By Team EaSE on Saturday, 01 January 2011
Category: January

Team EaSE Article: Passwords - Don't walk in front of a Bus!

Team EaSE discuss passwords in general and stress how important password construction and safety are to the overall security of your website and backups.

Team EaSE Podcast - Hils & Bo discuss passwords and their importance

{mp3}jan2011/passwords{/mp3}

Some warnings - buses that we have inadvertently stood in front of!

Creating a strong password

Common guidelines for choosing good passwords are designed to make passwords less easily discovered by intelligent guessing:

[Extract from: http://en.wikipedia.org/wiki/Password_strength ]

Guessing & Sarah Palin

Passwords can sometimes be guessed by humans with knowledge of the user's personal information. Examples of guessable passwords include:

Personal data about individuals are now available from various sources, many on-line. Attackers who know the user may have information as well. For example, if a user chooses the password "YaleLaw78" because he graduated from Yale Law School in 1978, a disgruntled business partner might be able to guess the password.

Guessing is particularly effective with systems that employ self-service password reset. For example, in September 2008, the Yahoo e-mail account of Governor of Alaskaand Vice President of the United States nominee Sarah Palin was accessed without authorisation by someone who was able to research answers to two of her security questions, her zip code and date of birth and was able to guess the third, where she met her husband.

[Extract from: http://en.wikipedia.org/wiki/Password_cracking ]

In short...

Leave Comments