Hello and welcome to CertForums.co.uk, here we host free active certification forums with links to the best free resources for Microsoft's MCSA MCSE MCDBA Cisco's CCNA CCDA and CCNP, and CompTIA's A+ Network+ i-NET+ and Security+ certifications in the UK. If you wish to post or use other advanced features you will need to register first. Registration is absolutely free and takes only a few minutes to complete so sign up today!

If you have any problems with the registration process or your account login, please contact support

Go Back   CertForums > Computing Support Forums > Security & Viruses
Home Forums Register Search Today's Posts Mark Forums Read

Remembering Passwords

Post New ThreadReply
 
Thread Tools Display Modes
  #16  
Old 02-May-2008, 12:23 PM
ffreeloader's Avatar
ffreeloader ffreeloader is offline
Lifetime Member
Posts: 3,649
Points: 3030 ffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 points
Power: 72
None
Join Date: 26 Jul 2005
Location: USA
Age: 54
Certifications: MCSE, MCDBA, CCNA, A+
WIP: LPIC 1
Quote:
Originally Posted by neilmowforth View Post
I choose my password dependent on what the site holds. E.g. this forum, my low security generic password, e retailer sites which store my card details have a medium security password (a mixture of numbers, capitals and lower case - but still rememberable), high security sites, such as my bank & email have a higher security password (a mixture of everything which means nothing to anyone - except me).
I guess I don't understand your last equating of needing as secure a password for email as for your bank login. Unless all the POP and IMAP servers you access to get your email use TLS or something like for all your email anyone can sniff your network traffic and get your email username and password. They are transmitted in clear text over the internet to almost all ISP's and IMAP email services.

I use the least secure password I have for email accounts because of it. It's just too easy to steal.

Now, if I'm encrypting email using PGP, or something similar, then I'll use a strong password, but email being so readily sniffed just isn't worth it. Email as about as insecure as things get....



Behold, the turtle. He makes progress only when he sticks his neck out.

James Bryant Conant
 
Reply With Quote
  #17  
Old 02-May-2008, 12:26 PM
neilmowforth's Avatar
neilmowforth neilmowforth is offline
New Member
Posts: 22
Points: 0 neilmowforth has no points
Power: 1
None
Join Date: 13 Feb 2008
Location: Oxford
Certifications: 270, 290, 291
WIP: 620, Girlfriend 1.0
Is it, oh dear! I only use web based email if that makes a difference.

The reason I use a secure password for it though, is if that gets hacked then you could go round all the other websites requesting an password email reminder etc.


Is it about my cube?
 
Reply With Quote
  #18  
Old 05-May-2008, 08:07 PM
Arroryn's Avatar
Arroryn Arroryn is offline
Groovin
Posts: 2,062
Points: 2542 Arroryn has over 2500 pointsArroryn has over 2500 pointsArroryn has over 2500 pointsArroryn has over 2500 pointsArroryn has over 2500 pointsArroryn has over 2500 pointsArroryn has over 2500 pointsArroryn has over 2500 pointsArroryn has over 2500 pointsArroryn has over 2500 pointsArroryn has over 2500 points
Power: 51
None
Join Date: 31 Mar 2005
Location: Coventry
Age: 24
Certifications: A+ and N+
WIP: Working+ (and other secrets...)
I just... remember them.

But I have my own 'system' as most people probably do. I think it's secure, but there again, most people feel secure until they're done over

I use a different password for each social site I frequent; I also have different passwords for all of my retail accounts. They all draw on the same theme for the word, but it's a rather vague theme (books) using a vague drawout (phrases from books) that are memorable to me. To give it a possible edge on security, I reference the phrase in a language that is not meant to be the core language of the site I am on (I know doesn't matter with sniffers or whatever, but it makes me feel safe!) I then intersperse each one with numbers, upper and lower case characters, and special characters.

Voila.

Some sites, it takes me maybe three attempts to remember the password. But I've never locked myself out (yet). And I tend to rotate the passwords on a monthly or bi-montly basis, depending on how proactive I'm feeling.

Of course, strong passwords are a moot point where they become so convoluted that you can't type them at a good speed. I've heard of domain admin passwords being had, just because a slowly-typing tech was being watched by a speed typist, who thought it would be a long-term good idea to have admin rights on their PC. Oooh dear.

 
Reply With Quote
  #19  
Old 06-May-2008, 09:56 PM
ManicD's Avatar
ManicD ManicD is offline
Valued Member
Posts: 233
Points: 147 ManicD has over 100 pointsManicD has over 100 points
Power: 6
None
Join Date: 24 May 2007
Location: East sussex, UK
Age: 20
Certifications: MCSA, N+, A+(Tech), ECDL
WIP: 70-294, 70-298
Quote:
Originally Posted by neilmowforth View Post
I choose my password dependent on what the site holds. E.g. this forum, my low security generic password, e retailer sites which store my card details have a medium security password (a mixture of numbers, capitals and lower case - but still rememberable), high security sites, such as my bank & email have a higher security password (a mixture of everything which means nothing to anyone - except me).
I have a variaty of passwords, and i randomly assign then to websites, each holds a different security level for me, and i just mentally keep track of what goes where. is not an exact science but i do seperate things like, email, bank account and forums etc.


Nemo vir est qui mundum non reddat meliorem
 
Reply With Quote
  #20  
Old 15-May-2008, 10:21 PM
mark_uol mark_uol is offline
New Member
Posts: 23
Points: 0 mark_uol has no points
Power: 1
None
Join Date: 15 May 2008
Location: Wiltshire UK
WIP: MsC IT Security UoL
You could try the mnemonic system. Pick a well known sentence such as “Mary had a little lamb its fleece was white as snow”. Now abstract each initial character then capitalize every second one.
MhAlLiFwWaS
Next introduce a non-alphanumeric character “/”
M/h/A/l/L/i/F/w/W/a/S
Now you can safely write down Mary ½ as an aid to memory. This password is medium strength in that it is invulnerable from dictionary attacks forcing a “brute strength” attack which is costly to the attacker.

 
Reply With Quote
Post New ThreadReply Spread this thread: Submit this thread to digg Submit this thread to del.icio.us


Go Back   CertForums > Computing Support Forums > Security & Viruses


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
2003 show user passwords? garyb Security & Viruses 9 06-Mar-2008 06:09 PM
Remembering IRQ's, COM and LPT tony_baduk A+ 8 27-Dec-2007 08:36 PM
Changing passwords for external user? nugget Software 11 15-Oct-2007 10:29 PM
Passwords Ozzy2k7 Security & Viruses 9 09-Sep-2007 09:10 AM
Remembering 9/11 SiFor The Lounge - Off Topic 4 11-Sep-2006 01:10 PM


All times are GMT. The time now is 11:35 AM.

Powered by vBulletin® Version 3.6.10
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
CertForums.co.uk (C) copyright 2003-2007 All Rights Reserved. Content published on CertForums.co.uk requires permission for reprint.
Hosted by Lunarpages