This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Passwords

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Definatly doug! in fact, i usually incorporate a peramiter into this system that is site specific. An example would be for this site, having one of the parts as the letters, ie wwwWTT with the rest of the standard setup the same for everywhere non-sensitive. Obviously, wwwWTT is not what i use here ;)
I create passwords from sentences. And obviously something I can remember. For the most I am using the front letter of every word, as is. Sometimes I leave first letter alone and use the second letter instead caitalized and the words which would normally be capatilized, I have none. Words like and or plus, can be converted to their respective signs ( & / +)
Example:

#1: "Our new dog is a Shiba, and ten weeks old."

Would become;

OndiaS,&10two.

#2: "oUr nEw dOg iS a shiba, aNd tEn wEeks oLd."

would become;

UEOSah,NEEL. or UEOSah,&EEL.

On critical sites, I use words that have no connections to my enviroment, and only a good memory serves me here (Altho the written passwords are locked in my safe)
It seems that this topic is now an interesting place to discuss our ideas :)


Interesting methods you use, really strong to dictionary attacks. Plus, In order to protect yourself from brute force attacks these passwords must be as large as possible. Computers are made even more and more fast, with better specifications, and can resolve many operations in a few seconds. In addition, some crackers use botnets so that each computer makes just part of the job, wich makes possible to attack really large passwords.


What I do is to create very strong, but short paswords like
  • ÑL,lt4
  • ,lñgh¨P^654
  • jn2¿?/
Then I mix them and create a unique pasword strong enough, for example:


ÑL,lt4,lñgh¨P^654jn2¿?/sK¨`4)&lnC-_¨´hg*¨Ñ152%=LP´ñpǨ^o8yu4·QgtrNK/&ñ9u^)67235grvñ¨?)905TGbhÑ)(=HTR·$O(/LÑñ´ascf!"$!"·%*9/(/)*-g-.x`rVc.-


I use each space that the website provides. After that, I manage the paswords with an app like paswordsafe, wichs masterkey I save in my bedroom´s locker. As Doug said, you should use different pass for each site, and that´s very easy to do with these tipes of apps.
Hehe, well, you do need a password program to remember those :lol:

However, I do have one more edge. 80-90% of all password finders is written for english (or so) So using
the special letters in my own language (Which I always incorporate in some way) give me
stronger passwords that way around.

The special letters we have in danish is;

Æ Ø Å

So we have 28 29 letters in the alphabet instead of 25 26.

:P

26 :whistling:


Corrected…I know, what a glitch. It is just that I remember the numbers from a song in pre-school, and W
is left out, since we don't use it much in Denmark, except for Whisky :lol: (almost)

Guys, how can we know wich type of characters in a website, forum, etc, are able for passwords?


I don't have an answer for you on that.

There are several features that we don't allow ourselves to have.
One of them is ability to "see" login-passwords.
For all the obvious reasons.

Therefore, when you log in or create a new password, you only see a progression of dots to represent the hidden key that you selected. We don't see even that except for our own password which is also cloaked just like yours. We do have the ability to give you a "new password" that you can then use to login and change to the password of your preference.

The only way I can imagine to determine what letters, numerals, and special characters are accepted would be to "experiment" by selecting one and then seeing if the new password is accepted.

Still you would have no way of determining if the Board software translated "your" special character to some Board Recognized letter or numeral or other standard special character.
So, we just try. I remember a few years ago many boards just support the use of letters and numbers in your password (no special characters), it seems nowadays people and companies are more concerned about security, at least to allow you to use many tipe of characters. However there are some important brands that should be more concerned about this. For example, Windows live aka hotmail doesn´t allow paswords longer than 11 characters :pullhair:


I agree with your policy. I´m convinced that Administrators shouln´t be able to see user´s passwords, just have an option to change it.

Still you would have no way of determining if the Board software translated "your" special character to some Board Recognized letter or numeral or other standard special character.


Still, I dont think it would be a problem, because when you log in, the password you enter would be also translated and would be correct :scratch:


FYI

WTT allows a 50 characters large password, and supports many tipe of characters, including high ANSI characters, many types of brackets, special characters…
:P :thumbup:


Anyway, you mention the use of a progression of dots that represent the written key, wich is highly used nowadays. This "method" is used not only for people near you that may be looking to your screen, but for malware that can record what you are seeing on the screen and send the video to its creator. Am I right?
I would imagine that is part of the reason for the dots. I also noticed that some sites reduce the dots to 6 long, regardless of the length of the password, when remembering them. The password is still long, it just 'pretends' its 6 characters. ;) I personally dont use password managers for 1 simple reason. Things break! I also use several computers, where i need to login to sites to gleen information, so the password manager on the first computer is not much use to me! I know i know, brains die too… but once my brain dies,i'll have no need for long passwords anymore ;)
Change your password immediately.

Never give your password(s) to anyone, especially online.

No responsible Tech will "ever" ask you for your password(s).

Posting your password in a Forum is like giving it to the world, including bad-guys that scan forums.
_____________________

to start over, here's a brief on the nature of strong passwords and how you might create them for yourself.
http://forums.whatthetech.com/Use_Strong_P…rds_t98701.html