|
|
View previous topic - View next topic |
Author |
Message |
Unknown Moira's Silly Little Slave Bitch
Joined: 19 Jul 2005 Posts: 82 Location: Behind you...
|
Posted: Sun Oct 08, 2006 10:22 pm Post subject: Password Creation Algorithm... |
[quote] |
|
Here's my piece of mind when it comes to passwords!
Passwords, we use these little suckers every day; from accessing E-Mail to logging onto computers. The “Professionals” tell us that “for securities sake” we must use a different password for everything! OUCH!!! If I used a different password for everything I accessed I would end up trying to remember anywhere from 10-45 passwords. The only people I know that can remember that many passwords are either geniuses or they use the same password for everything. There has to be a better way for us normal people to remember/use different passwords. There are a couple of different approaches people take when it comes to remembering passwords; software, writing, memorization or my way.
Some really lazy people who keep the keys to their kingdom all in one place use a software managing utility like “password agent” from http://www.moonsoftware.com. This is an extremely insecure method to use. For example, all an attacker has to crack is one password and they are given all of them. This method of storing passwords is just as useless as using the same password for everything. Those who are more “organized” write down all their passwords (not as bad as using the same one for everything). Unless, of course, you’re smart enough to hide that little slip of paper you wrote down your office’s computer password on in that really sneaky place; under your keyboard! Super Geniuses don’t have to bother with writing their passwords down, using a utility or using the same one. They just memorize all of them nice and quick. But, since we are talking about normal people here who have better things to do with their lives than memorize fifty plus passwords, let’s move on. My way of password generation is simple, quick and nigh impossible to crack. Well. as long as you don’t talk about it in your sleep.
In Algebra, mathematicians use functions for a lot junk. Basically, all functions do is take an expression in and return something that is changed along a set method. Now back to the world of passwords and normal people. We can do the same thing with our passwords. If we apply the genius of mathematics to English all we have to remember is a base password. This base password is never used anywhere ever. You memorize your base password (which in our example will be “passwordstink”), basing all your other passwords off the base. Example: Let’s take your base password “passwordstink” (without the quotes of course)and choose a password for your GMail account. All you have to do is change your base “passwordstink” according to your formula. In this example we will use the first two last two formula. So, your password “passwordstink” would be transmogrified into “GMpasswordstinkil” add you mom’s birthday “09GMpasswordstinkil43” and you’ve got one heck of a strong password. Here is another example: say you work at Wal-Mart and you need to create a password for your register. Take your base password “passwordstink” use your formula, add some meaningful numbers and boom there’s an unforgettable password that you can forget anytime you want. Say we used the same formula as the first example, your register password would be “09Wapasswordstinkrt43”. WOW!!! A normal person just created a password that is nigh un-crack-able and takes less than 10 seconds to remember. Goodbye Software, Geniuses, writing and crackers.
So, are you a lazy password creator, a genius or have you been converted ^_* _________________ Most people would succeed in small things if they were not troubled with such great ambitions.
|
|
Back to top |
|
|
RedSlash Mage
Joined: 12 May 2005 Posts: 331
|
Posted: Wed Oct 11, 2006 12:09 am Post subject: |
[quote] |
|
That is interesting. I'm not sure if the method described above is much more secure than the 1 password method (maybe because the example given seems a bit weak). I mean, basically, your base password+mom's b-day is like 1 password on its own. If an attacker were able to obtain this, then all the attacker has left to solve, is appending and prepending the two letters from the site name, which shouldn't be hard to guess.
But I guess the idea here is not let people know what technique you are using to compose the password. But for all practical purposes, I think this is quite a good technique on generating stronger passwords than just using the same password over and over.
|
|
Back to top |
|
|
Unknown Moira's Silly Little Slave Bitch
Joined: 19 Jul 2005 Posts: 82 Location: Behind you...
|
Posted: Wed Oct 11, 2006 3:14 pm Post subject: |
[quote] |
|
Quote: |
I mean, basically, your base password+mom's b-day is like 1 password on its own. |
Exactly!!! That is why you have your formula that you change/add to your base by.
Quote: |
say you work at Wal-Mart and you need to create a password for your register. Take your base password “passwordstink” use your formula, add some meaningful numbers and boom there’s an unforgettable password that you can forget anytime you want. Say we used the same formula as the first example, your register password would be “09Wapasswordstinkrt43”. WOW!!! |
Let's say you don't like the formula first two last two so instead you use one that inserts the first two last two like this:
you base password is "passwordstink" and you are creating a password for an ebay account... So your base password would be changed from "passwordstink" to "ebsswordstiay" then you add your own numbers that you can easily remember say your B-day, and the password changes to "09ebsswordstiay94". So, really the attacker has to know four things, the fact that you use this method, your formula, your base password and the numbers that you choose to use that you can easily remember.
was that a "better" example or did it just confuse the subject even more.... ^_^ _________________ Most people would succeed in small things if they were not troubled with such great ambitions.
|
|
Back to top |
|
|
|
Page 1 of 1 |
All times are GMT
|
|
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
|