Re: Good passwords and security priorities

From: Anne & Lynn Wheeler (lynn_at_garlic.com)
Date: 04/28/05

  • Next message: Henning: "Re: backdoor named tvic / Kayten / ttyshd download in apache logfile"
    Date: Wed, 27 Apr 2005 17:04:39 -0600
    
    

    "sinister" <sinister@nospam.invalid> writes:
    > Overall, I don't disagree; I have a list of all my passwords for work and
    > personal business on my home computer, and it's quite long, which is a real
    > hassle.
    >
    > However, at my work nearly all the risk is with break-ins from remote places
    > in cyberspace. So there's nothing wrong with most users just writing their
    > password down and leaving it in a desk drawer.

    several studies have indicated that at least 77% of fraudulent breakins
    involve insiders.

    recently in the news, there was something about plan for lifting a couple hundred
    million from some bank. there appeared to have been keyloggers installed
    on serveral machine ... possibly by somebody from a maint. or cleaning
    crew. the keyloggers were almost undetectable.

    not only wasn't the physical area not safe (for storing recorded passwords),
    but static data, shared-secret authentication mechanisms were vulnerable
    (whether they were written down or not).

    -- 
    Anne & Lynn Wheeler | http://www.garlic.com/~lynn/
    

  • Next message: Henning: "Re: backdoor named tvic / Kayten / ttyshd download in apache logfile"

    Relevant Pages

    • Re: Creating a Password
      ... >Such passwords can only be cracked by means of brute force. ... Disagree. ... I don't like arguing in topics like these, but this has to be said. ...
      (alt.computer.security)
    • Re: Creating a Password
      ... >Such passwords can only be cracked by means of brute force. ... Disagree. ... I don't like arguing in topics like these, but this has to be said. ...
      (microsoft.public.security)
    • Re: See what a weak password will get ya?
      ... > An example of a good password (though since I'm posting it here, ... I disagree. ... permutations of dictionary words. ... the best is to replace crypt based passwords with RSA ...
      (Debian-User)
    • Re: [PHP] HTTP Authentication thru PHP
      ... Jay Blanchard wrote: ... >user names and/or passwords. ... I disagree with this: special characters are useful to have better ...
      (php.general)
    • First time ssh user needs help, getting authentication failures
      ... I am using Etch completely updated on my home computer and was using the Ubuntu 8.04 live CD at my mothers house. ... On the live cd at my mothers house I used $ssh username@xxxxxxxxxxxxxxxxxxxxx, where username is my username on my home computer. ... # To enable empty passwords, ... # This is the ssh client system-wide configuration file. ...
      (Debian-User)