5 ms·
He's lost two VITAL passwords? This seems like a false premise then (which is fine, but the fictional premise seems unneeded and disrespectful).
by bcook 10y ago
He's lost two VITAL passwords? This seems like a false premise then (which is fine, but the fictional premise seems unneeded and disrespectful).
- FiloSottile 10y agoEhhmmmm. stares at feet I wish I could tell you anything better than "in my defense, I seem to forget only one vital password per year..." (But seriously, I never risked data: the WD didn't have FDE, it was just a matter of salvaging the hardware; the OpenBSD was still in the middle of a migration and I had the source still accessible, so it was a matter of saving time. And it's fun.)
- bcook 10y agoSimply put (since the article neglected to include the password), what should we learn from the article? I imagine the password was "too short". PS - My POV is fully critical. Please, do not be personally offended. [emoticon smile]
- RubyPinch 10y agoI think the thing to learn from the article is "how to go deep diving into an operating system's internals"
- ComodoHacker 10y ago>what should we learn from the article? Off-the shelf NAS' security is shit.
- vog 10y ago> I seem to forget only one vital password per year For me, it helps to enter the passwords from time to time. The easiest way to do this is to reboot. If you have moral issues with rebooting a system where rebooting is not necessary, maybe run just the password checker, e.g. by unlocking a second volume that has the same password, or something.
- phyzome 10y agoI would probably forget my FDE passphrase if my laptop did not have a processor fault causing it to spontaneously reboot every couple weeks (particularly in hotter weather.)
- clarry 10y agoI've recently gotten in the habit of writing passwords (or at least a part of them) down in a notebook. There are just too many passwords to remember, some of which I use very very rarely. I don't trust any password managers running on a networked computer or (gasp) phone, so paper is good for me. Plus it's more reliable.
- brokenmachine 10y agoFrom the article: > Turns out all the password fields except the login form have maxlength=16, so when resetting the password I pasted it from the password manager and it got cut without me knowing. So it could have been another WTF on the NAS that was silently truncating his passwords. ...or he could have become a super-hacker because his memory for passwords is terrible. :P
- bcook 10y ago> ...or he could have become a super-hacker because his memory for passwords is terrible. :P Necessity is the mother of invention. :) (The password trunction is quite a "WTF" though. Thanks for mentioning that.)
- phyzome 10y agoWhy assume bad faith? I tend to forget passphrases very soon after creating them, around the time I am memorizing or changing a new passphrase, or after a month or so of not using one (depending on how long I have used it for.) Other people may have other patterns. I have a fair number of passphrases that cannot be reasonably stored in password managers. As we know, it's hard to memorize a lot of high-entropy strings. I suspect that memorizing new ones tends to push out old ones.
- Cpoll 10y ago> which is fine, but the fictional premise seems unneeded and disrespectful I don't see how taking the effort to write a more compelling story is 'disrespectful' to the reader. This sort of lie doesn't hurt the reader; this isn't the news, and the writer hasn't distorted any of the technical facts.