![]() |
How long are your passwords?
I've been using several different ones over the years (changing them as needed) for several different levels of security. That said, I've typically kept them less than 10 characters or so even though they're random and not likely to be "guessed". Dang processors have gotten fast enough so it only takes less than 60 seconds to "crack" most passwords of this length I now learn :(. So, I reckon it's time for this ol' dawg to learn a new trick....LONG passwords (i.e a long sentence) seems be the way of the future out of necessity....YMMV.
|
On a windows machine, open powershell and type: [guid]::NewGuid(). You will get something that looks like this: ba76b0c6-9f23-49c2-92ec-ce9adff7d51e
Use that - or as much as you can remember - as your password. Try to make a sentence out of it to make it easier to remember. |
Yes, the processors are fast, but most systems only allow a certain amount of login tries before the account is locked. So that is not the way to hack into an account, they dont guess your password several million times per second and try them.
Passwords normally are saved encrypted in a DB. The fast processors are faster to decrypt the passwords. And then it does not matter how complicated the password is then. The only thing that matters is how secure the encryption is. If the encryption is cracked, then every password with that encryption is visible, no matter how complicated. And every string is just a string of characters to the machine. jnedfuhwerh23hehf28hf23 is equally hard to decrypt as a string of words with the same length who are easy to remember. |
Here is the password generator that I use.
|
I use sentences that I can remember, and throw in as many non-english words as I can. I figure a sentence in English, Spanish, and German is going to be hard to guess, if it is attacked in that way.
Still, I have my passwords saved as images in a database in an encrypted folder. |
Like mentioned before it really isn't your passwords it's the data base that stores them where the issue lies.
I don't really worry about passwords much but more the device I am using them on. There is no banking info or any app along those lines on my phone, nor is the email service that has my banking on it. I use yahoo for banking and google for my phone. I am not going to make it easy for someone to get access to my stuff but if someone is really determined to get at my credit rating of 247 and the $9.18 in my savings acct. then they are going to get it. One thing that allows me sleep well at night is my bank. I have had my checking acct hacked three times over the last ten years, and getting it resolved was very easy with a simple trip to the office with my statement and check ledger. |
It really doesn't matter. You can have the greatest password on Earth, but then the website gets hacked and they have your data anyway. It always amuses me how IT Security weenies create password rules that virtually guarantee you will have to write them down, make you change them every 30 days, but then can't protect the data. Yes, overly convoluted password rules are a pet peeve of mine.:)
|
Quote:
|
Quote:
And in future it will be harder to take a trip to that office as they are closing more and more of them. Good luck making all this online or via phone. |
I should mention I use a credit union for my banking, one detail I forgot to mention
|
Quote:
I also spent the first half of my IT career in banking....brings back painful memories SmileWavy |
Quote:
|
My passwords are 16-24 characters. I use LastPass to manage them - means you only need to remember one password.
|
I forget my passwords
|
I am looking for the perfect password app. With different web site that I have accounts with numerous email accounts and devices. I want a way to enter my passwords from several devices and many web sites and programs.
|
Glen - check out LastPass. It stores an encrypted password file on each of your devices plus in their cloud. You actually launch your websites from inside LastPass itself via the browser plug in. It will auto log in for you.
|
Quote:
|
Quote:
Using sentence-long passwords isn't really a good answer either - the longer the password, the greater chance of misspelling it and getting locked out of the device or application. Two areas that show promise are: 1. Dual-authentication systems: for example - the typical card reader security locks are now being replaced with a card reader / keypad combination - you still have to swipe a card, but you also have to authenticate that card by entering a 4 to 8 digit code. I believe some applications like Facebook are implementing stuff like this by using your cell phone number as a secondary layer of authentication besides your password. 2. Biometrics: this has been around for a long time, but is getting a little more traction again -- I've used fingerprint access points to get into my datacenter for years - and now the same technology is at the consumer level - as found in the newer iPhones. Some folks feel it is not quite ready, but I really like the ability to unlock my iPhone using my fingerprint as authentication. It works very well for me, and since my fingers are hopefully attached to the rest of my body, it makes it very difficult for a thief to get into my phone without my knowledge. Quote:
Best cloud to store passwords in are your brain. Still the hardest thing to hack. -Z-man. |
Quote:
|
Quote:
Since we are in healthcare if we find a Post-It with your AD password you can be terminated. Passwords for forums such as this aren't as complex as what I use for banking and such. Again, to keep people from gaining access not script kiddies and such. |
Quote:
|
1Password is your friend (or at least mine). It's expensive software but worth it.
I've heard LastPass is decent too but I don't want my stuff stored on anyone else's server, cloud, wherever. With 1Password it's all local - nothing lives on anyone else's server. That's how I want it. |
I looked over a co-worker's shoulder the other day as he typed his password, it was 12 asterisks.
|
Speaking of long passwords:
Quote:
|
"I needed a password eight characters long so I picked Snow White and the Seven Dwarves."
ba da bump. But serial folks |
Or ........................
Quote:
|
"Sorry, your password has been in use for 90 days and has expired - you must register a new one."
roses "Sorry, too few characters." pretty roses "Sorry, you must use at least one numerical character." 1 pretty rose "Sorry, you cannot use blank spaces." 1prettyrose "Sorry, you must use at least 10 different characters." 1****ingprettyrose "Sorry, you must use at least one upper case character." 1****INGprettyrose "Sorry, you cannot use more than one upper case character consecutively." 1****ingPrettyRose "Sorry, you must use no fewer than 20 total characters." 1****ingPrettyRoseShovedUpYourA**IfYouDon'tGiveMeA ccessRight****ingNow! "Sorry, you cannot use punctuation." 1****ingPrettyRoseShovedUpYourA**IfYouDontGiveMeAc cessRight****ingNow "Sorry, that password is already in use." |
Mine is 13 characters and rather odd.
|
Quote:
|
I just use the passwords that Safari suggests, and then when I get home and use the WindowsPC I have to request new ones. Only Pelican has my OG 1990s password.
|
Don't know. I password protected my password spreadsheet and can't remember the password. CURSES!
|
its not how long my password is its HOW FREAKING MANY i have! then to make things worse when i have to change one, sometimes it does not tell me the criteria for what it wants and it just keeps telling me its invalid. like it cant have a number for the character or the HAS to hav a number for the first character. Oh, and i really love the ones that start telling 30 days from now that my password will expire in 30 days or the ones that log you for 20 minutes AFTER you change your password.
i have a list of 30 passwords in my desk for everything here at work. how secure is that when you have to wirte them all down because we have so many. i have 2 just to log into my computer. we have a parts ordering system that about 3 of use the same ID and password because we have lost ours. the problem is if you dont use it for like 3 months it revokes your password and you have to call and get another one, so we all share one just because it keeps it active. great, now my day is ruined because of all this password crap. |
Yea - every silly two-bit site in the internet seems to require registration now. It's crazy - all about building profiles that can be sold to marketing companies or credit bureaus. People don't realize how much they're digging their own graves with respect to personal privacy every time they sign up for a new site.
|
Regarding storing passwords in the cloud:
https://blog.lastpass.com/2015/06/lastpass-security-notice.html/ |
Quote:
Looks like my paranoia is well-founded. Again. Irony alert: Password-storing company is hacked - Jun. 15, 2015 I TOLD YA' SO!!! ;) |
All times are GMT -8. The time now is 01:29 PM. |
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0
Copyright 2025 Pelican Parts, LLC - Posts may be archived for display on the Pelican Parts Website