Identi.ca Identi.ca
  • Login
  • Public

    • Public
    • Groups
    • Featured
    • Popular

Conversation

Notices

  1. Cyber Killer Cyber Killer System Administrators

    Passwords are like… http://ur1.ca/7g5iy - this image will never get old !sysadmin #security

    about 5 months ago from web at Koszalin, West Pomeranian Voivodeship, Poland
    • George Bankov likes this.
    • Space Hobo Space Hobo System Administrators

      @cyberkiller Changing passwords isn't as useful as having high-entropy ones in the first place. http://xkcd.com/936/

      about 5 months ago
    • Cyber Killer Cyber Killer System Administrators , Space Hobo

      @spacehobo actually that strip is wrong - that common word password is exremely weak to dictionary attacks, plus...

      about 5 months ago
    • Space Hobo Space Hobo System Administrators

      @cyberkiller You are the "someone who does not" in the hover text

      about 5 months ago
    • Cyber Killer Cyber Killer System Administrators , Space Hobo

      @spacehobo ...it would take 2,84e13 days to crack that 11 sign pass @ 1000 tries/sec, trying all 4word combinations in eng would take <1h

      about 5 months ago
    • Cyber Killer Cyber Killer System Administrators , Space Hobo

      @spacehobo yes, I dare argue with #xkcd ;-) /me grabs an asbestos suit ;-)

      about 5 months ago
    • Space Hobo Space Hobo System Administrators

      @cyberkiller You're comparing pwgen to dictionary passwords, and ignoring the measured entropy of english words.

      about 5 months ago
    • Cyber Killer Cyber Killer System Administrators , Space Hobo

      @spacehobo I'm comparing 11 random chars from 4 groups with 4 dictionary words: (2*23+10+32)^11 vs. 6677^4

      about 5 months ago
    • Cyber Killer Cyber Killer System Administrators , Space Hobo

      @spacehobo correction: (2*23+10+32)^11 vs. 62153^4, so it'd take >1h for the dictionary, but still the random pass is better

      about 5 months ago
    • Michał Andrzej Woźniak Michał Andrzej Woźniak System Administrators

      @cyberkiller yeah, but the person trying to break the password has no idea if that's 4 english words or ~20 alphanum chars. :)

      about 5 months ago
    • Michał Andrzej Woźniak Michał Andrzej Woźniak System Administrators

      @cyberkiller hence it should be viewed as a ~20 alphanum password, with regard to breaking and time needed for it

      about 5 months ago
    • Space Hobo Space Hobo System Administrators

      @cyberkiller I'm not debating against pwgen'd passwords. You seem to have not read the comic carefully enough.

      about 5 months ago
    • Cyber Killer Cyber Killer System Administrators , Space Hobo

      @spacehobo the comics author has made specific assumptions as to the first pass structure, that's why he got so low score for it

      about 5 months ago
    • Space Hobo Space Hobo System Administrators

      @cyberkiller and you think attackers don't benefit from making the exact same assumptions?

      about 5 months ago
    • Space Hobo Space Hobo System Administrators

      @cyberkiller it's a call for change from current bad advice about user-chosen passwords to good advice. Please read carefully.

      about 5 months ago
    • Cyber Killer Cyber Killer System Administrators , Michał Andrzej Woźniak

      @rysiek well, I usually run bruteforce and dictionary and mixed attacks in parallel, so it's whichever gets there first

      about 5 months ago
    • Cyber Killer Cyber Killer System Administrators , Space Hobo

      @spacehobo no, those assumptions were possible here because the string was known already. You can't tell if only 1st char is caps etc

      about 5 months ago
    • Space Hobo Space Hobo System Administrators

      @cyberkiller haha, you really are the caps guy in the hover text!

      about 5 months ago
    • Space Hobo Space Hobo System Administrators

      @cyberkiller the assumptions were possible because THIS IS HOW WE TELL PEOPLE TO MAKE PASSWORDS

      about 5 months ago
    • Cyber Killer Cyber Killer System Administrators , Space Hobo

      @spacehobo it is you how got fooled into believing that the output of 'pwgen -cnys 11 1' is ~2e8 combinations

      about 5 months ago
    • Cyber Killer Cyber Killer System Administrators , Space Hobo

      @spacehobo who tells? I never told anyone to create a password on a base of any existing word in any language, I tell ppl to use pwgen

      about 5 months ago
    • Space Hobo Space Hobo System Administrators

      @cyberkiller That is specifically NOT what is stated in the comic! Nobody is debating the strength of #pwgen passwords here!

      about 5 months ago
    • Space Hobo Space Hobo System Administrators

      @cyberkiller "We" the general tech industry, not you an individual.

      about 5 months ago
    • Space Hobo Space Hobo System Administrators

      @cyberkiller That comic is about balancing entropy and memorability to optimize for security.

      about 5 months ago
    • Space Hobo Space Hobo System Administrators

      @cyberkiller human factors mean that unmemorable passwords get committed to insecure storage, which is DISASTROUS.

      about 5 months ago
    • Cyber Killer Cyber Killer System Administrators , Space Hobo

      @spacehobo you could have said that earlier and save us this debate - I had only 3-4 hours of sleep today, so my brain is a bit off :-P

      about 5 months ago
    • Space Hobo Space Hobo System Administrators

      @cyberkiller well changing passwords is a human factors concern, so... duh?

      about 5 months ago
    • Michał Andrzej Woźniak Michał Andrzej Woźniak System Administrators , telecomix

      A few Polish NGOs are considering joining the #j18 #SOPA blackout with our own #ACTA blackout. msg me if interested /cc @telecomix

      about 5 months ago

Site notice

  • API
  • Status

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

Identi.ca is a microblogging service brought to you by Status.net. It runs the StatusNet microblogging software, version 1.1.0-alpha1, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All Identi.ca content and data are available under the Creative Commons Attribution 3.0 license.

Switch to mobile site layout.

Built in Montreal