Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
PwdRsch
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
PwdRsch
10y ago
Yep, unfortunately for passphrases the maximum acceptable password length on web sites tends to be the #1 factor limiting their use. I created sample passphrases and tried them on a handful of different sites to measure the problem. See st
2.
▲
by
PwdRsch
10y ago
Here you go: https://security.stackexchange.com/questions/62832/is-the-of...
3.
▲
by
PwdRsch
10y ago
They do try changing the capitalization of only the first character, but also invert the capitalization of all the characters in the supplied password. http://www.zdnet.com/article/facebook-passwords-are-not-case...
4.
▲
by
PwdRsch
10y ago
Some of the latest research on this technique: Fast, Lean, and Accurate: Modeling Password Guessability Using Neural Networks https://www.ece.cmu.edu/~lbauer/papers/2016/usenixsec2016-ne...
5.
▲
by
PwdRsch
10y ago
Yes. They didn't need to know his strong password to log on, they just needed access to his mobile phone SMS in order to complete the account recovery process and change his account password to a value they chose.
6.
▲
by
PwdRsch
12y ago
It is complete idiocy to use passwords across services. Utter insanity. It is the worst possible practice imaginable, and is never, ever excusable. It's one thing to argue for improving people's password practices, but please d
7.
▲
by
PwdRsch
13y ago
Here's what it says in the "How I became a password cracker" article ( http://arstechnica.com/security/2013/03/how-i-became-a-passw... ) on Ars from March: "Dan suggested that, in the interest of helping me get up to speed with password cra
8.
▲
by
PwdRsch
13y ago
Telling people to use passphrases is a great recommendation, but you still have to spend some time teaching them how to use passphrases effectively. In the article they list several passphrases that were cracked, such as "sleepingwithsiren
9.
▲
by
PwdRsch
13y ago
There actually has been research on how to split passwords across multiple servers (one example http://www.passwordresearch.com/papers/paper270.html ), and RSA is currently marketing a commercial product that does this. While I agree that
10.
▲
by
PwdRsch
13y ago
I used to do this same thing and never heard about pen testing firms being sued by their client. Most likely he was spinning a yarn. It is more likely that a security consulting firm will be sued if they report no issues and the bank is la
11.
▲
by
PwdRsch
14y ago
AJ Jacobs at Esquire magazine wrote about his experience doing something similar back in December: http://www.esquire.com/features/overly-documented-life-0113
12.
▲
by
PwdRsch
14y ago
That's simply not true. Rainbow tables are still the first choice of many people trying to crack passwords, with brute force or hybrid attacks as a follow up after the common passwords have been found. It doesn't hurt that there are a lot