Slashdot Mirror


Password Security Not Easy

mekkab writes "The Wall Street Journal reports (yet again) that despite knowing better, users do dumb things to compromise security. Is seven different 8 character passwords (with numbers and mixed cases) really too much to ask? Do people need training on how to make well known phrase (to them) into a perfect password acronym, or other memory boosting techniques? Or is it that the entire business culture needs to change from within to take digital security seriously?" If you require unmemorizable passwords, you've effectively changed the security requirement from "something you know" to "something you have", and if the required dongle is a note under your keyboard...

29 of 674 comments (clear)

  1. As an admin... by 0racle · · Score: 5, Funny

    I hate people that put their password under their keyboard. Like damn people, on the underside of the desk, is that so much to ask.

    --
    "I use a Mac because I'm just better than you are."
    1. Re:As an admin... by maskedbishounen · · Score: 2, Funny

      Pfft.

      We all know "real" men just kick down the door after they lock themselves outside.

      And real geeks lock themselves inside. ;)

      --
      "An infinite number of monkeys typing into GNU emacs would never make a good program."
    2. Re:As an admin... by Barlo_Mung_42 · · Score: 3, Funny

      I write mine on the yellow note paper taped to the pull out section above the top right drawer.
      I change it every week. This week it is 'Pencil'. Don't tell anyone though.

  2. My Password by Greenisus · · Score: 3, Funny

    My password is weu@$9JKcpw34.

    No one has ever guessed it.

    1. Re:My Password by Spudley · · Score: 4, Funny

      I use my dog's name as my password.

      My dog is called Pchg65Lb, but he changes his name every few weeks. :-D

      --
      (Spudley Strikes Again!)
    2. Re:My Password by Feynman · · Score: 2, Funny

      Hey, that's mine, too!

    3. Re:My Password by Surt · · Score: 2, Funny

      That's a fairly large Picanese hybrid greyhound you've got there.

      --
      "Who is the Journal of Quantum Physics going to believe?" --Stephen Hawking
  3. Spaceballs Password by vivin · · Score: 3, Funny

    Best password/pin ever:

    [King Roland has given in to Dark Helmet's threats, and is telling him the combination to the "air shield"]
    King Roland: One.
    Dark Helmet: One.
    Colonel Sandurz: One.
    King Roland: Two.
    Dark Helmet: Two.
    Colonel Sandurz: Two.
    King Roland: Three.
    Dark Helmet: Three.
    Colonel Sandurz: Three.
    King Roland: Four.
    Dark Helmet: Four.
    Colonel Sandurz: Four.
    King Roland: Five.
    Dark Helmet: Five.
    Colonel Sandurz: Five.
    Dark Helmet: So the combination is one, two, three, four, five? That's the stupidest combination I've ever heard! That's the kind of combination an idiot would put on his luggage!

    --
    Vivin Suresh Paliath
    http://vivin.net

    I like
  4. The SlashDot Password Guessin' Game by oexeo · · Score: 2, Funny

    (Disclaimer: Please don't play this game!)

    1) Take the following five passwords:

    - password
    - slashdot
    - 123456
    - password123
    - [Username]

    2) Attempt to login to as many slashdotters accounts as possible.

    3) Post incriminating/stupid/slanderous/troll comments on behalf of users you now 0wn.

    4) While the FBI are busy smashing down your door: Take a hammer to your hard-drive's plateaus, and run like a screaming idiot while you think about how stupid you where to follow my instructions.

    (Disclaimer: Please don't play this game!)

    P.S. If your password was listed above: Change it!

    1. Re:The SlashDot Password Guessin' Game by mchugh · · Score: 2, Funny

      One down! :)

      (Insert incriminating/stupid/slanderous/troll comments here. Not to mention Offtopic, Inflammatory, Inappropriate, Illegal, or Offensive comments.)

      - notmchugh

  5. even no password at all by Anonymous Coward · · Score: 1, Funny

    incredible some slashdot users don't even use password

    see this anonymous coward, shame on him

  6. Re:I only have 2 passwords by Anonymous Coward · · Score: 1, Funny

    I use aaaaaaaa and goatse911 for everything. Haven't been rooted yet...

  7. In case you forget them.... by lukewarmfusion · · Score: 2, Funny

    ...just put them all in an Excel spreadsheet, keep a copy printed out and stored in your filing cabinet under a folder labeled "Passwords" and don't lock the cabinet.

    I gave my two weeks' notice and this was the first thing my bosses wanted me to do: write down all the passwords for them so they could keep everything on file.

    Fantastic.

  8. Re:Known for quite some time... by savagedome · · Score: 2, Funny

    There will always be that one person who will use their first name and last initial

    Yeah. Bunch of idiots. That's why I drop the last initial.

  9. Easy trick... by GillBates0 · · Score: 4, Funny
    Get someone to kick you in the nuts everytime you forget your password.

    You'll be surprised by how dramatically your capacity to remember passwords will improve once this becomes a regular feature of your workday.

    For added effect, construct horribly complex and impossible to remember passwords a few times every day. Over time, basic survival instincts and the urge to avoid the inevitable kick in the balls will overcome the limitations posed by your poor memory.

    --
    An Indian-American Hindu committed to non-violent thought/speech/action alarmed by the global explosion of radical Islam
  10. Re:I only have 2 passwords by Profane+MuthaFucka · · Score: 2, Funny

    My luggage is 1, 2, 3, 4, 5. Probably your luggage too.

    Actually, I have my luggage combination written in sharpie on the outsize, right next to the lock. It's 0-0-0-0. That's so the TSA can open it up if the numbers happen to get bumped away from 0-0-0-0.

    Online I have an easy password, which is used everywhere unimportant; a medium password, which is used on sites that I would not want to lose the account for; a hard password used on sites with sensitive and personal information; and a secure password which is used on sites with direct access into my bank account, such as bill pay sites.

    At work they require us to have those unmemorizable passwords, so I just tatooed it on my cock where it's always 'handy'. Had a bit of trouble when they increased the length from 6 to 8 letters. Those last two letters hurt quite a lot.

    --
    Fascism trolls keeping me up every night. When I starts a preachin', he HITS ME WITH HIS REICH!
  11. Re:I only have 2 passwords by Anonymous Coward · · Score: 2, Funny

    Tell me about it, just the other day I rooted some guy who used aaaaaaaa and goatse911 for everything. Poor sucker probably doesn't even realize he's been rooted yet.

  12. Admit it... by Anonymous Coward · · Score: 1, Funny

    Admit it, you "forget" your password on purpose sometimes, don't you.

    You sick bastard.

  13. Re: Use BIOMetrics by Anonymous Coward · · Score: 1, Funny

    It would be interesting to mix passwords and biometrics. In medium security settings, you could simply provide the requested information directly using the keyboard.

    Linux 2.2 (pts/1)

    username: cmdrtaco
    cock size: 2inches

    Welcome to The Lunix
    >

  14. President Scroob... by blueZ3 · · Score: 2, Funny

    Is that you?

    --
    Interested in a Flash-based MAME front end? Visit mame.danzbb.com
  15. Re:I only have 2 passwords by Anonymous Coward · · Score: 1, Funny

    We have very tight security. Every time I change my password, someone in the IT department calls me up and asks what I changed it to so they can verify that the new password is really secure.

  16. Re:My take : three zones by Chris+Burke · · Score: 2, Funny

    I like the sites that ask you to provide a challenge question that they will ask if you forget your password. My question is always "Go fuck yourself" and the response is whatever happens when I smack my palm on the keyboard repeatedly until the character limit is reached. I don't forget my passwords. :)

    Of course, then you call up your bank and all they want is your SSN and mailing address... Sheesh.

    --

    The enemies of Democracy are
  17. Re:Easy trick... The *REAL* BOFH by HighOrbit · · Score: 2, Funny

    I thought our help-desk guy might have been the original BOFH, but I was wrong. Even he wouldn't have thought of that. Man, you are harsh.

    [Suddenly the phone rings, disturbing the BOFH's game of Half-Life]

    [random_user]Hello Help Desk? I forgot my password. I have to print a powerpoint document for a briefing I am giving in 5 minutes so I need my password reset right now!

    [BOFH] Oh....let me check...we can only reset passwords once a day between 6AM & 7AM because it affects the user settings and we can do that after the server's been initialized. Otherwise the server might malfunction and several random files could be deleted from your home directory. Are you sure you can't wait until later?

    [random_user][pauses]yes, I need it NOW. I'm briefing our department VP in 5 minutes.

    [BOFH]ok... you're the boss...I'm resetting it to "12345678"...try loging on in a few minutes [while typing "del /users/random_user/*.ppt"]

  18. Re:Just get rid of them... by Desert+Raven · · Score: 2, Funny

    Yeah, no kidding. A junior manager in a company I worked as IT manager for got all pissed off because I required minimum 8-char passwords, so he set it to FFFFFFFF.

    Imagine his surprise when he found himself locked out of the system the next morning. Seems he didn't know I ran a password cracker against the password database every morning. 'course, he also didn't know I had caller-id. It took him until mid-afternoon to finally get hold of me, and only then because he got off his fat butt to physically track me down.

    He tried to threaten me by saying he'd report me to the company owner. Seems he also didn't know that the company web proxy kept logs of all activity. :) Funny part was, he also didn't know that the company owner had a much better catalog of porn links than he did...

    I kinda miss that job.

  19. Daily password changes by snuf23 · · Score: 2, Funny

    I once worked for a company where the insane CEO (dotcom era) decided to get serious about security by requiring daily password changes.
    The cool thing was that they never implemented any restriction on what the passwords could be.
    I think the most common passwords that resulted were Monday, Tuesday, Wednesday etc.

    --
    Sometimes my arms bend back.
  20. Re:If the required dongle is a note under your kb. by TheMadRedHatter · · Score: 4, Funny

    >a E9 b ?p c &m
    >d 6K e aY f eP
    >g !S h gn i D=
    >j Hd k vw l Cb
    >m W5 n 4$ o R3
    >p x% q 7M r NF
    >s +2 t s* u Ay
    >v fL w zG x Zu
    >y cX z Qr

    So what does the output of that Perl script look like? ;-)

    -- TheMadRedHatter

    --

    while(1)
    {

    }

    Ah, the story of life.
  21. Re:Biometrics by Anonymous Coward · · Score: 1, Funny

    ... and the next day he woke up in a bathtub full of ice and his kidney was gone.

  22. Re:Easy obscure passwords by acceleriter · · Score: 2, Funny

    Just stay away from Dvorak keyboards!

    --

    CEE5210S The signal SIGHUP was received.

  23. Re:Special Characters != More Secure by Anonymous Coward · · Score: 1, Funny

    Tolken-based authentication?

    Is that where your smart-card device is a ring of power? Or where a hobit is required to gain access?