{"id":25,"date":"2012-01-06T10:40:59","date_gmt":"2012-01-06T10:40:59","guid":{"rendered":"http:\/\/news.innerfire.net\/?p=25"},"modified":"2018-07-25T15:29:16","modified_gmt":"2018-07-25T15:29:16","slug":"password-security","status":"publish","type":"post","link":"https:\/\/news.innerfire.net\/?p=25","title":{"rendered":"Password security"},"content":{"rendered":"<p>Weak passwords are still by far the most effective way to break into a system and even though many people think they have clever ways to obfuscate their passwords, they often fail badly either by inadvertently making something guessable or by coming up with something so hard you have to write it down somewhere or use a password manager just to use it.\u00a0 How bad is it?\u00a0 I have had 3 different techs assign me the same login &#8220;Gerhard&#8221; with password &#8220;G3rh4rd&#8221;\u00a0 and at an additional time someone even tried to be even more clever &#8220;G3h4rd!&#8221;\u00a0 This is bad.\u00a0 I know from experience that I can expect a password guessing script to hit my personal server at least 4 times daily.\u00a0 Originally the scripts all hit the ssh port until I took countermeasures but now they check every open port for possible password combinations from FTP to SASL to web logins and even with my countermeasures I can expect to have 1 or 2 accounts on my system cracked per year forcing me to disable someone&#8217;s website until they change their password again.<\/p>\n<p>How can we come up with a password that is both hard to guess and easy to remember?\u00a0 Thankfully it is easy.<\/p>\n<p>Take a couple of lines from a song you like but not the first lines and not the chorus.\u00a0 For example take this verse from a <a href=\"http:\/\/pdmusic.org\/1800s\/01etpr.txt\">Election&#8211;The People&#8217;s Right<\/a>\u00a0<sup>[1]<\/sup> written in 1801:<\/p>\n<blockquote><p>We should support and pleasure take<br \/>\nIn frequent Free Elections.<\/p><\/blockquote>\n<p>Now take the first letter of each word. &#8220;wssaptiffe&#8221;\u00a0 and there you go. The password is not an actual word so not likely to be hit by a dictionary attack but if you know the song you know your password so it&#8217;s easy to remember.\u00a0 One important note though: if ever the password was used on a website that got broken into you <strong>must<\/strong> assume the password is now added to several dictionaries for future attacks.<\/p>\n<p>[1] I selected this song because it was the first one I could find that was both out of copyright and readable.<\/p>\n<p>I feel this is important enough that I grant permission to republish this article provided a link to <a href=\"https:\/\/news.innerfire.net\">news.innerfire.net<\/a> stays with the article.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Weak passwords are still by far the most effective way to break into a system and even though many people think they have clever ways to obfuscate their passwords, they often fail badly either by inadvertently making something guessable or by coming up with something so hard you have to write it down somewhere or [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[],"class_list":["post-25","post","type-post","status-publish","format-standard","hentry","category-security"],"_links":{"self":[{"href":"https:\/\/news.innerfire.net\/index.php?rest_route=\/wp\/v2\/posts\/25","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/news.innerfire.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news.innerfire.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news.innerfire.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news.innerfire.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=25"}],"version-history":[{"count":13,"href":"https:\/\/news.innerfire.net\/index.php?rest_route=\/wp\/v2\/posts\/25\/revisions"}],"predecessor-version":[{"id":103,"href":"https:\/\/news.innerfire.net\/index.php?rest_route=\/wp\/v2\/posts\/25\/revisions\/103"}],"wp:attachment":[{"href":"https:\/\/news.innerfire.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=25"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news.innerfire.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=25"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news.innerfire.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=25"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}