5 ms·
This is an interesting attack that uses other people's password hints to match a hashed password. However, it seems unlikely that the Edward Snowden would use s
by casca 13y ago
This is an interesting attack that uses other people's password hints to match a hashed password. However, it seems unlikely that the Edward Snowden would use such a weak password to protect any resource that he considered sensitive.
Please use a randomly generated password that is as long and complex as the site you're using will allow, stored in a password safe.
- wereHamster 13y agoI don't trust third parties to securely store my passwords. The problem with randomly generated passwords it that they are hard (impossible?) to memorize. Password squares help there, because they allow you to visually memorize the password by using a path inside a random character grid. I recently created a website that generates a random 'password square'. It should display nicely on latest browsers (which support flexbox). You can optionally supply a seed if you want to reuse the same path but have it yield a different password. https://caurea.org/passwd/ https://caurea.org/passwd/ https://caurea.org/passwd/#seed https://caurea.org/passwd/#seed The website is intentially barebones, to allow you to print it out and store offline.
- Shish2k 13y ago> It should display nicely on latest browsers (which support flexbox) So after years of telling people "Don't use table tags for layout", web devs have finally got that message... and they've started using layout tags for tables instead :(
- oneeyedpigeon 13y agoIn no way is that a table. It's a grid.
- dnr 13y agoIf you're memorizing a lot of passwords, you're doing it wrong. Use a password manager and memorize one, that no sites ever see. (In practice you'll probably want to memorize another one or two for important accounts and a login password.)
- wereHamster 13y agoI tried to address that in the first sentence.
- dnr 13y agoNo decent password manager will expose your passwords to a third party. If syncing is supported, only passwords encrypted with your master password are sent over the network. AFAIK, that's how all the popular ones work. FWIW, I use "pass", which is a short bash script that's a thin wrapper around gpg. If you can't trust that, I'm not sure how you can use a computer. http://zx2c4.com/projects/password-store/ http://zx2c4.com/projects/password-store/ Btw, your password square generator isn't using a secure source of random numbers, which makes me highly doubtful.
- kbenson 13y ago> No decent password manager will expose your passwords to a third party. Unless you are verifying the source and compiling yourself, your password manager IS a third party. > FWIW, I use "pass", which is a short bash script that's a thin wrapper around gpg. If you can't trust that, I'm not sure how you can use a computer. Sure, I probably trust GPG and the devs behind it. But unless you are downloading from them directly and verifying binaries, or building yourself from their source (and comparing source), you aren't really just trusting them, you're trusting the people that are distributing GPG to you. If the provider is a well respected linux distro, I probably trust it, but it's quite a bit less trust than the GPG devs themselves get. There's a lot more hands involved there and many more places for someone to inject some nefarious code, or just plain screw up[1]. I guess the real point is that "decent" in "decent password manager", or any security product for that matter, has higher bar than in many other industries, but this many not be common knowledge. Edit: For that matter, I guess the only reason I trust GPG at all is that enough decentralized volunteers will look at it that coercing them all into keeping silent (or silencing them in another manner) about any backdoor they find is probably impossible (or at least requires enough effort as to make it unfeasible). [1]: https://www.schneier.com/blog/archives/2008/05/random_number_b.html https://www.schneier.com/blog/archives/2008/05/random_number...
- agrona 13y agoYou don't have to blindly trust a third party. I have a KeePass which can generate random passwords. I trust that because it's open source, so I could look at what they're doing--and build it myself--if I wanted. I store the db file in Dropbox, but I don't trust them either: my file is encrypted with both a unique password and a second key file which I've taken pains to only ever transmit by copying on removable media.
- unfamiliar 13y agoI'm guessing Snowden probably wouldn't use a hotmail account for anything sensitive.
- Periodic 13y agoI've been using PwdHash[0] for a few years now. It is basically a system for generating a password using your input hashed and salted with the domain name of the site. This takes the security of the password itself out of the hands of the site and allows for some password reuse. There are also browser extensions available which make it easy to use. 0: https://www.pwdhash.com https://www.pwdhash.com
- JulianMorrison 13y agoIt strikes me that this only grows the length of your typed in password by one bit: did they use PwdHash? Y/N. The other components of the salt, namely the site details, are implicit.
- plywoodtrees 13y agoIt doesn't make your password for any particular site any harder to guess. It does avoid reuse, without needing to sync or otherwise remember N distinct passwords, which is worthwhile. Reuse is the main reason why theft of password dbs (as distinct from just compromise of the site) is a problem for the user.