Maybe people like to share ideas about making passwords that are both strong and easy to remember. That can be done in this topic.
Maybe people like to share ideas about making passwords that are both strong and easy to remember. That can be done in this topic.
Ja mata
TosaInu
Use words that you know or that are familiar to you, but make them 1337 to increase security. For instance, if ardvaark means something to you, use it but make it: @rdv44rk!
You can also go one step further and use phrases instead of words, e.g. T0$@Ru1z7h30rg!, which has upper and lower case, numbers & symbols and makes little sense without the source phrase.
Last edited by therother; 10-26-2008 at 19:38.
Nullius addictus iurare in verba magistri -- Quintus Horatius Flaccus
History is a pack of lies about events that never happened told by people who weren't there -- George Santayana
Take a word you like. Let's say you are a huge fan of spicy foods so we'll use Spicy as an example. You're going to make this your password, but you wonder if someone who you know, or just some bot, could hack it.
Spicy
Seems pretty easy, huh? Well by inserting numbers inbetween the letters, you increase the chance that the bot will not be able to crack the password. So let's take a look at that in action.
S0p9i8c7y6
Looks pretty good, right? No. We're not done yet. The next point we're going to do is randomize the numbers up a bit. This is so even if the bot is pretty advanced and tries something like this, he won't get it. Any number that is not a straight sequence will work as long as you haven't given it out here on the site. So let's do a random date that's important to you, no. Not your Bday, you may have shared that here! So instead we'll do Columbus Day. Something we here in the states recognize. (sometimes)
S1p0i1c3y6
We throw a 6 in there just to be tricky. What started simply as Spicy has been spiced up a bit by way of implementing an obscure holiday's date into it. 10-13 (or 13-10 for you Europeans).
And there you go. A nice and secure password that is out of the ordinary. You might say to yourself "Monk, that's dumb, I'll never remember that!" Well that's true at first, but these sorts of passwords are very easy if you figure out their rhythm of typing them. After a week of solid use (not saving your cookies so you'll remember it) you'll get the PW down easily.
Wait why would a bot hack my password?
There, but for the grace of God, goes John Bradford
My aim, then, was to whip the rebels, to humble their pride, to follow them to their inmost recesses, and make them fear and dread us. Fear is the beginning of wisdom.
I am tired and sick of war. Its glory is all moonshine. It is only those who have neither fired a shot nor heard the shrieks and groans of the wounded who cry aloud for blood, for vengeance, for desolation.
Why? A bot might hack your password: to take overthe worldyour account.
Well, at any rate one of the nastier things people can do with bot accounts is post advert spam (we've seen a couple of those), check your e-mail address to hook you up for SPAM mail (am not sure if it shows up, but would be on the wishlist for quite a few bot-masters if it did), use your signature space for (links to) malicious content by which the bot-masters may hijack other peoples browsers.
Or just shut you out of the ORG unless you create a new account. Which may be tricky if the ORG has duplicate account filters based on, say, e-mail addresses?
Strong passwords as in really very strong are very long and very random. So you usually get the best by using a random password generator and use, say 20 characters. That means a bot could have to go through as much as ~10^21 rounds of guesswork. (= beyond practical with the keep-you-out-for-x-mins after 3 consecutive failed attempts) In order for it to actually work it would even have to keep a list of foolish attempts it made. A big list if your lucky. A short one if not, because it remains a matter of chance.
- Tellos Athenaios
CUF tool - XIDX - PACK tool - SD tool - EVT tool - EB Install Guide - How to track down loading CTD's - EB 1.1 Maps thread
“ὁ δ᾽ ἠλίθιος ὣσπερ πρόβατον βῆ βῆ λέγων βαδίζει” – Kratinos in Dionysalexandros.
Last edited by Tellos Athenaios; 10-27-2008 at 01:14.
- Tellos Athenaios
CUF tool - XIDX - PACK tool - SD tool - EVT tool - EB Install Guide - How to track down loading CTD's - EB 1.1 Maps thread
“ὁ δ᾽ ἠλίθιος ὣσπερ πρόβατον βῆ βῆ λέγων βαδίζει” – Kratinos in Dionysalexandros.
Ah, just read the announcement. I doubt you'd need anything like the kind of strength we've been talking about right now to protect your average Org user account from bots. vB has a few safety features built in such that as long as it isn't something really easy to guess, like your username, "password", "letmein" etc., or a dictionary word, you should be fine.
Found this site, which give you some indication about how strong your password is. Doesn't check dictionary words though, so isn't entirely accurate. Plenty of other password strength metrics out there though.
Love to hear the mnemonic for that one!
Last edited by therother; 10-27-2008 at 02:31.
Nullius addictus iurare in verba magistri -- Quintus Horatius Flaccus
History is a pack of lies about events that never happened told by people who weren't there -- George Santayana
I recall that I couldn't get my password back in the old version of vBulletin, so it would be a good idea to improve it first.
And second, don't give info about yourself... and use it in your password. For example, if I live in Washington, I wouldnt use Washington as a password. I wouldn't use Cirilic characters either. But yes a combination of numbers, letters and some weird thing as !"·$$%&/()=_.:,;
That's all.-
Names, secret names
But never in my favour
But when all is said and done
It's you I love
I'm gonna go spice up my password.![]()
My Greek Cavalry submod for RS 1.6a: http://www.twcenter.net/forums/showthread.php?t=368881
For Calvin and TosaInu, in a better place together, modding TW without the hassle of hardcoded limits. We miss you.
.
There's a Mozilla extension called Secure Password Generator, which can produce random passwords from letters, numbers and predefined special characters in adjustable frequencies and of any given number of characters.
As for meaningful words, blend them with numbers and mix upper/lower case.
.
Ja mata Tosa Inu-sama, Hore Tore, Adrian II, Sigurd, Fragony
Mouzafphaerre is known elsewhere as Urwendil/Urwendur/Kibilturg...
.
- Tellos Athenaios
CUF tool - XIDX - PACK tool - SD tool - EVT tool - EB Install Guide - How to track down loading CTD's - EB 1.1 Maps thread
“ὁ δ᾽ ἠλίθιος ὣσπερ πρόβατον βῆ βῆ λέγων βαδίζει” – Kratinos in Dionysalexandros.
For me, I use a random number/letter generator to generate my password and then just memorize it. Even if I have no easy way to remember it, after a while, I just know it and don't have to look off a piece of paper or anything like that
"I do not know what I may appear to the world; but to myself I seem to have been only like a boy playing on the seashore, and diverting myself in now and then finding a smoother pebble or a prettier shell than ordinary, whilst the great ocean of truth lay all undiscovered before me." - Issac Newton
Don't have the same password for more then 1 account. If you lose your PW here for example, and it the same PW for .Org account, your e-mail and your work e-mail, you in touble.
I just use 123mith456 for all my online activities, hasn't failed me yet.
Abandon all hope.
Last edited by TevashSzat; 10-27-2008 at 20:13.
"I do not know what I may appear to the world; but to myself I seem to have been only like a boy playing on the seashore, and diverting myself in now and then finding a smoother pebble or a prettier shell than ordinary, whilst the great ocean of truth lay all undiscovered before me." - Issac Newton
Hello Caius,
You mean a password reset? That can go wrong indeed and there are some chains that can break. The script can fail, the e-mail details may be wrong, the mailserver can have a hiccup, mail is blocked or bumped.
It will be good to make that secret question/secret answer in your UserCP first. Then verify whether your e-mail account is still up to date. If it isn't you could send me a PM and ask me to update it first while you can still login. Of course, you can also do that yourself, but please after you did the first step, because there is a chance that it will lock you out.
When you lose access to your account, you can contact me (through a temp account, e-mail, a friend asking for you). Of course I like to be sure I reset the account for the right owner only. The secret password/answer is one of those lifelines. So put some thought in those too.
Ja mata
TosaInu
Something I'd like to suggest in addition to what others have added:
Pick an event you can easily remember. This will provide a word and a number.
For example, graduating from college. Pick the letters of your alma mater and the graduation date. It's not important that it be completely unknown, just that a- it's not easily known and b- you won't forget it.
Next, interweave the two data sets, the letters and the numbers.
Next, in a pattern meaningful to you, come up with a system of capitalization you will remember.
Finally, select your favorite dingbat and insert it somewhere into the string.
Example (note: I do not use my graduation event as a seed, I use another qualifying event).
So, I graduated from UCONN in June of 1996. I'll take U-C-O-N-N and 0-6-9-6.
I'll interleave them to make U0C6O9N6N.
Next, I need to pick a capitalization scheme. I'll make u lower and all the rest upper.
u0C6O9N6N.
next, insert my favorite dingbat * (not actually my favorite dingbat) into the 3rd position
u0*C6O9N6N and voila.
Works for anniverseries, birth of chidren, prom date, you name it.
"A man who doesn't spend time with his family can never be a real man."
Don Vito Corleone: The Godfather, Part 1.
"Then wait for them and swear to God in heaven that if they spew that bull to you or your family again you will cave there heads in with a sledgehammer"
Strike for the South
My advice? Never use "password".
Spoiler Alert, click show to read:
It is better to conquer yourself than to win a thousand battles. Then, the victory is yours. It cannot be taken from you, not by angels or by demons, heaven or hell.
Hello Caius,
Didn't it mention trying copying and pasting of the URL in case clicking failed?
Ja mata
TosaInu
My password was ridiculously simple... Added something today. After each character, the character of the key below that one. So, after Q would come A, after W would come S, etc. (qwerty-keyboard,that is)
- Chu - Gi - Makoto - Rei - Jin - Yu - Meiyo -
It was more like
Sxazsxazk,ik_{Rfujl.edsx
:P
- Chu - Gi - Makoto - Rei - Jin - Yu - Meiyo -
bah, good job i stay logged in as org decided my password after losing it, my usual password is just a number sequence now though, a like 12 character long one, but i no it off by heart![]()
Bookmarks