Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Pass the Chocolate
Scott Granneman, 2004-05-26

For the 70% of the population that will trade their computer password for a bar of chocolate, this one's for you.

Comments Mode:
Pass the Chocolate 2004-05-27
pthread (1 replies)
Pass the Chocolate 2004-06-01
Anonymous
Pass the Chocolate 2004-05-27
Dominic Cronin
Pass the Chocolate 2004-05-27
Anonymous (1 replies)
Pass the Chocolate 2004-05-28
microchp
Pass the Chocolate 2004-05-27
N. Alan
Pass the Chocolate 2004-05-27
Anonymous
Pass the Chocolate 2004-05-27
Anonymous (1 replies)
Pass the tequila 2004-05-27
Mene Tekel
Pass the Chocolate 2004-05-27
Anonymous
Pass the Chocolate 2004-05-27
E. de Jong
WRITE them passwords down... 2004-05-27
Nicholas Weaver
Write them down and KEEP THEM IN YOUR WALLET. I have some root passwords and my obscure "secure" account passwords written down in my wallet. (My main password and ssh passphrase are 100% memorized, so it is not an issue there)

Likewise, you want Bruce Shneier's passwords? You mug him!

The lesson is that the wallet is already kept reasonably secure: I know where it is at effetively all times, and the union of people who would want to steel my wallet is very different from those who would break into my account, and I'd know it if my wallet went missing anyway.

Likewise, all the funky pin based authentication tokens are doing the same thing, giving you a physical device, which you stick in either your wallet (cardkey-shaped) or keychain (keyfob-shaped), attaching the secret into something you really care about.

Now you really CAN bang on random keys, get a purely random password, and until repetition makes you remember it, you have ready access.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/245/26487#26487
Pass the buck 2004-05-27
Mene Tekel (1 replies)
Pass the buck 2004-06-01
Anonymous
Pass the Chocolate 2004-05-28
Anonymous
Pass the Chocolate 2004-06-01
Tommy Ward (2 replies)
Pass the test 2004-06-03
Mene Tekel
Re: Pass the Chocolate 2006-11-28
Anonymous (1 replies)
Re: Re: Pass the Chocolate 2007-06-15
Anonymous
Pass the Chocolate 2004-06-02
steeef
Pass the Chocolate 2004-06-06
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus