Page 1 of 1

Passwords

Posted: 08 Jul 2015, 11:13
by markfiend
http://arstechnica.com/security/2013/05 ... passwords/

If you use anything other than a properly randomised password, CHANGE IT. Here is a sample of supposedly secure passwords that crackers have broken quickly and easily:
Image

If possible, use something like KeePass

Posted: 08 Jul 2015, 11:28
by nowayjose
Lesson: never store plain password hashsums, always use them with a salt (random initialization vector). That is pretty common knowledge. From the screenshot above, it is obvious this simple method has been omitted from that list of hashes, for whatever reason. Also, make sure your password db doesn't get stolen.

Posted: 08 Jul 2015, 11:40
by markfiend
If you read the accompanying article, even salting passwords doesn't help much if the site uses crappy hashing like MD5 or SHA1.

Posted: 08 Jul 2015, 13:35
by Izzy HaveMercy
I always use the same password: **********

Let 'em try to crack THAT ;D

(and always use a semicolon in your password, H4X0Rz love that little character)

IZ.

Posted: 08 Jul 2015, 13:45
by Pista
Izzy HaveMercy wrote:I always use the same password: **********

Let 'em try to crack THAT ;D



IZ.
:lol: :lol:

Posted: 08 Jul 2015, 14:13
by million voices
I can't say as I really understood all of it, but I thought the section "Anatomy of a Crack" would have been more interesting

Posted: 08 Jul 2015, 14:14
by markfiend
what, hunter2?

(clicky for the uninitiated)

(Edit: that was @Izzy)

Posted: 08 Jul 2015, 14:48
by Izzy HaveMercy
markfiend wrote:what, hunter2?

(clicky for the uninitiated)

(Edit: that was @Izzy)
;D :notworthy: ;D :notworthy: ;D

IZ.

Posted: 09 Jul 2015, 16:42
by Bartek
Oh, crap, that was mine password to gmail.
(Like google didn't read my e-mails).