: 2

      Roland:3
      Helmet: 3

      Roland: 4
      Helmet: 4

      Roland: 5
      Helmet: 5...
      Opening air shields with combination 12345 - That's the stupidest combination I ever heard!

      President Spaceball: That's the combination on my luggage.
      Commence operation MegaMaid - And somebody change the combination on my luggage!

    3. Re:My /. password is... by jrockway · · Score: 1

      > My mod points, please :)

      They should sell Mod Points at think geek. Really.

      --
      My other car is first.
    4. Re:My /. password is... by Omerna · · Score: 2

      The interesting thing is, I checked and he wasn't lying.

      --


      No sig for you.
    5. Re:My /. password is... by dossen · · Score: 1

      Just to nitpick:
      It's "President Skroob"

    6. Re:My /. password is... by zenintrude · · Score: 1

      I wonder what the percentage of 13 to 17-year-old computer geeks that use 1337 as their password...

      Category #6 should be "\/\/4|\||\|4 83 |-|4X0r"

      --
      - colin
    7. Re:My /. password is... by nixxy · · Score: 1

      The 13-17 year olds that would be using 'l33t speak' shit in there passes aren't geeks they are script kiddies

      I personally have about 6-10 passwords and use them for most things, good thing is i only have to try 6-10 passes on stuff if i forget a pass bad thing someone guesses one of the passes they might be able to access multiple things.. its just finding what i use and the right password. None of my passwords are written down but I tend to store them in dir on my comp... incase i forget.. but this still doesn't have all my passes.

      ------------

      --
      ------------
      "There is a thin line between genius and insanity and I can't walk straight"
  241. Re:Writing down passwords isn't always stupid. by oivvio · · Score: 1

    Not at all. In Secrets & Lies Bruce Schneier actually recommends putting your passwords on paper in some situations. Random passwords that are long enough to withstand brute force attacks by todays computers are also too long to fit into the human brain, unless you start fiddling with Hannibal style memory palaces.

    Now Schneier doesnt recommend you to stick the note on your monitor. But in a lot of situations Id say that even that is not such a big deal (No I dont do that myself. Its just too counterintuitive.) The security risk in my workplace is not my ten coworkers or the cleaning lady that comes in once a week. The script kiddies that want to fill my server with warez are the risk and the likelyhood of d00z sneaking into my office or even looking through my waste paper is about as large as that of SÄPO (Swedish secret police) launching a TEMPEST attack against me.

  242. Password is password by wpc4 · · Score: 1

    I work in the IT department of a huge Hospital "chain", if you will. I estimate over 90% of the passwords are either "password" or the six letter name of the company. The users that have actually changed their password have gone to other words, for example, jones or celtics. Nothing tricky at all. While we don't allow any "generic" accounts, if you know the first initial, middle initial, and their lastname there is a good chance you can login as them just by using password. How ironic, eh? Makes it easier for us IT folks, but does nothing for our security. Currently my service area is migrating to Lotus Notes for our messaging platform, moving from Microsoft Exchange. I have heard that the main reason for this was the increased security LN provides. The user ids come with wonderful upper and lower case 8 digit long passwords. What do we do when we get the id and start setting up the user? Change the password for a cryptic one, to, can you guess, "password". Thus defeating the whole benefit of going to lotus notes. Ah, well, whatever administration wants.

  243. Re:Writing down passwords isn't always stupid. by Feynman · · Score: 1
    I have every single password . . . written down [and] tucked in . . . my files.

    Similarly, after I'm forced to change my many passwords at work (*), I write the new one down on a slip of paper which I keep briefly in my wallet. My wallet is always in the pocket of the pants I'm wearing unless I'm performing a monetary transaction or sleeping at home (or otherwise not wearing pants). If that piece of paper gets stolen, I've got bigger problems!

    (*) Every 180 days, to something significantly enough different from your old one to cause trouble remembering

  244. Heh by neema · · Score: 3

    And then there's the category "Stupid" for the zillions who use "Trustno1", "Swordfish", and "Password".

    Yeah, those stupid people. Haha, they're so dumb.

    *Quickly loads preferences page to change password*

  245. suggest that. by loraksus · · Score: 2

    unless you work in helpdesk...

    The slashdot 2 minute between postings limit:
    Pissing off coffee drinking /.'ers since Spring 2001.

    --
    1q2w3e4r5t6y7u8i9o0pqawsedrftgthyjukilo;p'azsxdcfv gbhnjmk,l.;/
  246. Re:I'm with Stupid -- by Ian+Wolf · · Score: 1

    Please tell me you do that with a script.

    --
    "The words of the prophets are written on the Slashdot walls."
  247. Re:I'm with Stupid -- by Ian+Wolf · · Score: 2

    I expected this request a _long_ time ago, AC's must be getting a little sluggish.

    It was 127.0.0.1, hack to your heart's content.

    --
    "The words of the prophets are written on the Slashdot walls."
  248. Re:I'm with Stupid -- by Ian+Wolf · · Score: 2

    I'll give you that, but in a business? In a business who's business is e-com? Or a business who's hosting other company's sites and databases?

    I don't think so.

    Sure my passwords for my home box aren't the greatest, but my firewall/router's sure is.

    --
    "The words of the prophets are written on the Slashdot walls."
  249. I'm with Stupid -- by Ian+Wolf · · Score: 5

    Or I was I should say. One of my previous employers had fourteen NT/Win2K and 4 Solaris boxes all with the combos of administrator/password and root/password. Nice eh? Their web server, ftp servers, domain controllers, everything. I tried twice to get them changed. I even started to put better passwords on new machines, but the CTO kept changing them.

    "I don't want to have to remember 18 different passwords." You don't Genuis, give the same password if you must, but make them tough.

    To this day, if I want to call an old co-worker, but can't remember their number, I look it up on their intranet.

    --
    "The words of the prophets are written on the Slashdot walls."
  250. Re:Dear God ... by commodoresloat · · Score: 1

    I bet a good number of U.S. Congressmen do.

  251. Acronyminus Cowardus by Bluesee · · Score: 1

    When my sysadmin would change pass words every thirty days, I used to do acronyms of songs - er, dinosaur songs at that.

    Here, guess this Led Zep tune and win a prize.

    wfsteen
    kmlad
    idttr
    irbtbtbof
    idwicb
    cilybhily
    lglg
    bbsiblyy
    iatliatl
    lmwmoy

    etttm
    tydmng
    ...

    etc...

    (Since I've Been Loving You)

    It helps on a Monday morning to log in with a little soul on your fingertips.

    Oh, and if it's too short? Just add bbboy ("baby baby baby oooh yeah") or some other Plantism.

    This way, I could remember the pw 'cuz I only had to remember the song. When people asked me which song it was, I'd reply by singing "...a three hour tour..." It was the Song that became Ultra Super Double Top Secret!

    --
    SDMI: Finally! Music that won't rip or burn! Brought to you by the fine folks at RIAA.
  252. Re:The passward is electrifing by wishus · · Score: 2
    or

    C) Store them in a 128-bit DES encrypted database on their Palm pilot.
    ---

  253. What about non-passwords? by Jetson · · Score: 1

    My employer recently abandoned using passwords for the laptops. Instead each user is issued an IR device the size of a remore car alarm dongle and a PIN. To log in to the laptop they have to type in their personal PIN and complete the sequence by beaming a hard-coded signal from the IR device to the laptop. Not difficult to break using a Palm hand-held if you have access to the original IR device, but at least the average joe who breaks into cars won't get anything useful off the machine.

  254. Dumbiest password I have seen by SnapperHead · · Score: 1

    My father used this password for years, it only took 5 years or so for him to change it.

    qwerty

    When will people learn ?


    until (succeed) try { again(); }
    --
    until (succeed) try { again(); }
  255. My "Catagories" by AgentOBorg · · Score: 1

    I have several password types of my own:

    • Dumb (Public): Very simple, even idiotic password for things I plan to share and are not sensitive ("mage," "thanku"). I don't care who knows there - think "hint, not scrurity."
    • Sloppy and reused: but slightly cryptic: easily derived from words and for insignificant things. (I don't care if someone cracks access to my Consumer Reports Online.)
    • Decent: Good enough for typical use. (My POP3 accounts.)
    • Unique and Bizarre: Based onobsured things, multiply encoded in bizarre (non-mechanical) ways, full of numbers and symbols, never reused, and hard to invent. (For important stuff, like root, finacial services, webservice, etc.)

    I, at least, find this a practical system, there being a time and a place for all levels of goodness.

  256. here's mine by Syn404 · · Score: 1
    k, my password is z1m2x3n4c5b. In case it matters, I'm posting from a friend's account. so when will the results be ready?

    --

  257. Re:The clueless disease by Alien54 · · Score: 2
    LOL!! That was one of my submissions to that page! I've got a couple more there, and some on techtales.com too. God, it happened about 3 or 4 years ago now. I wonder whatever happened to that dimwit...

    With any luck he's a Microsoft programmer right about now.

    Which would explain alot of stuff.

    Check out the Vinny the Vampire comic strip

    --
    "It is a greater offense to steal men's labor, than their clothes"
  258. The clueless disease by Alien54 · · Score: 5
    Of course, there is the possibility that the user may be deficient in other areas as well

    As seen on Computer Stupidities:

    Student: "Hey, how do I lodge in to Hotmail?"
    Me: "You've got to type in your username and password in those fields that say 'username' and 'password'."
    Student: "I don't have one of those."
    Me: "You need one to log in to Hotmail."
    Student: "It's 'LODGE' in."
    Me: "The term is 'log in,' and you can't log in without a username and password. I can help you create one if you'd like."
    Student: "Um, excuse me, but I THINK I know what I'm talking about. It's LODGE in, and I don't want a username and password, I just want to get some email!"

    I just went back to working after that, and he left complaining about how "crappy" the computers in the lab were, after trying to "lodge in" for ten more minutes.

    Of course, there are hundreds of stories out there just like that one.

    Check out the Vinny the Vampire comic strip

    --
    "It is a greater offense to steal men's labor, than their clothes"
    1. Re:The clueless disease by Tviokh · · Score: 2

      LOL!! That was one of my submissions to that page! I've got a couple more there, and some on techtales.com too.

      God, it happened about 3 or 4 years ago now. I wonder whatever happened to that dimwit...

      There are a few more like that on my own page of work related stories:
      http://ubergoth.net/rtfm

      --
      http://pebkac.net
  259. Re:Add to that group by Erasmus+Darwin · · Score: 2
    "Password" does not necessarily need to be a "stupid" password.

    If you need significant security, it's a stupid password because it's guessable. If you don't need significant security, it's a stupid password because it's (relatively) long. You might as well go with "1234". It's equally guessable, but more than twice as easy to type (if you factor in both length and the ease of typing something sequential).

  260. GNU Keyring by TrumpetPower! · · Score: 2

    Obviously, most people won't put up with the hassle, but I've taken to using the GNU Keyring for PalmOS. It stores everything with 3DES and will generate random passwords for you. All I really have to remember is the one password to unlock it. You might think that (in my case) a twelve-character strong random mixed-case alphanumeric password would be hard to remember, but I enter it so many times a day it's easier if I don't think about it.

    Before that, I would use something like this:

    #!/usr/bin/perl -w

    use strict;
    use Digest::SHA1 qw(sha1_base64);

    $_ = my $length = shift @ARGV;
    unless (defined $length) {
    $_ = $length = 12;
    }
    unless (/^\d+$/) {
    $length = 12;
    }

    print substr((sha1_base64(`dd if=/dev/srandom bs=1024 count=1 2>/dev/null`)), 0, $length);

    print "\n";

    ...and keep the result in my wallet. I figured that, if my wallet got lost or stolen, I was screwed anyway, and loosing the passwords would be the least of my worries.

    b&

    --
    All but God can prove this sentence true.
  261. Re:Add to that group by daBum · · Score: 1
    "And then there's the category "Stupid" for the zillions who use "Trustno1", "Swordfish", and "Password""

    "Password" does not necessarily need to be a "stupid" password. I've used it on systems that have little access to anything else, or have meaningless data.Things that require passwords, yet don't have anything meaningful related to me. (i.e., "free" online services...) Alternately, I've used it in places that "casual" users wouldn't need access to, yet did not need full security (or main security was handled somewhere else). ex: password on a print server in a remote office.... for an account that only exists on that box, and has some local admin privledges, related to printing.

    Now, using it for passwords on things I actually care about... that's completely different.
    --
    I am dyslexia of borg - your ass will be laminated.
  262. Too many damn passwords! by ZanshinWedge · · Score: 2

    Every damn website wants a different password. For maximum security every password should be completely random and different.

    Back in the real world....
    I say, you have to know the level of importance of what the password is for. There's obviously a difference in importance to the root password for the database server you admin. at work and the password for your slashdot account. There's nothing wrong with using more easily remembered passwords for the low level stuff (various web sites and such) and only the highest level for the important stuff.

    One thing that I do for the "huge sea of moderately unimportant passwords that I don't need to use often" is put them in a text file and encrypt it using pgp. On the rare occasions when I need the password I can unencrypt it and copy/paste.

    1. Re:Too many damn passwords! by zhrike · · Score: 1

      I don't stop with the websites. I create cryptic passwords for everything. The more you do it, the easier it becomes as a matter of course. But in order to remember my passwords, I may have to write something down. So I memorize random strings of alpha-numeric characters and symbols. Anywhere from five to eleven characters, and I string them together to make various passwords. So when I do write something down, its something like this:
      !d_______3_________fF_________

      Where the first character or two points to a string which I already have memorized. Usually it doesn't take long for any written notes to be useless, and they never leave my person anyway.

      I will choose perhaps the same four or five strings to use for all of the web-based stuff, and just jumble them up.
      So that is one method I use to make easy to remember passwords for various sites.

  263. Hello, please answer this survey... by sulli · · Score: 2
    Please send all of your passwords to ZDNet Password Center for analysis. Don't worry, your privacy will be protected.

    Results:

    40% had passwords falling into categories "Cryptic, Family, Friends, Sex, Geeky, Miscellaneous."
    60% told us to fuck off. (correct answer)

    --

    sulli
    RTFJ.
  264. Passwords? Who needs to write down passwords? by RyuuzakiTetsuya · · Score: 1

    I have a cue cat. I used it for the admin password on my Win2k box and such. Incredibly secure. So secure, *I* don't even know my own Admin password. God that'll suck when my cue cat decides to break. Or I loose the barcode.

    --
    Non impediti ratione cogitationus.
  265. Re:Oops... by nekid_singularity · · Score: 1

    Don't feel so bad, I thought the same thing! I also thought that FUD stood for fucked-up disinformation.

    --
    Numbers 31:17,18 Now kill all the boys. And kill every woman who has slept with a man,but save for yourselves every virg
  266. Re:Oops... by jawtheshark · · Score: 1

    Actually at work I always use a large injury (with a number so I don't have to change it completely): fuckWorkAgain12 or so....
    Really is a good start in the morning, believe me ;-)

    --
    Ahhh...the great dumpster continuum. Many a free computer will be found there. -- sowth (748135)
  267. Muscle memory by groomed · · Score: 1

    I often choose a password based on how easy it is to type. Then I make sure that I type it a lot for a few days. After that, it's all muscle memory.

  268. billy logon. by Rev.+DeFiLEZ · · Score: 1
    $ ssh billgates@microsoft.com
    password: ilovetux

    Linux eviltactics 2.2.17 #1 Sun Jun 25 09:24:41 EST 2000 i586 unknown
    Welcome.
    billgates@eviltactics:~ $

  269. useful method by wheel · · Score: 1
    I read all of these posts at -1 and didn't see this system (though I've heard it from several live humans), so here it is:

    Pick a pass phrase, and use the 1st letter of each word as your password. If you're paranoid, do some 4@x0r char-number substitution on the result.

    Ok, so someone here thought of that, but then did something supremely goofy and added a couple of insane rules to it. Really!

  270. Password Requirements by Shickdawg · · Score: 1

    Maybe it's just the places I've worked, but they had requirements for passwords... For example, one company required that your password begin with a letter, end with a letter and have at least 1 number in it, and be no less than 6 characters. Passwords were changed every 3 months, and any given password could have no more than 2 character sub-strings in common with the last two passwords. Another company requires your PIN for certain online tools cannot start with 0 (zero), as all employee numbers start with said character. They both had tools in place to insure these parameters were met.

    It seems to me everybody should have such restrictions on passwords, to keep the family dog's name out of passwords.

    Kit

  271. Nice to know... by TrebleJunkie · · Score: 1
    It's nice to know that I don't fit in *any* of those groups.

    I pray to God that nobody spent millions on that study.

    I'd also like to have a copy of that "hey, buddy! I'm doing a research project, could you tell me what your passwords are?" list.

    Ed R.Zahurak

    --

    Ed R.Zahurak

    You know, oblivion keeps looking better every day.

  272. Re:fingerprints by agentZ · · Score: 2
    Fingerprints are not unique.

    Well, the jury is still out on whether fingerprints are unique. But, just like MD5 sums, although there may be collisions, the difficulty of finding constructing a collision is prohibitive to cracking the system. That is

    Given f(m1), it is very difficult to find an m2 such that f(m1)=f(m2) in a reasonable amount of time, where f(x) can be the taking the fingerprint or the hash of x. (Ironically, maybe that's why hashing is sometimes called "fingerprinting"...)

  273. How to choose a password by agentZ · · Score: 5
    If you really want to read all of the rules on how to choose a good password, check out this guide from MIT's SIPB.

    Do the karma whore dance!

  274. Abbott & Costello by tswinzig · · Score: 2

    Abbott: I'm having a problem logging onto your network.

    Costello: Well then what's your password?

    Abbott: Yes!

    Costello: I mean the text of the password!

    Abbott: What!

    Costello: Your password!

    Abbott: What!

    Costello: The thing you type to gain access to our network!

    Abbott: What!

    Costello: The text of your password!

    Abbott: What is my password!

    Costello: Now whaddya askin' me for?

    Abbott: I'm telling you What is my password.

    Costello: Well, I'm asking YOU what's your password!

    Abbott: That's text of the password.

    Costello: That's what's text?

    Abbott: Yes.

    Costello: Well go ahead and tell me.

    Abbott: What.

    Costello: Your password.

    Abbott: What!

    Costello: The text of your password.

    Abbott: What is my password!

    ...

    --

    "And like that ... he's gone."
  275. I always write passwords in my palm by DVega · · Score: 2

    I use a little PalmOs utility to store passwords. Its name is Strip. It stores all your passwords encripted with DES or Idea encription algorithms. It's GPLes and very useful.

    But don't use the password generator tool. It has a big security flaw.

    ---

    --
    MOD THE CHILD UP!
  276. 5 most common passwords!!! by B00yah · · Score: 2

    D00d, I tr13d the 5, god, sex, secret, password and love, and I hacked a gibson!!

    1. Re:5 most common passwords!!! by Technician · · Score: 2

      For the older crowd, don't forget the default Novell Netware password was also common as was the 2 secret words in the original Adventure Game. My first password was a cryptic password. It was a number of one of my favorite IC's (not a uP or TTL believe it or not) and a word found printed on one of my first computer keyboards. Happy cracking ;-). One of my favorite early programs used keystroke capture for password entry. Enter, backspace, arrow keys, shift keys could all be part of a valid password. Password length could be defined. After stating length, just hit that many keys and it would be recorded as the password.

      --
      The truth shall set you free!
    2. Re:5 most common passwords!!! by 4mn0t1337 · · Score: 1
      Hmmm...

      Does this mean that 3l337 h4x0r speak is inherently "Cryptic" and thus a safe password?

      Or have all of those script kiddies ruined safe passwords for the rest of us by forcing the inclusion l33t w0rdz in all of the pswd dictionaries??

      ______

      --

      ______
      Once: you're a philosopher. Twice: a pervert.

    3. Re:5 most common passwords!!! by dogbertcarroll · · Score: 1

      Swordfish was my password until the movie came out. I figured no one would think of using Groucho Marks' secret word. Of course when the movie came out I had to change it.

  277. Are most /. passwords cryptic? by brlewis · · Score: 5

    I'm sure we're all good cryptics here

    Do we really know that /. passwords are more secure than average. Everybody e-mail me your /. password. I'll summarize the results.

    Bruce Perens: Don't bother; I have yours already.

  278. Re:The passward is electrifing by Crizp · · Score: 1

    Yeah I feel the same sometimes.

    How I come up with my passwords: Just keep a hand on the keyboard, close my eyes and hit 8 random keys and throw a SHIFT in there a couple of times. The result is something like "gT4sF5G5".

    Then I write it down, and after a couple of times use I remember it and burn the note.

  279. Re:Dvorak Rules! by Grishnakh · · Score: 1

    I use Dvorak too, at home, and of course am stuck with Qwerty at work. What's weird is I can switch between them easily (like if I have my laptop next to my Dvorak desktop), but for some reason I can't type Dvorak on Qwerty, or Qwerty on Dvorak. I'm a touch typist and don't even look at the keys when I type normally. I guess it's some psychological block.

  280. What I don't understand... by hearingaid · · Score: 1
    ... is why people give a shit about cleartext passwords. I mean, anybody with router access can sniff out your password anyway. It doesn't matter if it's 08.xy.9~1ao or dude. It's still not going to be secure.

    I only use decent passwords for SSL.

    On an unrelated note, back in the '80s when I first started calling BBSes, I used to use colours as passwords. Like, green, orange, yellow. Nobody ever figured them out. Were they cryptics? :) (I picked the colour of something I happened to be looking at at the time I picked the password.)

    --

    my old sig used to be funny, but then slashcode ate it and now it's not funny anymore

  281. here is my password ... but how to use it by clarkie.mg · · Score: 1

    here is the password of my unix account : #fsb,avd Now you just have to guess where to use it ...

    --
    Men are born ignorant, not stupid; they are made stupid by education. Bertrand Russel
  282. No password by Bender+Unit+22 · · Score: 2

    Sometimes no password is better than a easy password.
    Many times i have seen people try to guess a password when there were none. :) of course this was on test setups where it really didn't matter. :-)
    --------

  283. Why the method by ackthpt · · Score: 1
    I pick out passwords which I can remember. I've seen some tricky ones, usually on little Post-It notes on screens, in pencil drawers, under keyboards, etc. The best was on a terminal for logging into a financial system, it was written on a card which was taped to the front.

    For best security: Choose a password you'll likely forget and absolutely have no chance of ever remember or re-discovery.

    --
    All your .sig are belong to us!

    --

    A feeling of having made the same mistake before: Deja Foobar
  284. How did you know... by excesspwr · · Score: 2
    my password was swordfish?!

    Great...it'll be another couple of weeks 'til I can come up with something even more creative.

  285. Password Generator... by HaeMaker · · Score: 1

    I use it always:

    dd if=/dev/urandom bs=1 count=8 2> /dev/null | uuencode -m /dev/stdout | grep -v begin-base64 | dd bs=1 count=8 2> /dev/null

    I am sure there are a million ways to do this better, but this is the way to do it that occured to me at the time I wrote the script.

    As you can see, my english is as verbose and cryptic as my shell scripting.

  286. 1st by CitznFish · · Score: 1

    First Post happens to be my Password of choice as well..

    --
    'mmmmmmmmm.... forbidden donut'
  287. Survey Methods by Kallahar · · Score: 1

    The article seems to imply that they had every password in the study, and that they also knew the names of the users. Therefore, isn't the biggest security threat that the users gave up their passwords? No matter how "secure" the password is, if you just tell someone because they say they are doing a study then that password is as insecure as "god".

    Social Engineering is a much bigger treat than hard-to-guess passwords...

    -Kallahar

  288. Fitting security to the need by feelafel · · Score: 1

    Although it's admittedly stupid, I find that using simple-to-remember passwords is far more effective than coming up with a "cryptic" one for each and every site on the 'Net that requires user registration. A quick mental count tells me that I have registered with over 30 web based services that require a password and login. I don't want to use the same password (see below) and remembering not only 30 passwords but which one I used on which site is absurd.

    I've come up with several cryptics which I use for sites that require high security - for a lot of these free web "services" that only require login to verify identity and get at bookmarks, I tend to use simple passwords that I can remember in order to not have to continually recall which password I used where.

    Also, I'm always worried about what happens if someone hacks these most likely not-so-secure sites and downloads a pwd file. At that point they'd have my most common username and password, and I'd be ripe for the picking.

    feelafel

  289. Easy memorizing, hard password by Kphrak · · Score: 2

    Because I often get on my local library's system to check my account or place holds on books, I use my library card number for my password. 9 digits long.

    But wait, you say, isn't that insecure? I could lose your card, or an evil librarian could get into all my accounts. AND it's a number so it could possibly be brute-forced.

    Not exactly. First of all, I substitute letters for some of the numbers. Another fun thing to do is to hold down shift while typing some of the numbers (maybe the first three). I'm pretty secure by that point.

    Also, I don't use my current card. I use the one I got at age 8 or something and lost about ten years ago...but not before the number was burned onto my consciousness. ;)

    People are always horrified when they say, "type in your password" and I sit down and type a nine-character password. Or when, due to some system stupidity, it echos my password to me and someone's looking over my shoulder, they see a big fatty wad of gibberish that's almost impossible to read at a glance, and even harder to remember (you could remember "five-six-seven-nine", maybe, but how about "percent-china_hat-ampersand-left-paren"?). :)

    The only thing that sucks is having to quote a password to someone. And sometimes poorly written (i.e. non-Unix) programs won't take non-alphanumeric characters. But other than that, it takes the best of both worlds; an easy-to-remember number and an extremely difficult password. Understandably, this approach might not please the ultra-paranoid, or people who change their passwords often (I alternate between different card numbers), but it's pretty decent when you want a secure password to memorize.



    -Andy Schmitt
    --

    There's no sig like this sig anywhere near this sig, so this must be the sig.
  290. Here I thought we were not doing a library check.. by (H)elix1 · · Score: 2

    for passwords, but then I found out I just can't spell...

  291. Re:The passward is electrifing by Xibby · · Score: 2

    Why does everyone think it's hard to remember more than one random alpha numeric sequence?

    Off the top of my head: 7 cryptic passwords
    4 internet IP addresses
    10 phone numbers

    --
    I'm going to go back in my box and will think within the limits of my box: MS Sucks Linux Good I read too much Slashdot.
  292. Well, here's my scheme, FWIW... by GTRacer · · Score: 1
    Actually, it's two schemes, one for network access and the other for internet.

    For the legion of sites where logins are necessary or desirable (/., NYT, etc.) I have two "core" passwords. When I register on the site, I pick a core and then a suffix that's somewhat related to the site, hopefully separated by at least one abstracion layer (New York Times -> NYT -> nit)

    That way, in theory, if someone hacks/engineers/takes at gunpoint one PW form one site, it's no good elsewhere as the core may or may not match and they still don't know the suffix.

    For net access I have a set of foreign words, some misspelled and laced with a numeric index and punctuation and mixed casing. Every 42 days (!) I advance the index, go to the next word and voila'!

    Has anyone noticed websites that only take 8 character PWs even if the input accepts more? My-Deja mail will let you type like 20 chars but it only validates the first 8!

    OK, now everyone tell me how lame and insecure my scheme is, IF YOU CAN !

    GTRacer
    - Social Engineering for Fun and Profit

    --
    Defending IP by destroying access to it? That makes sense, RIAA/MPAA. Go to the corner until you can play nice!
  293. Re:Random is the only way! -WHY?!?! by snakecoder · · Score: 1

    I've never understood this and maybe somebody can engage. Isn't it really just a matter of how you implement?

    I am assuming that most randomizers use chaotic formulas which means we don't need to worry about predictable patterns (In the topological sense there are patterns, but you can't determine what the next number will be without running through the equations yourself)

    Of course if you continually seed the pattern with the same number, your starting value will always be the same.

    My perspective:
    I use python whrandom as an example
    x=whrandom.whrandom(1,1,1)
    int(x.random*100)
    >1
    int(x.random*100)
    >89
    now set y-whrandom.wharandom(1,1,1) and you get the same values for the same steps.

    If I can predict how you seed, I've got your sequence. I can also chart out the number the 16 million start combinations and the first couple of thousand iterations to perform statistical analysis on what is more likely to pop up.

    But:
    But what about this.
    RandomVal=''
    x=whrandom.whrandom()
    while len(RandomVal) 10:
    y=whrandon.whrandom()
    selectChoice=int(y.random()*100)
    # 44 arbitrarily chosen
    if selectChoice == 44:
    # you could replace int(..) with a function that gives you alpha numerics
    RandomVal=int(x*10)

    You now run along one sequence line, but the start and stop points are based on multiple datetime seedings. Obviously this could be made more complex making statistical prediction as well as seed guessing a moot point.

    Basically randomize your radomize selector which selects the next randomize selector, etc... This methodology, while slow, eventually gets affected by processor temperature, other processes, etc...

    Go easy on my, I'm just an amateur.

    Note whrandom.whrandom() without seed numbers uses a time based seed.

    --
    -Nuke the moon
  294. Good Password Technique by corvi42 · · Score: 3
    A few little tricks I've picked up for finding good passwords:

    If you've ever played the "guess that vanity licence plate" game, this is an automatic way to come up with good passwords. You take a phrase or expression you know you can remember and obfuscate it as you might if you wanted that same phrase on a vanity licence plate but need to squash out characters so it will fit. For example, you might take the phrase "rose garden" - you could write it out as "rOzgRdN" ( where password is case sensitive of course ) so that when you read it you pronounce the upper case letters as the name of the letter and the lower case as the sound the letter makes. Of course 1337-ifying your passwords has a similar effect.

    Of course the nice thing about this is you can keep all your goofy old passwords - family names, celebrities and ego-boosting cliches, just make them difficult for a password cracker to grab out of lists of plain-text.

    Another trick that I've always liked is to use chess notation. Think of any move in a game of chess, one that you can remember easily and write it out using one of the conventional chess notations. For example the move "white queen captures kings rook 3" would be "wQxKr3".

    --

    There are a thousand forms of subversion, but few can equal the convenience and immediacy of a cream pie -Noel Godin
  295. Magic of MD5Sum by hjhornbeck · · Score: 1
    I'm surprised noone here has caught on to a huge advantage of one-way hash password systems, like MD5sum: they allow far more than 8 characters to be used. For instance, I used to be a big fan of Ren and Stimpy, so an ideal password for me would be "You're coveting my ice-cream bar!". It's too long for a password dictionary, too obscure since few people know I was a fan, has too many ways to misspell or alter it, yet I'll never forget it.Of course, it's a pain to type in at 3am. It's a poor choice if the system locks down your account after a few missed attempts, or limits you to 8 characters. But when it's feasable this type of password gives the security of a randomly-generated one and is as easy to remember as a self-chosen single word.

    HJ Hornbeck

  296. Cryptic != bad by einhverfr · · Score: 1

    Nonsensical == bad, but cryptic == good. Cryptic passwords which make sense are good because they are easy to remember but hard to break.

    --

    LedgerSMB: Open source Accounting/ERP
  297. Here is a secure scheme by einhverfr · · Score: 2
    I break my passwords down into three categories based upon the need for security and the security offered by the medium (I do NOT use the same password for my root acct on my Linux box that I use for an insecure login for a web site.

    For the insecure category, I use common a common dictionary word. For the midrange category, I use a derivative of a non-standard transliteration of a Middle Irish word.

    For the most secure, I will use a phrase from some other dead language, spaces omited, important words capitalized, punctuation included along sometimes with numbers. (Example I don't use: Cogito,ErgoSum).

    But what if you share root administration with one assistant? How about the following scheme: Each person comes up with a four character alphanumeric password and then the two passwords are put together. For instance if I come up with Lvx8 and the assistant comes up with Ek93, we get Lvx8Ek93--easy to remember because it is Lvx8 + Ek93, but hard to break. Since the 4 digit ones are often abreviated, this furthermore makes them easy to remember but hard to break.

    Thought I would share some tactics I have found useful.

    Also when I have too many passwords to keep in my head, I will leave myself a sheet of mnemonic devices for each password which is specifically designed so that others will be mislead... (Another unused example: Password is Thelema-- Mnemonic phrase is Will/Love. I will let the Thelemites figure this one out...).

    Golley, gee-- I must really be in the cryptic category....

    --

    LedgerSMB: Open source Accounting/ERP
  298. Re:A few years ago... by corky6921 · · Score: 1
    Yep, I work there, and they still are. :) The best thing is that IT won't tell them to you, and then you ask, "Is it 'welcome'"?

    "Oh... uh... yeah..."

  299. Zer0cool would like to remind you that.... by Str8Dog · · Score: 2

    ... a majority of Mac users use love,sex and god for passwords. HACK THE PLANET!

    --


    Str8Dog
    using System.Darkside; public
  300. Writing down passwords isn't always stupid. by whjwhj · · Score: 5

    Everybody keeps suggesting that writing down passwords is 'stupid' and something an 'idiot' would do. This is not always the case.

    Here, in my home office, I have every single password I need (about 20 of them) written down in pencil on a single sheet of notebook paper. It's tucked in a relatively obscure location in my files.

    Is this a security threat? Not really. Somebody would have to bust into my house and ruffle through my paper files in order to find them. Unlikely, at best.

    What would be considerably more insecure than writing them down is to keep them in a text file on my machine. Somebody hacks my machine across the internet and I'm toast.

    So next time you folks start throwing out terms like 'stupid' and 'idiot', think it through a little bit, OK? Saves you from the embarrasment of being the stupid one.

    1. Re:Writing down passwords isn't always stupid. by suwain_2 · · Score: 1
      Yes, I agree. There's a big difference between writing the root password down in black permanent marker on your monitor, and keeping a list of accounts/passwords located somewhere in the middle of your wallet.

      If someone is so desperate to steal my wallet, I'm okay with them reading my Netscape cache file and looking at some of my digital pictures...
      ________________________________________________

      --
      ________________________________________________
      suwain_2 :: quality slashdot p
  301. Re:The passward is electrifing by jumpingfred · · Score: 1

    I have about 20 passwords to rember for things like work, ATM, voice mail, back accounts. A lot of these also have some account name also ascociated with it. I don't know about you but I have to write these down or I will forget.

  302. Re:ergo tip by lastfish · · Score: 2
    Use a transparent post-it (or pref. an open-shtick alternative) so you don't have to move it everytime you need full-screen. An added plus is reduced risk from trash divers as each note will last longer.

    For extra security use black ink and turn the lights down a bit.

  303. keyboard sequences by VE3THX · · Score: 1

    I use keyboard sequences for less-secure (i.e. non-root) situations. Pick a rememberable repeating pattern of keys such as 4z5x6c7v; all I have to remember are the first two characters and the last.

    --
    Cheers, PJ Dougherty
    1. Re:keyboard sequences by beanerspace · · Score: 1

      Thanks ... that one should be easy to spot from across the room.

  304. My pass creation method by ratguy · · Score: 1
    I think I'm somewhere inbetween Fan and Cryptic. I like taking a song title (one that I'm listening to a lot) and then make an acronym out of it. Then I tag a number onto the end, front, or middle of it.

    Ratguy

  305. Competition time. by rixster · · Score: 1

    Name as many films with the "super-access everything" password as you can...
    (I can only think of 2 right now - Tron and War Games)

    --
    Two wrongs may not make a right, but three ....
    1. Re:Competition time. by Regolith · · Score: 1

      Let's see if I remember correctly...

      The Net
      Any film with a talking computer/"expert system" with a voice synthesizer.

      -----

      --

      Bow before my sig, for it is good.
  306. My (easier) way by truthsearch · · Score: 1

    My way is less secure, but far easier to remember. I randomly pick a decent length word from the dictionary. Some word that relates to nothing you would normally think of. Then I use synonyms or similar sounding words for other passwords. It's very easy to remember...

    ...and now that I think about it, it's educational as well! Damn, I should be really smart and use lots of complicated words in my posts, but I forget my old passwords, which probably makes for even better security.

    ---

  307. Passwords are insecure by definition by gelcaps · · Score: 1

    The problem with passwords is that they are not authentication of identity.

    The best secured system usually relies on passwords, somewhere, and of course, a chain is only as strong as its weakest link.

    --
    --- it's pelvis to be cube
  308. Oops... by jmcneill · · Score: 5

    I think someone discovered the password to my other account, 'Anonymous Coward'. People keep using it to post annoying messages under every article.

    1. Re:Oops... by suwain_2 · · Score: 1

      Can you actually use an asterisk as a password? In regular expressions, it does mean "everything"; do you know if UNIX will get confused by this? I'd *love* to set my password to a bunch of asterisks. 'Course, that's probably not very secure...
      ________________________________________________

      --
      ________________________________________________
      suwain_2 :: quality slashdot p
    2. Re:Oops... by underpaidISPtech · · Score: 1
      Ya know, I'm totally embarrased to say this, but when I first discovered /. , I thought Anonymous Coward was a real account. I didnt clue in until I noticed that AC was responding to its own posts :P

      <Dons flame-retardant suit in preparation for the inevitable onslaught.>

    3. Re:Oops... by Unknown+Bovine+Group · · Score: 4
      Yeah I called Microsoft tech support because my password was showing up when I typed it into the login box!

      They couldn't figure it out for quite a while until they asked what my password was....

      Of course, it was ******(star-star-star-star-star-star).

      --
      m00.
    4. Re:Oops... by Unknown+Bovine+Group · · Score: 4
      Of course there's another password category "people who make up passwords in hopes that someone WILL find them out".

      Like my pw I hope one day to have the FBI demand from me:

      password: guessityourselfyoudumbcunt.

      --
      m00.
  309. Love stories by imevil · · Score: 1

    I once found out two male users who had as password $GIRLNAME . $NUMBER, where $GIRLNAME had the same value for both of them. I don't remember the number. I know them, so I am sure they are two different ppl. Well, that's not password psychology, that's pure gossip...

  310. Re:Win Users Might Want to Try Password Safe by suwain_2 · · Score: 1
    Now, not that I'm accusing them or anything, but...

    How easy would it be for them to keep a database - someone from IP 1.2.3.4 tried "p4ssw0rd" and we said it was secure; and then log into that IP, and try common account names using that password?

    Again, not that I'm accusing them or anything...
    ________________________________________________

    --
    ________________________________________________
    suwain_2 :: quality slashdot p
  311. Social Engineering at it's best? by suwain_2 · · Score: 3
    The ultimate way to get everyones' passwords: Post an article to Slashdot, getting hundreds of people to post comments describing exactly how they got their password.

    Talk about "social engineering"... ;)
    ________________________________________________

    --
    ________________________________________________
    suwain_2 :: quality slashdot p
  312. Common passwords where I once worked... by perlchimp · · Score: 1

    I read a lot of posts, but not all 400, so sorry if this has been said.

    The last company I worked for was a free hosting company. Passwords were stored as plain text in a database(I did not set this up.) Once I selected out the 10 most common just for fun. 1 out of 40 people used 'password'. This was out of 50,000 users. I cannot remember the rest but the top 10 accounted for about 35-45% of all the passwords.

    1. Re:Common passwords where I once worked... by CKW · · Score: 1

      :)

      The last time I wanted to download Netscape 4.x gold, Netscape was forcing people to have some kind of free download account. You know, fill in a survey and get a username/password, then you can download junk.

      I didn't want to go through all that hassle, nor give them any personal information or e-mail address to spam. So I did sort of the same thing you did, I just started typing in pairs of the most common first names. paul/paul, john/john, etc. Didn't work. But the system had one of those "forgot your password, use the question-reminder feature" things. So I asked for "paul"'s password question. It was "home state". I chose one of the most heavily populated US States I know of, California. Bingo.

  313. Re:The passward is electrifing by geomcbay · · Score: 1
    Most people aren't geeks.

    I personally don't have trouble remember a number of passwords because I usually use these passwords nearly every day. (Actually a lot of my passwords are more in finger-memory than brain-memory. Can't for the life of me recall what the exact sequence is unless I am typing it!)

    Most people tend to use their passwords much less than that, though, and if you don't use them on a regular basis it can be pretty tough to recall, even if your memory for such things is generally good.

  314. Re:The passward is electrifing by geomcbay · · Score: 2
    Its kind of hard to remember more than one random number sequence password. So if users do use random characters (I assume you really mean random characters, since limiting yourself to just numbers reduces the possible keyspace quite a bit), they are likely to either:

    A) use the same password everywhere. Which is pretty stupid or

    B) Write their passwords down in a list somewhere, which is also stupid.

  315. dell by wroot · · Score: 1
    How about all of the morons who leave "dell" as root password of preinstalled Dell Linux boxes?

    No kidding. This actually happens.

    Wroot

  316. geek by astr0boy · · Score: 2
    "The cryptics are most likely to be what we would regard as "geeks"

    so "p9R14Tl7" (which is old) would or wouldn't qualify me for geekdom?

    -----

    --

    -----
    so i says to mable, i says

  317. Apple's Keychain by MasterVidBoi · · Score: 1

    While I'm not a sysadmin, and nothing particularly disastrous would happen if my passwords were compromised, I do like to keep them somewhat secure, and would like to place myself somewhat of a crpyic.

    Since I use a mac, I use Apple's Keychain system for password management. From the surface, it looks fairly secure as long as no one figures out your master passphrase. From there you can set access controls to allow none/some/all applications to have access to individual entries.

    I was wondering if anyone here had any experience on how secure Keychain is, such as how strong it's encryption is compared to how strong it should be to be reasonably crack-proof if someone managed to get their hands on the file.

  318. how about... by rudib · · Score: 1

    njiuhb? or qwertz? or a 'cryptic' one, XdRgBhU8... ;)

  319. biometrics plus by markmoss · · Score: 2
    Ultimately we need something that doesn't depend on human memory to retain "secret" information, hopefully not as drastic as implanting a chip... There are various biometric systems that (when they work) identify you by your own physical characteristics. One problem with those is that if you are identifying yourself to a server with your thumbprint (say), what keeps someone from just bypassing the fingerprint box and feeding in a recording? So a good system might be a chip on a card that (1) generates fully random passwords for you (like with a circuit that derives 1's and 0's from quantum noise), (2) remembers them, and (3) requires a live thumb on the sensor surface (top of the chip itself) every time you want it to crank out a password. But (4) you need some sort of backup system--muggers won't leave that card on you just because it won't do them any good. And this still leaves you vulnerable to someone snooping the lines while you are logging onto their target server.

    A better system would be that same chip, only instead of storing fixed passwords, it conducts a conversation with the server, proving it's identity in a way that a snooper cannot replicate. E.g., the server sends out a random number. Your smartcard checks your thumb is there and has a pulse, then encrypts the random number with a 4096 bit private key and sends it back. The server uses the corresponding public key to decrypt and check. Line snooping does no good, because the challenge (random #) and response (encrypted #) are different every time, and that private key never leaves the chip.

    1. Re:biometrics plus by CKW · · Score: 1

      One problem with those is that if you are identifying yourself to a server with your thumbprint(say), what keeps someone from just bypassing the fingerprint box and feeding in a recording?

      The same technology that prevents you from re-playing back an SNMP V3 USM or SNMP v2usec message.

      There are already biometric hardware systems available which result in unique encrypted messages which can not be replayed.

  320. Re:THe PsyChol0gy of g3t7ing la1d-ofF by Anomymous+Coward · · Score: 1
  321. You need a PASSWORD for that? by BillX · · Score: 1
    You don't need a password to root one of these. Just overflow the buffer in the sadmind program.

    I'm going to go out ass-first on a limb and suggest that Stupid probably hasn't applied the latest patches...

    --

    --
    Caveat Emptor is not a business model.
  322. Re:Sad mind? by BillX · · Score: 1
    This exploit has been known for a while now.

    --

    --
    Caveat Emptor is not a business model.
  323. Dvorak Rules! by matt_j_99 · · Score: 2

    I use the Dvorak layout on my keyboard, and that is a pretty good password protection scheme in an of itself! I'll use easy to remember words, like linuxrules, and convert them to the qwerty layout. So, linuxrules would be pglfbofpd; Plus, it freaks people out to start typing at the machine, so that is a pretty good protection mechanism!

  324. scooping hollywood by Salieri · · Score: 1

    I believe this idea was explored in the Michael Douglas thriller The Game, in which -- in one of the indistinguishable layers of reality and truth, anyway -- a psychologist gives said Douglas many hours of physiological and psychological exams for the surreptitious purpose of successfully guessing all of his passwords.

  325. Best password ever! by ByTor-2112 · · Score: 1

    Isn't everyone's password CPE1704TKS?

  326. People! by Strangely+Unbiased · · Score: 1

    You want a safe & simple password? Use whatever you want, written in lame-language e.g password--->p455w0rd Can't get any safer than that, and your Windows friends will admire you for your wisdom and coolness!

    --


    There is no such thing as 'world peace'.
    1. Re:People! by slashism · · Score: 1

      The password for use inside DS9 by the commander (Cisco?) was "Alpha-215." That could get him data and control of virtually every operation on the ship.

  327. Hoorah! Most redundant posting in Slashdot history by screwballicus · · Score: 2
    Solely for the sake of taking the record for the largest number of virtually identical explanations of a given fact in Slashdot history, I will now post that Swordfish was originally used as a password in the Marx Brother's movie Horse Feathers

    While I'm here on the redundancy bandwagon I shall further take your time to post, in pursuit of equally belaboured drivel, that the Gameboy Advance has a screen that can only be seen by certain breeds of Canadian Arctic Spotted Owl because battery life is more important than being able to perceive what is going on in a computer game and, further, conclude with an agonizing rebuttal, reading that The Gameboy Advance may only be 15MHz, but it uses a highly optimised(tm) RISC CPU (Q: as opposed to a highly de-optimised RISC CPU?) which is as fast as an SNES. I would go on about Linux vs. BSD and Macs: are they still viable? but this would eventually necessitate that I summarily smash my head directly through my monitor in a desperate last-ditch effort to end the horror slowly enveloping me.

  328. Also. . . by frosti · · Score: 1

    Don't forget the all-mighty "Peekaboo" password.

  329. Wonder why no one thinks of by lm747 · · Score: 1

    creating passwords from equations or inequations... Like five+3=8 or five+3!=225

    --
    --- lm747
  330. AOL by Regolith · · Score: 1

    Kinda makes you wonder how many AOL users have "A/S/L" or "ASL" as their password?

    -----

    --

    Bow before my sig, for it is good.
  331. Re:The passward is electrifing by flippety_gibbet · · Score: 1

    Maybe they choose not to.

    There's an anecdote that Albert Einstein did not commit his telephone number to memory - asked why not, he explained that if he needed to know it, he could look it up in the book...

    --
    <-- You are here.
  332. nothing by Aerog · · Score: 1

    Back in the day when I ran a highly unsuccessful BBS in High School, we had a problem with certain users (well, a certain user) getting local access and deleting all the executables on the computer, severly crippling the whole system. Needless to say we set up a password sytem and just set the password to nothing. Since it was high school, it confused the hell out of people even if they managed to hear someone talking about it.

    'course now it's just one of those that's rediculously easy in the real world. Oh well. maybe I'll just set mine to something nobody'll ever guess. asdf123 sounds pretty good. And nobody'll ever think of it!

    --

    - Relativistic? That's barely Newtonian!
  333. Re:simple passwd scheme by HohlerMann · · Score: 1

    Do you really want to hax0r my Macintosh 7200/120 running Mac OS 8.1?

  334. simple passwd scheme by HohlerMann · · Score: 2
    Old id software cheat codes work well for minimal internal security...
    • idspispopd
    • iddqd
    • idchopper
    • idclip
    • idkfa
    etc.
  335. No matter what u use... by CuteAlien · · Score: 1

    ... those great movie hackers will find it out anyway, just a few seconds before your evil plans will succeed. That's why hollywood rules this world :)

  336. Root Password of null string by Tech187 · · Score: 1

    I have a friend who ran Linux for awhile, Slackware 3.6. One night in a friendly mood after she'd just sent me an email message (she uses Earthlink) I read the header on the message to figure out what her IP was for the moment. I telnetted to that IP, but discovered that due to a reinstall that she'd recently done I no longer had an account to log on the machine and request a 'talk' session with her.

    I tried 'root' at login: instead.

    Yep. She had no root password at all. I quickly changed that by giving root a password, then (of course) created an account for myself. Then I logged off as root (this was a friend, remember) logged on as myself with the newly created account, and requested a 'talk' session to mention to her that her security had been, umm, a little lax.

    Slackware 3.6 didn't require you to (or even mention to you that you should) establish a root password, and of course the default is a root account with no password whatever.

    She'd been browsing the web rather actively for about a week in that state.

    Fun with Linux.

  337. A good psuedo-random number... by shobadob · · Score: 1

    Multiply the number of obsessive-compulsives (including me ;) who just had to tell us their "magical formula" for getting a password, by your karma. Make that number negative (if your karma didn't do it already ;). Multiply that by the number of characters in your most recent post.

  338. So let me get this straight... by Degauss+This! · · Score: 1

    Some company asked a bunch of people what
    there passwords were, and people replied back?

    Am I the only one who has problems with this?

    Degauss

    --
    ...If you're gonna be dumb, you'd better be tough...
  339. Why bother....... by b0geyeZ · · Score: 1

    If you want into someone's network, why mess around sniffing and cracking, when a bit of well placed social engineering gets a result 95% of the time. Examine the facts 1. Most helpdesk staff are underpaid, underworked and only doing it get to the "next level", whatever that might be. 2. Most mid-high level suits have bad tempers and little patience with underlings and technology. 3. Jo/Joleen average when faced with angry people who can have direct input on their future cave in faster under pressure than a bathysphere with a broken seal. Result, the CEO's account details with a changed password of your choice in double-quick time......... It does not matter how strong the password is if you can replace it with one of your choosing for the price of a phone call.........

    --
    top -l|grep $SUITS
  340. Looks like someone stole CmdrTaco's password again by jhill · · Score: 1

    Yet another brilliant post by our fearless leader. Maybe he should change his password to something other than password *grin*

  341. My password scheme by pyro_peter_911 · · Score: 1

    I just use "a" as my password. That way when someone launches a dictionary attack against my system it doesn't waste as much bandwidth as my old "zenzebrazygotes" password.

    Peter

  342. Another problem by Registered+Coward+v2 · · Score: 1

    with password choice are brain-dead forms for entering passwords.

    Take slashdot for instance:

    You can enter more characters than the 12 limit in its password selection box. So when I entered my password:

    RAS_macintosh

    it left off the h. It wasn't until I had my password emailed to me did I realize what happened and start leaving off teh h when I logged in.

    No wonder peopel pick simple passwords...

    --
    I'm a consultant - I convert gibberish into cash-flow.
  343. Does this scare you? by steddyj · · Score: 1

    Even after my repeated protests, my boss insisted I give a user the root pswd to the RHL machine in his office which he uses to check compatibility of journal papers we post online. His arguement? He has many years of experience with computers including work with the military. So I hand him a small slip of paper with the pswd on it. I tell him to memorize it and then "you know what to do with it" meaning of course to dispose of it properly. What to I watch this military man do? He looks at it briefly, then tapes it to the underside of the pencil tray in his desk! Doh!

  344. I'm torn by MarkusQ · · Score: 1
    I can't tell if you did that intentionally and are one of those people who goes in for very obscure humour, or if it is just a one-in-a-million (exactly one-in-a-million) coincidence. Neither one seems particullarly plausible.

    -- MarkusQ

  345. Win Users Might Want to Try Password Safe by idonotexist · · Score: 1

    http://www.counterpane.net/passsafe.html

    I am not with the company or anything. Just wanted to pass it on because it helps for easily generating and maintaining passwords.

    --
    "There ought to be limits to freedom"
  346. A few years ago... by Violet+Null · · Score: 2

    The most popular password was, according to studies, 'mozart'.

    Of course, anyone who has 'swordfish' as their password deserves to have their account cracked.

  347. My Random Method by Sonic+Dude · · Score: 1

    I truly believe that I have the best random method for finding a password. When I was in THIRD GRADE, I turned on the TV and the first word I heard became my password. Nine years later, I still have the same password. No person would listen to the TV shows from an entire year and try every word there just to get into my account.

    And, should my account ever be compromised, I'll break out an old Simpsons episode and pick the first word I hear.

    Anyone who knows my password may email me now, and I will begin worshipping you ASAP.

    --
    -BaV
  348. broken relations by mscout1 · · Score: 1

    Another good way to pick a pw is to use a number that once meant something to you, but is no longer associated with you. 40-15-40 is my high school locker combo. No-one else knows that this number has any importance to me. But 4 years of remembering it on a daily basis has permanently engraved in in to my gray matter. Then 1337 it (4ols4o). Now you have a pw that has no connection with you, is alphanumeric, and unforgettable. I could probably even tell someone and they will forget it because to THEM it is just a meaningless string of numbers. PS: That is not my pw. I use my Student ID#, not my locker combo (the same logic applies to both). I also lied about my combo # (might need to change my combo some day)

    --
    ------- I saw a VW Beatle the other day. The vanity Plates said "FEATURE"
  349. The passward is electrifing by The1lorax · · Score: 1

    the problem with having these sorts of studies is that I could call up some one I hate and ask: "Which of the following catagories would your password fall in?" Easy hack. People should have learned to use random number sequences by now.

    --
    You can't judge a book by the way it wears its hair.
  350. Good passphrases by Bob_Robertson · · Score: 1

    Enter Password: no. or how about, "fuck you i want my lawyer!" so you can pass the lie detector test....

    --
    The Ludwig von Mises Institute. The reasoning individuals economics
  351. Password? As Shipped by deathcow · · Score: 1

    Dont forget the geniuises who buy a $million dollar computer$ Vax setup and then forget to change the stock sysAdmin password. Thats another kind of password idiot altogether -- the default password idiot.

    We used this technique to enter our local (huge) school districts Vax setup, authorize our own accounts and play for a few weeks.

    In the end, the members of our hacking troop who were over 18 years enjoyed an entirely different conclusion to the fun than the two of us who were juveniles.

  352. Add to that group by NickFusion · · Score: 2

    "And then there's the category "Stupid" for the zillions who use "Trustno1", "Swordfish", and "Password""

    ...and M$ Passport....

    --
    What were you expecting?
  353. How about choosing based on ease of typing? by Ulwarth · · Score: 1

    I choose my passwords based on ease of typing. No, I don't use "fred" - I choose phrases that are easy for a touch-typist, because the keys alternate back and forth between the hands.

    Example: pqv0m3N

    This is "hard" to remember, but it's not hard to remember how to type it, because it's very natural to type if you're a touch-typist. Once my fingers remember the pattern, I don't have to remember what the actual letters are.

    I suppose I'd be in trouble if I ever had to enter it on a Dvork keyboard, or if I broke my left hand and had to type it all with my right :)

  354. Anecdote by return+42 · · Score: 1

    I used to program an IBM 370 in COBOL and I discovered one day that I could use a search routine to search for my password on all disks, which told me where passwords were kept (in clear - duh!) Browsed around a little and found the sysadmin's password: DAYOFF. Yep, that reflected his personality all right :)

  355. the only good system is to check constantly by nikster · · Score: 1

    on our university, the server was constantly running a run-of-the-mill password cracker program (dictionary, names, replace i with 1, o with 0 and all sorts of other "tricks"), which would send offending users a not saying basically "your password is stupid. reset it or you will be kicked". the nicely explained how to create safe passwords first of course. since i would classify as the cryptic type, mine was never cracked. since i can't remember tons of passwords, i have several categorized ones i use over and over again. categories go from low security (from sites that will lose the pwd anyways or store it unencrypted or for pwds that go over IP unencrypted (POP email, /.), to high security.

  356. Crappy program I wrote by duren686 · · Score: 1

    I was fooling around in VB (yeah, be quiet) recently and wrote a program that takes three words (username, keyword1, keyword2), combines them, and munges the result to generate an alphanumeric password that no-one will ever guess, and even if you gave it to them they'd forget it after a few min.

    --
    Y2K Compliant since the late 1890s
  357. Another technique by Derkec · · Score: 1

    Another decent way to get a fairly cryptic password that is easy to remember is to make some sort of pattern on the keyboard. Make sure you hit a number or two and some punctuation and you've got a nice, cryptic easy to remember password. I wouldn't guard the pentagon with it though.

  358. what am i what ami by tortus · · Score: 1

    i cant figure what group i belong to. im obsessed with my goldfish, but i consider it a part of my family. im confused. somebody help me. oh, by the way, its name isnt swordfish. it's "im a big stupid idiot"

  359. Did anyone else notice... by ELBnet · · Score: 1
    • That the numbers totaled up to 103%
    • People actually gave their passwords out to the people doing the survey!!
    I'd guess this means that only the real dumb were included in the survey!

    --
    -- I thought I was wrong once, but I was mistaken