Author Topic: How Complex Does Your Password Have To Be?  (Read 6937 times)

Offline Zalc

  • Dansdeals Lifetime Platinum Elite
  • *******
  • Join Date: Nov 2014
  • Posts: 1804
  • Total likes: 158
  • DansDeals.com Hat Tips 0
    • View Profile
  • Location: USA
Re: How Complex Does Your Password Have To Be?
« Reply #40 on: October 26, 2017, 09:19:39 PM »
I used to use it
Also:
 https://lastpass.com/support.php?cmd=showfaq&id=6036
How many times should I try it?  :)
It depends, tapatalk might glitch and do it 4 times!

Offline skyguy918

  • Dansdeals Presidential Platinum Elite
  • ********
  • Join Date: Mar 2011
  • Posts: 4077
  • Total likes: 835
  • DansDeals.com Hat Tips 1
  • Gender: Male
    • View Profile
  • Location: Queens, NY
Re: How Complex Does Your Password Have To Be?
« Reply #41 on: October 26, 2017, 10:05:25 PM »
This one is pretty simple to crack: 3Nz@g0DILJuPY!cFYXeSs6EJ
Fantastic. Now explain how you remember it.

Offline yesitsme

  • Dansdeals Lifetime Presidential Platinum Elite
  • *********
  • Join Date: Dec 2014
  • Posts: 5116
  • Total likes: 2238
  • DansDeals.com Hat Tips 4
  • Gender: Male
    • View Profile
Re: How Complex Does Your Password Have To Be?
« Reply #42 on: October 26, 2017, 10:34:10 PM »
It's not just about length of the password but also what the makeup of the password is, nobody really sits there and tries to brute force passwords anymore, they use databases of already cracked passwords and run those through instead. The idea of using Hebrew or Yiddish phrases is actually a really good idea (because they most likely aren't in the data bases being used) as is lastpass. This is a great video if you want to know more about how passwords are actually cracked. [ Invalid YouTube link ]
Bcrypt is the hashing algorithm to use, every time you encrypt something it generates a different fixed length string ie $2y$12$QjSH496pcT5CEbzjD/vtVeH03tfHKFy36d4J0Ltp3lRtee9HDxY3K

Anthony Ferrara slideshow
https://www.slideshare.net/ircmaxell/password-storage-and-attacking-in-php
happens to be I love reading every post of his
https://blog.ircmaxell.com/
https://www.slideshare.net/ircmaxell
https://blog.ircmaxell.com/2012/12/seven-ways-to-screw-up-bcrypt.html

Anthony developed the php bcrypt compatibility library and he suggests that all[Most] these paswords mentioned over here are wrong


["-"]

Offline skyguy918

  • Dansdeals Presidential Platinum Elite
  • ********
  • Join Date: Mar 2011
  • Posts: 4077
  • Total likes: 835
  • DansDeals.com Hat Tips 1
  • Gender: Male
    • View Profile
  • Location: Queens, NY
Re: How Complex Does Your Password Have To Be?
« Reply #43 on: October 26, 2017, 10:35:51 PM »
Bcrypt is the hashing algorithm to use, every time you encrypt something it generates a different fixed length string ie $2y$12$QjSH496pcT5CEbzjD/vtVeH03tfHKFy36d4J0Ltp3lRtee9HDxY3K

Anthony Ferrara slideshow
https://www.slideshare.net/ircmaxell/password-storage-and-attacking-in-php
happens to be I love reading every post of his
https://blog.ircmaxell.com/
https://www.slideshare.net/ircmaxell
https://blog.ircmaxell.com/2012/12/seven-ways-to-screw-up-bcrypt.html

Anthony developed the php bcrypt compatibility library and he suggests that all[Most] these paswords mentioned over here are wrong



I'll ask the same question. What about the password for the password manager?

Offline yesitsme

  • Dansdeals Lifetime Presidential Platinum Elite
  • *********
  • Join Date: Dec 2014
  • Posts: 5116
  • Total likes: 2238
  • DansDeals.com Hat Tips 4
  • Gender: Male
    • View Profile
Re: How Complex Does Your Password Have To Be?
« Reply #44 on: October 26, 2017, 10:52:19 PM »
I'll ask the same question. What about the password for the password manager?
enable Multifactor Authentication.
["-"]

Offline good sam

  • Dansdeals Presidential Platinum Elite
  • ********
  • Join Date: Jun 2011
  • Posts: 3524
  • Total likes: 558
  • DansDeals.com Hat Tips 10
    • View Profile
Re: How Complex Does Your Password Have To Be?
« Reply #45 on: October 27, 2017, 12:22:21 AM »
https://www.technologyreview.com/s/542576/youve-been-misled-about-what-makes-a-good-password/

According to this, my above explanation is outdated.  Never-the-less, they don't recommend short.
The hacker in Mr. Robot feeds relevant info into his software to crack passwords. Birthday, anniversary, children's names, dogs' names etc. If accurate, I see why short and long wouldn't make a difference.
If you don't care why would you comment?
HT: DMYD

Offline skyguy918

  • Dansdeals Presidential Platinum Elite
  • ********
  • Join Date: Mar 2011
  • Posts: 4077
  • Total likes: 835
  • DansDeals.com Hat Tips 1
  • Gender: Male
    • View Profile
  • Location: Queens, NY
Re: How Complex Does Your Password Have To Be?
« Reply #46 on: October 27, 2017, 02:08:37 AM »
The hacker in Mr. Robot feeds relevant info into his software to crack passwords. Birthday, anniversary, children's names, dogs' names etc. If accurate, I see why short and long wouldn't make a difference.
That's only matters if your password contains those things. Take out that factor and length makes a big difference.

Offline Yammer

  • Dansdeals Presidential Platinum Elite
  • ********
  • Join Date: Aug 2015
  • Posts: 3727
  • Total likes: 217
  • DansDeals.com Hat Tips 1
    • View Profile
Re: How Complex Does Your Password Have To Be?
« Reply #47 on: October 27, 2017, 02:59:26 AM »
I'll ask the same question. What about the password for the password manager?
I use Google passwords and have 2 step verification on the account.

Offline Boruch999

  • Dansdeals Lifetime Platinum Elite
  • *******
  • Join Date: Jun 2014
  • Posts: 2164
  • Total likes: 186
  • DansDeals.com Hat Tips 0
    • View Profile
Re: How Complex Does Your Password Have To Be?
« Reply #48 on: October 27, 2017, 06:36:40 AM »
I'll ask the same question. What about the password for the password manager?

Make one random (or yiddish based or the like) long password for the manager and remember it.  For the rest make individual random long passwords (my manager will generate.)

Offline yitrap

  • Dansdeals Presidential Platinum Elite
  • ********
  • Join Date: Apr 2014
  • Posts: 3315
  • Total likes: 56
  • DansDeals.com Hat Tips 1
  • Gender: Male
    • View Profile
Re: How Complex Does Your Password Have To Be?
« Reply #49 on: October 27, 2017, 07:31:17 AM »
All of you discussing how you formulate your passwords are obviously reusing the same passwords on multiple websites, (unless you claim to remember 100+ passwords.)
This is the WORST idea you can have.
You can create a formula that changes for each website but the logic remains making it easy to remember.

Offline 1234567

  • Dansdeals Bronze Elite
  • *
  • Join Date: Jul 2012
  • Posts: 34
  • Total likes: 7
  • DansDeals.com Hat Tips 1
    • View Profile
Re: How Complex Does Your Password Have To Be?
« Reply #50 on: October 27, 2017, 09:34:01 AM »
Bcrypt is the hashing algorithm to use, every time you encrypt something it generates a different fixed length string ie $2y$12$QjSH496pcT5CEbzjD/vtVeH03tfHKFy36d4J0Ltp3lRtee9HDxY3K

Anthony Ferrara slideshow
https://www.slideshare.net/ircmaxell/password-storage-and-attacking-in-php
happens to be I love reading every post of his
https://blog.ircmaxell.com/
https://www.slideshare.net/ircmaxell
https://blog.ircmaxell.com/2012/12/seven-ways-to-screw-up-bcrypt.html

Anthony developed the php bcrypt compatibility library and he suggests that all[Most] these paswords mentioned over here are wrong




https://security.stackexchange.com/questions/62832/is-the-oft-cited-xkcd-scheme-no-longer-good-advice

Offline ChaimMoskowitz

  • Dansdeals Lifetime Presidential Platinum Elite
  • *********
  • Join Date: Jun 2014
  • Posts: 7232
  • Total likes: 1097
  • DansDeals.com Hat Tips 1
  • Gender: Female
    • View Profile
Re: How Complex Does Your Password Have To Be?
« Reply #51 on: October 27, 2017, 10:04:18 AM »
Fantastic. Now explain how you remember it.
I change it once a year and just memorize it. Parts of it do mean something.
I just found a new supply of forks!

Offline aradisc

  • Dansdeals Platinum Elite
  • ****
  • Join Date: Jan 2014
  • Posts: 286
  • Total likes: 18
  • DansDeals.com Hat Tips 0
    • View Profile
Re: How Complex Does Your Password Have To Be?
« Reply #52 on: October 27, 2017, 11:12:44 AM »
Everyone here can guess my Yiddish phrases, so I have to switch to Ladino or Judeo-Arabic instead.  ;D

Actually I just signed up for LastPass families ($48 year, vs $24 for individual) and am gifting it to some relatives who I know aren't using strong passwords. It may not sound like much of a gift, but if it stops a single instance of identity theft... The sharing and contingency features of families are good too for emergencies https://helpdesk.lastpass.com/emergency-access/

Offline JoeyShmoe

  • Dansdeals Lifetime Platinum Elite
  • *******
  • Join Date: Nov 2014
  • Posts: 1286
  • Total likes: 254
  • DansDeals.com Hat Tips 0
  • Gender: Male
    • View Profile
  • Location: Lakewood
Re: How Complex Does Your Password Have To Be?
« Reply #53 on: October 27, 2017, 12:40:22 PM »
Everyone here can guess my Yiddish phrases, so I have to switch to Ladino or Judeo-Arabic instead.  ;D

Actually I just signed up for LastPass families ($48 year, vs $24 for individual) and am gifting it to some relatives who I know aren't using strong passwords. It may not sound like much of a gift, but if it stops a single instance of identity theft... The sharing and contingency features of families are good too for emergencies https://helpdesk.lastpass.com/emergency-access/
With families you can give someone access without them getting your passwords?
DDF A-Z Link Extension
Chrome
Firefox
Info

Offline skyguy918

  • Dansdeals Presidential Platinum Elite
  • ********
  • Join Date: Mar 2011
  • Posts: 4077
  • Total likes: 835
  • DansDeals.com Hat Tips 1
  • Gender: Male
    • View Profile
  • Location: Queens, NY
Re: How Complex Does Your Password Have To Be?
« Reply #54 on: October 27, 2017, 01:00:36 PM »
Make one random (or yiddish based or the like) long password for the manager and remember it.  For the rest make individual random long passwords (my manager will generate.)
And now you've arrived at my position from the start.

Offline Zalc

  • Dansdeals Lifetime Platinum Elite
  • *******
  • Join Date: Nov 2014
  • Posts: 1804
  • Total likes: 158
  • DansDeals.com Hat Tips 0
    • View Profile
  • Location: USA
Re: How Complex Does Your Password Have To Be?
« Reply #55 on: October 27, 2017, 01:42:01 PM »
Everyone here can guess my Yiddish phrases, so I have to switch to Ladino or Judeo-Arabic instead.  ;D

Actually I just signed up for LastPass families ($48 year, vs $24 for individual) and am gifting it to some relatives who I know aren't using strong passwords. It may not sound like much of a gift, but if it stops a single instance of identity theft... The sharing and contingency features of families are good too for emergencies https://helpdesk.lastpass.com/emergency-access/
Can't you have them sign up for their own free lastpass?

Edit:
The free version has some pretty good contingencies as well:

One time passwords, recovery emails etc.