Programming Forums
User Name Password Register
 

RSS Feed
FORUM INDEX | TODAY'S POSTS | UNANSWERED THREADS | ADVANCED SEARCH

Reply
 
Thread Tools Display Modes
Old Jul 24th, 2004, 6:31 PM   #31
kurifu
Expert Programmer
 
kurifu's Avatar
 
Join Date: Jul 2004
Location: Halifax, Nova Scotia (Canada)
Posts: 784
Rep Power: 5 kurifu is on a distinguished road
Send a message via ICQ to kurifu Send a message via MSN to kurifu
Actually changing your password "on a regular basis" can be just as bad as not changing them if someone is around to know exactly when you are going to do it... security through obscurity, mix things up a bit and do it at somewhat inconsistent intervals.
__________________
Clifford Matthew Roche <geek@cliffordroche.com>
Web Hosting: http://www.crd-hosting.com
Consulting: http://www.crdev-consulting.com
kurifu is offline   Reply With Quote
Old Jul 24th, 2004, 7:33 PM   #32
sarumont
Hobbyist Programmer
 
sarumont's Avatar
 
Join Date: Apr 2004
Location: /dev/urandom
Posts: 154
Rep Power: 5 sarumont is on a distinguished road
Send a message via ICQ to sarumont Send a message via AIM to sarumont Send a message via Yahoo to sarumont
Quote:
Originally posted by kurifu@Jul 24 2004, 04:31 PM
security through obscurity, mix things up a bit and do it at somewhat inconsistent intervals.
As long as you only do this with your password changing...not your coding.
__________________
"Time is an illusion. Lunchtime doubly so."
-the late, great Douglas Adams
sarumont is offline   Reply With Quote
Old Jul 25th, 2004, 4:36 PM   #33
kurifu
Expert Programmer
 
kurifu's Avatar
 
Join Date: Jul 2004
Location: Halifax, Nova Scotia (Canada)
Posts: 784
Rep Power: 5 kurifu is on a distinguished road
Send a message via ICQ to kurifu Send a message via MSN to kurifu
haha, well the obscurity part still holds for coding
__________________
Clifford Matthew Roche <geek@cliffordroche.com>
Web Hosting: http://www.crd-hosting.com
Consulting: http://www.crdev-consulting.com
kurifu is offline   Reply With Quote
Old Jul 26th, 2004, 10:13 AM   #34
Pizentios
Programming Guru
 
Pizentios's Avatar
 
Join Date: May 2004
Location: Brandon, Manitoba, Canada
Posts: 2,023
Rep Power: 7 Pizentios is on a distinguished road
Send a message via ICQ to Pizentios Send a message via MSN to Pizentios
Quote:
lol. sounds like you lucked out on that one... I had to use a Linux boot disk not to long ago to get into my win xp box.
One of the many tools that i use at work on a weekly basis. Users are so dumb.
__________________
Profanity is the one language that all programmers understand.

Check out my Blog <---updated Nov 30 2007!
Pizentios is offline   Reply With Quote
Old Jul 26th, 2004, 10:17 AM   #35
big_k105
PFO Founder

 
big_k105's Avatar
 
Join Date: Mar 2004
Location: Fargo, ND
Posts: 1,667
Rep Power: 10 big_k105 is on a distinguished road
Send a message via AIM to big_k105 Send a message via MSN to big_k105 Send a message via Yahoo to big_k105
i dont normally change my passwords as i would never remember what i changed them to :ph34r:
__________________
BIG K aka Kyle
Programming Forums
Kyle K Online

Please do not PM or email me programming questions. Post them in the forums instead.
big_k105 is offline   Reply With Quote
Old Jul 27th, 2004, 7:16 PM   #36
kurifu
Expert Programmer
 
kurifu's Avatar
 
Join Date: Jul 2004
Location: Halifax, Nova Scotia (Canada)
Posts: 784
Rep Power: 5 kurifu is on a distinguished road
Send a message via ICQ to kurifu Send a message via MSN to kurifu
I was like that, you get used to it quickly though. You could always write them down and store them in a secure place... probably not that secure of an idea though.
__________________
Clifford Matthew Roche &lt;geek@cliffordroche.com&gt;
Web Hosting: http://www.crd-hosting.com
Consulting: http://www.crdev-consulting.com
kurifu is offline   Reply With Quote
Old Jul 27th, 2004, 11:12 PM   #37
Infinite Recursion
Programming Guru
 
Infinite Recursion's Avatar
 
Join Date: Jul 2004
Location: United States
Posts: 3,473
Rep Power: 8 Infinite Recursion is on a distinguished road
Send a message via MSN to Infinite Recursion Send a message via Yahoo to Infinite Recursion
Thank about this guys... the last password generator I wrote creates and validates passwords that containts 2 lowercase alphas, 2 uppercase alphas, 2 symbols, 2 digits and 2 randoms at 10 characters in length and randomly filled. The upper and lower alphas cannot be side by side to reduce chances of a dictionary attack.

I told my employer that we have effectively reduced security because the users will be writing their passwords down on their desks. Hell when I wrote my own password to conform to the audit specs, just to confirm the password required me typing into notepad and copying and pasting it.

At any rate, figured I'd add in the passwords from hell
__________________
http://jasonpowers.net

"There are a thousand hacking at the branches of evil to one who is striking at the root."
Infinite Recursion is offline   Reply With Quote
Old Jul 28th, 2004, 9:51 AM   #38
Pizentios
Programming Guru
 
Pizentios's Avatar
 
Join Date: May 2004
Location: Brandon, Manitoba, Canada
Posts: 2,023
Rep Power: 7 Pizentios is on a distinguished road
Send a message via ICQ to Pizentios Send a message via MSN to Pizentios
those are always the best ones.
__________________
Profanity is the one language that all programmers understand.

Check out my Blog <---updated Nov 30 2007!
Pizentios is offline   Reply With Quote
Old Jul 30th, 2004, 7:42 PM   #39
kurifu
Expert Programmer
 
kurifu's Avatar
 
Join Date: Jul 2004
Location: Halifax, Nova Scotia (Canada)
Posts: 784
Rep Power: 5 kurifu is on a distinguished road
Send a message via ICQ to kurifu Send a message via MSN to kurifu
The problem is that if a password is too arbitrary, then there is no incentive for the user to remember the password, this is something you learn in your basic psychology course. Unless that person is using the password in a daily basis, and even when they are first given the password the process of moving such a string of characters from their short term to long term memory requires a lot of initial uses.... pay the person to write the password down 1,000 time over and you have solved the problem (but who really wants to do that.. lol).

On the other hand a password that is not nearly arbitrary enough is easy to crack if you know a few details about the person, I have done this for people who have asked me to recover old email passwords for them on a few occasions.

Biometric authentication seems like an ineresting was to go around the problem of course... you could always look into a technology I played around with some time ago kind of like biometric authentication (only not using biometrics) at: http://www.ibutton.com.

Only problem with that of course is that they are like keys... you do not want to loose them, though they have taken a few measures to prevent this. At least if you loose it you know to change your access codes, but if you leak a password... you might not know until it is too late, that is of course if you know even then...
__________________
Clifford Matthew Roche &lt;geek@cliffordroche.com&gt;
Web Hosting: http://www.crd-hosting.com
Consulting: http://www.crdev-consulting.com
kurifu is offline   Reply With Quote
Old Aug 3rd, 2004, 10:39 AM   #40
Pizentios
Programming Guru
 
Pizentios's Avatar
 
Join Date: May 2004
Location: Brandon, Manitoba, Canada
Posts: 2,023
Rep Power: 7 Pizentios is on a distinguished road
Send a message via ICQ to Pizentios Send a message via MSN to Pizentios
Passwords are always going to be the weak point in any system. Give a person some time and a whole bunch of cpu cycles and there going to get in.
__________________
Profanity is the one language that all programmers understand.

Check out my Blog <---updated Nov 30 2007!
Pizentios is offline   Reply With Quote
Reply

Bookmarks

« Previous Thread in Forum | Next Thread in Forum »

Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump




DaniWeb IT Discussion Community
All times are GMT -5. The time now is 4:37 PM.

Powered by vBulletin® Version 3.7.0, Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Copyright ©2007 DaniWeb® LLC