Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Pass the Chocolate
Scott Granneman, 2004-05-26

For the 70% of the population that will trade their computer password for a bar of chocolate, this one's for you.

Comments Mode:
Pass the Chocolate 2004-05-27
pthread (1 replies)
Pass the Chocolate 2004-06-01
Anonymous
Pass the Chocolate 2004-05-27
Dominic Cronin
Pass the Chocolate 2004-05-27
Anonymous (1 replies)
Pass the Chocolate 2004-05-28
microchp
Pass the Chocolate 2004-05-27
N. Alan
Pass the Chocolate 2004-05-27
Anonymous
Pass the Chocolate 2004-05-27
Anonymous (1 replies)
Pass the tequila 2004-05-27
Mene Tekel
Pass the Chocolate 2004-05-27
Anonymous
Pass the Chocolate 2004-05-27
E. de Jong
WRITE them passwords down... 2004-05-27
Nicholas Weaver
Pass the buck 2004-05-27
Mene Tekel (1 replies)
Pass the buck 2004-06-01
Anonymous
Pass the Chocolate 2004-05-28
Anonymous
Pass the Chocolate 2004-06-01
Tommy Ward (2 replies)
Pass the test 2004-06-03
Mene Tekel
Re: Pass the Chocolate 2006-11-28
Anonymous (1 replies)
Re: Re: Pass the Chocolate 2007-06-15
Anonymous
Pass the Chocolate 2004-06-02
steeef
As others here have already mentioned, adding numbers to the end of a password only increases cracking difficulty marginally. I'm not convinced that adding different cases or special symbols helps that much either.

The most secure passwords are either randomly or mnemonicly (is that a word?) generated. The benefit of the latter is that it's easier to remember than the former.

For example, I can take an easily-remembered phrase like "if you can't beat them, join them" and create a password out of the initial letters: iycbtjt. It looks random, but to the creator, it makes sense. Granted, it's only 7 letters, but it's better than using dictionary words.

Another method is to take a dictionary word and split it up with numbers or special characters. Like splitting aardvark with 546: aard546vark. It's no longer a dictionary word, but the creator can see it as such.

Here's a PDF translated into HTML discussing the memorability of passwords:
http://tinyurl.com/28b8m

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/245/26605#26605
Pass the Chocolate 2004-06-06
Anonymous







 

Privacy Statement
Copyright 2008, SecurityFocus