Subject: How to devise passwords that drive hackers away
  This thread has been closed by sexyloser at 18-5-2024 11:07. 
atomic3d
Throbbing Titan
Rank: 7Rank: 7Rank: 7


UID 41127
Digest Posts 0
Credits 3282
Posts 2642
Karma 3157
Acceptance 2501
Reading Access 70
Registered 10-3-2010
Status Offline
Post at 13-11-2012 08:33  Profile P.M. 
Font size: S M L
How to devise passwords that drive hackers away

November 12, 2012
You are not paranoid if you are worried about protecting your passwords.

Not long after I began writing about cybersecurity, I became a paranoid caricature of my former self. It's hard to maintain peace of mind when hackers remind me every day, all day, just how easy it is to steal my personal data.

Within weeks, I set up unique, complex passwords for every website, enabled two-step authentication for my email accounts, and even covered up my computer's Web camera with a piece of masking tape — a precaution that invited ridicule from friends and co-workers who suggested it was time to get my head checked.

But recent episodes offered vindication. I removed the webcam tape — after a friend convinced me that it was a little much — only to see its light turn green a few days later, suggesting someone was in my computer and watching.

More recently, I received a text message from Google with the two-step verification code for my Gmail account. That's the string of numbers Google sends after you correctly enter the password to your Gmail account, and it serves as a second password. (Do sign up for it.) The only problem was that I was not trying to get into my Gmail account. I was nowhere near a computer. Apparently, somebody else was.

It is absurdly easy to get hacked. All it takes is clicking on one malicious link or attachment.

Companies' computer systems are attacked every day by hackers looking for passwords to sell on auctionlike black market sites where a single password can fetch $20.

Hackers regularly exploit tools like John the Ripper, a free password-cracking program that use lists of commonly used passwords from breached sites and can test millions of passwords per second.

Chances are, most people will get hacked at some point in their lifetime.

The best they can do is delay the inevitable by avoiding suspicious links, even from friends, and manage their passwords. Unfortunately, good password hygiene is like flossing — you know it's important, but it takes effort.

How do you possibly come up with different, hard-to-crack passwords for every single news, social network, e-commerce, banking, corporate and email account and still remember them all?

To answer that question, I called two of the most (justifiably) paranoid people I know, Jeremiah Grossman and Paul Kocher, to find out how they keep their information safe.

Grossman was the first hacker to demonstrate how easily somebody can break into a computer's webcam and microphone through a Web browser.

He is now chief technology officer at WhiteHat Security, an internet and network security firm, where he is frequently targeted by cybercriminals.

Kocher, a well-known cryptographer, gained notice for clever hacks on security systems. He now runs Cryptography Research, a security firm that specialises in keeping systems hacker-resistant.

Here are their tips:

Forget the dictionary
If your password can be found in a dictionary, you might as well not have one. "The worst passwords are dictionary words or a small number of insertions or changes to words that are in the dictionary," said Kocher. Hackers will often test passwords from a dictionary or aggregated from breaches. If your password is not in that set, hackers will typically move on.

Never use the same password twice
People tend to use the same password across multiple sites, a fact hackers regularly exploit. While cracking into someone's professional profile on LinkedIn might not have dire consequences, hackers will use that password to crack into, say, someone's email, bank, or brokerage account where more valuable financial and personal data is stored.

Come up with a passphrase
The longer your password, the longer it will take to crack. A password should ideally be 14 characters or more if you want to make it uncrackable by an attacker in less than 24 hours. Because longer passwords tend to be harder to remember, consider a passphrase, such as a favourite movie quote, song lyric, or poem, and string together only the first one or two letters of each word in the sentence.

Or just jam on your keyboard
For sensitive accounts, Grossman says that instead of a passphrase, he will randomly jam on his keyboard, intermittently hitting the shift and alt keys, and copy the result into a text file which he stores on an encrypted, password-protected USB drive. "That way, if someone puts a gun to my head and demands to know my password, I can honestly say I don't know it."

Store your passwords securely
Do not store your passwords in your in-box or on your desktop. If malware infects your computer, you're toast. Grossman stores his password file on an encrypted USB drive for which he has a long, complex password that he has memorised. He copies and pastes those passwords into accounts so that, in the event an attacker installs keystroke logging software on his computer, they cannot record the keystrokes to his password. Kocher takes a more old-fashioned approach: He keeps password hints, not the actual passwords, on a scrap of paper in his wallet. "I try to keep my most sensitive information off the internet completely," Kocher said.

A password manager?
Maybe password-protection software lets you store all your usernames and passwords in one place. Some programs will even create strong passwords for you and automatically log you in to sites as long as you provide one master password. LastPass, SplashData and AgileBits offer password management software for Windows, Macs and mobile devices. But consider yourself warned: Kocher said he did not use the software because even with encryption, it still lived on the computer itself. "If someone steals my computer, I've lost my passwords." Grossman said he did not trust the software because he didn't write it. Indeed, at a security conference in Amsterdam earlier this year, hackers demonstrated how easily the cryptography used by many popular mobile password managers could be cracked.

Ignore security questions
There is a limited set of answers to questions like "What is your favourite colour?" and most answers to questions like "What middle school did you attend?" can be found on the internet. Hackers use that information to reset your password and take control of your account. Earlier this year, a hacker claimed he was able to crack into Mitt Romney's Hotmail and Dropbox accounts using the name of his favourite pet. A better approach would be to enter a password hint that has nothing to do with the question itself. For example, if the security question asks for the name of the hospital in which you were born, your answer might be: "Your favourite song lyric."

Use different browsers
Grossman makes a point of using different web browsers for different activities. "Pick one browser for 'promiscuous' browsing: online forums, news sites, blogs — anything you don't consider important," he said. "When you're online banking or checking email, fire up a secondary web browser, then shut it down." That way, if your browser catches an infection when you accidentally stumble on an X-rated site, your bank account is not necessarily compromised. As for which browser to use for which activities, a study last year by Accuvant Labs of web browsers — including Mozilla Firefox, Google Chrome and Microsoft Internet Explorer — found that Chrome was the least susceptible to attacks.

Share cautiously "You are your email address and your password", Kocher emphasised. Whenever possible, he will not register for online accounts using his real email address. Instead he will use "throwaway" email addresses, like those offered by 10minutemail.com. Users register and confirm an online account, which self-destructs 10 minutes later. Grossman said he often warned people to treat anything they typed or shared online as public record.

"At some point, you will get hacked — it's only a matter of time," warned Grossman. "If that's unacceptable to you, don't put it online."
The New York Times

Read more: http://www.smh.com.au/digital-li ... .html#ixzz2BxhDFXym
Top
 


All times are GMT+8, the time now is 27-11-2024 15:17

Powered by Discuz! 5.0.0 © 2001-2006 Comsenz Inc.
Processed in 0.035145 second(s), 9 queries , Gzip enabled

Clear Cookies - Contact Us - 141Love
Disclaimer: This forum is operated as a real-time bulletin board system. 141CLUB.COM carries no legal liability on its contents. All messages are solely composed and up-loaded by readers and their opinions do not represent our stand. Readers are reminded that the contents on this forum may not convey reliable information thus it is readers' own responsibility to judge the validity, completeness and truthfulness of the messages. For messages related to medical, legal or investment issues, readers should always seek advice from professionals. Due to the limitation of the forum's real-time up-loading nature, 141CLUB.com is not able to monitor all the messages posted. Should readers find any problems regarding the messages, do contact us. 141CLUB.COM reserves the rights to delete or preserve any messages and reject anyone from joining this forum. 141CLUB.COM reserves all the legal rights.