<?xml-stylesheet type="text/xsl" href="https://community.element14.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Why passwords are important...</title><link>/members-area/personalblogs/b/clem-martins-s-blog/posts/why-passwords-are-important</link><description>I know a lot of you are thinking, why bother about passwords? Well let me clue you in. Many passwords we use are very weak. Let me list a few and show how long it would take to break with modern computers. password ...</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Why passwords are important...</title><link>https://community.element14.com/members-area/personalblogs/b/clem-martins-s-blog/posts/why-passwords-are-important</link><pubDate>Thu, 24 Oct 2019 17:19:48 GMT</pubDate><guid isPermaLink="false">93d5dcb4-84c2-446f-b2cb-99731719e767:a77f6fa2-95f4-4284-8c87-34dd3de3f24e</guid><dc:creator>BigG</dc:creator><slash:comments>2</slash:comments><description>&lt;p&gt;I just so happened to request a new password on Microchip.com. My password choice failed.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Talk about a bad password rule. Has to be one of the weakest security rule I&amp;#39;ve seen in a very long time... someone to speak to them... &lt;span&gt;[View:/resized-image/__size/16x16/__key/commentfiles/f7d226abd59f475c9d224a79e3f0ec07-a77f6fa2-95f4-4284-8c87-34dd3de3f24e/contentimage_5F00_4751.png:16:16]&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span&gt;[View:/resized-image/__size/458x136/__key/commentfiles/f7d226abd59f475c9d224a79e3f0ec07-a77f6fa2-95f4-4284-8c87-34dd3de3f24e/contentimage_5F00_204760.png:458:136]&lt;/span&gt;&lt;/p&gt;&lt;img src="https://community.element14.com/aggbug?PostID=7901&amp;AppID=318&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</description></item><item><title>RE: Why passwords are important...</title><link>https://community.element14.com/members-area/personalblogs/b/clem-martins-s-blog/posts/why-passwords-are-important</link><pubDate>Fri, 11 Oct 2019 18:16:35 GMT</pubDate><guid isPermaLink="false">93d5dcb4-84c2-446f-b2cb-99731719e767:a77f6fa2-95f4-4284-8c87-34dd3de3f24e</guid><dc:creator>clem57</dc:creator><slash:comments>1</slash:comments><description>&lt;p&gt;I wish to propose the following:&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt; Traditionally, authentication procedures are divided into two stages: identification and secret password. Note identification with longer strings helps make the password space large...&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;To date, research on password security and the usability of these mechanisms has rarely been investigated. But more has been done since news of hacker attempts hits the public raising awareness.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Since security mechanisms are designed, implemented, applied and breached by people, human factors should be considered in their design. Too often we neglect this using simple techniques.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;It seems that currently, hackers pay more attention to the human link in the security chain than security designers do, by using social engineering techniques to obtain passwords. This means Facebook, twitter and other places can help a hacker get into the mind of the user...&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;The key element in password security is the crackablity of a password combination. But often the length of the password is too little.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;System-generated passwords are essentially the optimal security approach; user-generated passwords are potentially more memorable and thus less likely to be disclosed. &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Password composition, alphanumeric password is more secure than one composed of letters alone. But the use of all elements like symbols and caps is better.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;img src="https://community.element14.com/aggbug?PostID=7901&amp;AppID=318&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</description></item><item><title>RE: Why passwords are important...</title><link>https://community.element14.com/members-area/personalblogs/b/clem-martins-s-blog/posts/why-passwords-are-important</link><pubDate>Sat, 05 Oct 2019 02:08:18 GMT</pubDate><guid isPermaLink="false">93d5dcb4-84c2-446f-b2cb-99731719e767:a77f6fa2-95f4-4284-8c87-34dd3de3f24e</guid><dc:creator>Gough Lui</dc:creator><slash:comments>1</slash:comments><description>&lt;p&gt;Users need complex passwords - we know that much. Users need to avoid reuse as well - in case any password is compromised.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;But on the server side, administrators need to do their part as well. For one, there are still probably some sites with plain-text password storage ... when the best practice is to salt and hash the password, with the choice of salt and hash having a significant impact on offline cracking time (and resources necessary to validate the password). Sometimes users are asked to change their passwords not because the password itself is vulnerable, but perhaps it was salted and hashed with an algorithm which has become &amp;quot;weak&amp;quot; in the face of increased computing power and discovered vulnerabilities, whereas re-setting it will allow for a new salt-hash record using the latest settings to be made.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;But as usual, security is only as good as the weakest point ...&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;- Gough&lt;/p&gt;&lt;img src="https://community.element14.com/aggbug?PostID=7901&amp;AppID=318&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</description></item><item><title>RE: Why passwords are important...</title><link>https://community.element14.com/members-area/personalblogs/b/clem-martins-s-blog/posts/why-passwords-are-important</link><pubDate>Fri, 04 Oct 2019 16:15:02 GMT</pubDate><guid isPermaLink="false">93d5dcb4-84c2-446f-b2cb-99731719e767:a77f6fa2-95f4-4284-8c87-34dd3de3f24e</guid><dc:creator>dougw</dc:creator><slash:comments>1</slash:comments><description>&lt;p&gt;It is all very confusing to me.&lt;/p&gt;&lt;p&gt;I assume the quoted time is related to the maximum number of possible different passwords or the maximum number of tries it would take to ensure the password was tried, but presumably it could get it right on the first try. In practice, it will never take the maximum possible time to guess a password.&lt;/p&gt;&lt;p&gt;Also every password system has a minimum time allowed between tries, even if it is just communications bandwidth, which would make fast computers irrelevant in computing more possible passwords. And some systems increase the time after every try or every few tries, sometimes the minimum time gets to be a very long period. Sometimes it goes to infinity.&lt;/p&gt;&lt;p&gt;These extending times are often used when the password is a 4 digit pin.&lt;/p&gt;&lt;p&gt;Without knowing the timing of allowed tries, computing a time to crack a password seems a bit arbitrary.&lt;/p&gt;&lt;img src="https://community.element14.com/aggbug?PostID=7901&amp;AppID=318&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</description></item><item><title>RE: Why passwords are important...</title><link>https://community.element14.com/members-area/personalblogs/b/clem-martins-s-blog/posts/why-passwords-are-important</link><pubDate>Fri, 04 Oct 2019 15:58:39 GMT</pubDate><guid isPermaLink="false">93d5dcb4-84c2-446f-b2cb-99731719e767:a77f6fa2-95f4-4284-8c87-34dd3de3f24e</guid><dc:creator>glennvanderveer</dc:creator><slash:comments>1</slash:comments><description>&lt;p&gt;At some point, that password has to be entered in by typing it, whether or not autotype is used.&amp;nbsp; And it is all for nothing if you have to type in the password to open your keepass database either upon creation or upon use.&lt;/p&gt;&lt;img src="https://community.element14.com/aggbug?PostID=7901&amp;AppID=318&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</description></item><item><title>RE: Why passwords are important...</title><link>https://community.element14.com/members-area/personalblogs/b/clem-martins-s-blog/posts/why-passwords-are-important</link><pubDate>Fri, 04 Oct 2019 15:40:55 GMT</pubDate><guid isPermaLink="false">93d5dcb4-84c2-446f-b2cb-99731719e767:a77f6fa2-95f4-4284-8c87-34dd3de3f24e</guid><dc:creator>glennvanderveer</dc:creator><slash:comments>1</slash:comments><description>&lt;p&gt;Although the article does not say how the first break in happened, it could have been as simple as a visualbasic script that installed a key logger.&amp;nbsp; It doesn&amp;#39;t matter what password rules you follow, key loggers record everything.&amp;nbsp; At the time of the article, VB scripts where a plague on Microsoft Windows and Office platforms.&lt;/p&gt;&lt;img src="https://community.element14.com/aggbug?PostID=7901&amp;AppID=318&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</description></item><item><title>RE: Why passwords are important...</title><link>https://community.element14.com/members-area/personalblogs/b/clem-martins-s-blog/posts/why-passwords-are-important</link><pubDate>Fri, 04 Oct 2019 14:28:37 GMT</pubDate><guid isPermaLink="false">93d5dcb4-84c2-446f-b2cb-99731719e767:a77f6fa2-95f4-4284-8c87-34dd3de3f24e</guid><dc:creator>clem57</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;If you think about it, getting into systems by even youth happens. So why make the password too easy? I have the following example:&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;a class="jive-link-external-small" href="https://www.nytimes.com/2000/09/23/us/youth-sentenced-in-government-hacking-case.html" rel="nofollow ugc noopener" target="_blank" title="https://www.nytimes.com/2000/09/23/us/youth-sentenced-in-government-hacking-case.html"&gt;https://www.nytimes.com/2000/09/23/us/youth-sentenced-in-government-hacking-case.html&lt;/a&gt; &lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Enjoy the read and then ask why did they get in so easily, could it have been lax password withing the affected organisations?&lt;/p&gt;&lt;p&gt;Clem&lt;/p&gt;&lt;img src="https://community.element14.com/aggbug?PostID=7901&amp;AppID=318&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</description></item><item><title>RE: Why passwords are important...</title><link>https://community.element14.com/members-area/personalblogs/b/clem-martins-s-blog/posts/why-passwords-are-important</link><pubDate>Fri, 04 Oct 2019 13:32:04 GMT</pubDate><guid isPermaLink="false">93d5dcb4-84c2-446f-b2cb-99731719e767:a77f6fa2-95f4-4284-8c87-34dd3de3f24e</guid><dc:creator>gadget.iom</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Here are results for the passwords I use for two of my more secure services. Both I know and type from memory. &lt;/p&gt;&lt;p&gt;&lt;span&gt;[View:/resized-image/__size/620x195/__key/commentfiles/f7d226abd59f475c9d224a79e3f0ec07-a77f6fa2-95f4-4284-8c87-34dd3de3f24e/4682.contentimage_5F00_204758.png:620:195]&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;[View:/resized-image/__size/620x187/__key/commentfiles/f7d226abd59f475c9d224a79e3f0ec07-a77f6fa2-95f4-4284-8c87-34dd3de3f24e/3286.contentimage_5F00_204759.png:620:187]&lt;/span&gt;&lt;/p&gt;&lt;img src="https://community.element14.com/aggbug?PostID=7901&amp;AppID=318&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</description></item><item><title>RE: Why passwords are important...</title><link>https://community.element14.com/members-area/personalblogs/b/clem-martins-s-blog/posts/why-passwords-are-important</link><pubDate>Fri, 04 Oct 2019 08:33:10 GMT</pubDate><guid isPermaLink="false">93d5dcb4-84c2-446f-b2cb-99731719e767:a77f6fa2-95f4-4284-8c87-34dd3de3f24e</guid><dc:creator>koudelad</dc:creator><slash:comments>2</slash:comments><description>&lt;p&gt;My recommendation is using certificates wherever possible: SSH, remote desktops, etc. &lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;If I can&amp;#39;t use a certificate, I use a strong generated password and store it locally in something like &lt;a class="jive-link-external-small" href="https://keepass.info/" rel="nofollow ugc noopener" target="_blank"&gt;KeePass&lt;/a&gt;. I wouldn&amp;#39;t trust cloud password managers, there have been security breaches.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Use two factor authentication for all publicly available services. Nice and open-source application for mobile phones is &lt;a class="jive-link-external-small" href="https://freeotp.github.io/" rel="nofollow ugc noopener" target="_blank"&gt;FreeOTP&lt;/a&gt;. Or hardware modules like &lt;a class="jive-link-external-small" href="https://www.yubico.com/" rel="nofollow ugc noopener" target="_blank"&gt;Yubikey&lt;/a&gt;, which &lt;span&gt;[mention:aa6deffed12746e1bb75f89ce3d88178:e9ed411860ed4f2ba0265705b8793d05]&lt;/span&gt; mentioned.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Encrypt data storage on computers and mobile phone. Not for an illusion of being unbreakable for secret services, but for common situations when device gets lost or stolen by a random guy.&lt;/p&gt;&lt;img src="https://community.element14.com/aggbug?PostID=7901&amp;AppID=318&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</description></item><item><title>RE: Why passwords are important...</title><link>https://community.element14.com/members-area/personalblogs/b/clem-martins-s-blog/posts/why-passwords-are-important</link><pubDate>Thu, 03 Oct 2019 20:10:08 GMT</pubDate><guid isPermaLink="false">93d5dcb4-84c2-446f-b2cb-99731719e767:a77f6fa2-95f4-4284-8c87-34dd3de3f24e</guid><dc:creator>glennvanderveer</dc:creator><slash:comments>1</slash:comments><description>&lt;p&gt;I would also argue that for brute force password cracking, the length of time that a password is valid should also be a factor.&amp;nbsp; If it takes 3 months to brute force guess a password, but the password life is only 1 month, then that password is secure enough to use.&lt;/p&gt;&lt;img src="https://community.element14.com/aggbug?PostID=7901&amp;AppID=318&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</description></item><item><title>RE: Why passwords are important...</title><link>https://community.element14.com/members-area/personalblogs/b/clem-martins-s-blog/posts/why-passwords-are-important</link><pubDate>Thu, 03 Oct 2019 19:24:25 GMT</pubDate><guid isPermaLink="false">93d5dcb4-84c2-446f-b2cb-99731719e767:a77f6fa2-95f4-4284-8c87-34dd3de3f24e</guid><dc:creator>Jan Cumps</dc:creator><slash:comments>1</slash:comments><description>&lt;p&gt;For an alternative opinion, search this term online: “do strong passwords accomplish anything”&lt;/p&gt;&lt;img src="https://community.element14.com/aggbug?PostID=7901&amp;AppID=318&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</description></item><item><title>RE: Why passwords are important...</title><link>https://community.element14.com/members-area/personalblogs/b/clem-martins-s-blog/posts/why-passwords-are-important</link><pubDate>Thu, 03 Oct 2019 19:07:45 GMT</pubDate><guid isPermaLink="false">93d5dcb4-84c2-446f-b2cb-99731719e767:a77f6fa2-95f4-4284-8c87-34dd3de3f24e</guid><dc:creator>mudz</dc:creator><slash:comments>1</slash:comments><description>&lt;p&gt;Well you guys want to end this or not? &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span&gt;[View:/resized-image/__size/16x16/__key/commentfiles/f7d226abd59f475c9d224a79e3f0ec07-a77f6fa2-95f4-4284-8c87-34dd3de3f24e/contentimage_5F00_938.png:16:16]&lt;/span&gt;&lt;span&gt;[View:/resized-image/__size/719x222/__key/commentfiles/f7d226abd59f475c9d224a79e3f0ec07-a77f6fa2-95f4-4284-8c87-34dd3de3f24e/contentimage_5F00_204757.png:719:222]&lt;/span&gt;&lt;/p&gt;&lt;img src="https://community.element14.com/aggbug?PostID=7901&amp;AppID=318&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</description></item><item><title>RE: Why passwords are important...</title><link>https://community.element14.com/members-area/personalblogs/b/clem-martins-s-blog/posts/why-passwords-are-important</link><pubDate>Thu, 03 Oct 2019 19:00:01 GMT</pubDate><guid isPermaLink="false">93d5dcb4-84c2-446f-b2cb-99731719e767:a77f6fa2-95f4-4284-8c87-34dd3de3f24e</guid><dc:creator>three-phase</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;My first one is the format I use for my works computer;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span&gt;[View:/resized-image/__size/620x353/__key/commentfiles/f7d226abd59f475c9d224a79e3f0ec07-a77f6fa2-95f4-4284-8c87-34dd3de3f24e/2047.contentimage_5F00_204755.png:620:353]&lt;/span&gt;&lt;/p&gt;&lt;p&gt;Second one is the format I use on my personal USB drives;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span&gt;[View:/resized-image/__size/620x346/__key/commentfiles/f7d226abd59f475c9d224a79e3f0ec07-a77f6fa2-95f4-4284-8c87-34dd3de3f24e/0804.contentimage_5F00_204756.png:620:346]&lt;/span&gt;&lt;/p&gt;&lt;img src="https://community.element14.com/aggbug?PostID=7901&amp;AppID=318&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</description></item><item><title>RE: Why passwords are important...</title><link>https://community.element14.com/members-area/personalblogs/b/clem-martins-s-blog/posts/why-passwords-are-important</link><pubDate>Thu, 03 Oct 2019 18:22:03 GMT</pubDate><guid isPermaLink="false">93d5dcb4-84c2-446f-b2cb-99731719e767:a77f6fa2-95f4-4284-8c87-34dd3de3f24e</guid><dc:creator>e14 Contributor</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;&lt;span&gt;[View:/resized-image/__size/778x229/__key/commentfiles/f7d226abd59f475c9d224a79e3f0ec07-a77f6fa2-95f4-4284-8c87-34dd3de3f24e/contentimage_5F00_204754.png:778:229]&lt;/span&gt;&lt;/p&gt;&lt;p&gt;I confess that the word parts were not in English!&lt;/p&gt;&lt;img src="https://community.element14.com/aggbug?PostID=7901&amp;AppID=318&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</description></item><item><title>RE: Why passwords are important...</title><link>https://community.element14.com/members-area/personalblogs/b/clem-martins-s-blog/posts/why-passwords-are-important</link><pubDate>Thu, 03 Oct 2019 15:14:02 GMT</pubDate><guid isPermaLink="false">93d5dcb4-84c2-446f-b2cb-99731719e767:a77f6fa2-95f4-4284-8c87-34dd3de3f24e</guid><dc:creator>neilk</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Pleased to say that the password I use to access my password manager would take a computer 23 years to crack &lt;span&gt;[View:/resized-image/__size/16x16/__key/commentfiles/f7d226abd59f475c9d224a79e3f0ec07-a77f6fa2-95f4-4284-8c87-34dd3de3f24e/7737.contentimage_5F00_1.png:16:16]&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Neil&lt;/p&gt;&lt;img src="https://community.element14.com/aggbug?PostID=7901&amp;AppID=318&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</description></item></channel></rss>