<?xml version="1.0"?>
<rss version="2.0"><channel><title/><link>https://www.edugeek.net/blogs/blog/1415-nervepoint-technologies/</link><description/><language>en</language><item><title>Password Security Tips From a Hacker</title><link>https://www.edugeek.net/blogs/entry/880-password-security-tips-from-a-hacker/</link><description><![CDATA[<p>It's amazing just how easy it is to crack passwords these days, Nate  Anderson from ArsTechnica a self confessed script-kiddie shows in his <a href="http://arstechnica.com/security/2013/03/how-i-became-a-password-cracker" rel="external nofollow">article</a> just how easy it was to crack 4,000 passwords in the space of a minute!</p><p> </p><p>
We all know how to build complex passwords:</p><p> </p><p> </p><p>
</p><ul><li>Include mixed cases, letters, number, symbols <br />
</li><li>Change passwords regularly <br />
</li><li>Avoid names especially of people you know <br />
</li><li>And don't repeat old passwords <br />
</li></ul><p></p><p> </p><p>
All the things you would find in a good AD password policy</p><p> </p><p>
After ArsTechnica's article there are probably a few more items you should add to that list next time you change your password.</p><p> </p><p>
 <strong>The Long and Short</strong></p><p>
The experiment that Nate ran initially was focused on passwords of no  more than 6 characters which he pretty much cracked in seconds  regardless of adding symbols and mixed cases. But as the length of the  passwords increased so to did the time. The chart below shows how a  simple thing as increasing the length of a password from 6 characters to  9 dramatically increased the time taken to hack 17000 passwords using  brute-force.</p><p>
 <a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2013_07/cracking3.png.c88f6c412265ec2685f4c7360052d5f0.png" data-fileid="239" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="cracking3.thumb.png.4831f382ece27d13173ccae63d7e2df4.png" data-fileid="239" data-src="https://www.edugeek.net/uploads/monthly_2025_03/cracking3.thumb.png.4831f382ece27d13173ccae63d7e2df4.png" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p> </p><p>
Avoid the pitfalls of small simple to remember passwords, long ones can be just as easy to remember.</p><p> </p><p>
 <strong>Its all in the Patterns</strong></p><p>
One of the interesting points in the article is that hacking relies on  patterns. Adding numbers and symbols you might think will help but if  you stick to a common pattern for your passwords it really makes little  difference. Avoid using typical password patterns like &lt;word&gt;+&lt;3 numbers&gt; or following the same one  as your colleagues, once a hacker knows the pattern of one password  they can pretty much expect all other accounts to follow the same rules.</p><p> </p><p>
 <strong>Expanding Pool of Words</strong></p><p>
The number of words in the Oxford English dictionary exceeds well over  100,000 but the words used in most passwords is limited to a small  subset of this the same set you'll find in wordlists used by hacking  tools. Avoid using common everyday words, consider words that are not  common, everyday words.</p><p>
 </p><p><strong>
Getting Everyone On-Board</strong></p><p>
Its all too common to find only some end users following password  policies and it's usually the ones that don't who have the most to lose.  If you're having trouble convincing people then show them how quickly  these guys were able to hack <a href="http://arstechnica.com/security/2013/05/how-crackers-make-minced-meat-out-of-your-passwords/" rel="external nofollow">16,000 passwords</a>! Getting everyone's buy-in on using more complex password policies improves your network security and your users all round.</p>]]></description><guid isPermaLink="false">880</guid><pubDate>Fri, 12 Jul 2013 14:02:15 +0000</pubDate></item><item><title>Password Security Tips From a Hacker</title><link>https://www.edugeek.net/blogs/entry/879-password-security-tips-from-a-hacker/</link><description><![CDATA[<p>It's amazing just how easy it is to crack passwords these days, Nate Anderson from ArsTechnica a self confessed script-kiddie shows in his <a href="http://arstechnica.com/security/2013/03/how-i-became-a-password-cracker" rel="external nofollow">article</a> just how easy it was to crack 4,000 passwords in the space of a minute!</p><p> </p><p>
We all know how to build complex passwords:</p><p> </p><p> </p><p>
</p><ul><li>Include mixed cases, letters, number, symbols <br />
</li><li>Change passwords regularly <br />
</li><li>Avoid names especially of people you know <br />
</li><li>And don't repeat old passwords <br />
</li></ul><p></p><p> </p><p>
All the things you would find in a good AD password policy</p><p> </p><p>
After ArsTechnica's article there are probably a few more items you should add to that list next time you change your password.</p><p> </p><p>
<strong>The Long and Short</strong></p><p>
The experiment that Nate ran initially was focused on passwords of no more than 6 characters which he pretty much cracked in seconds regardless of adding symbols and mixed cases. But as the length of the passwords increased so to did the time. The chart below shows how a simple thing as increasing the length of a password from 6 characters to 9 dramatically increased the time taken to hack 17000 passwords using brute-force.</p><p>
[ATTACH=CONFIG]19475[/ATTACH]</p><p> </p><p>
Avoid the pitfalls of small simple to remember passwords, long ones can be just as easy to remember.</p><p> </p><p>
<strong>Its all in the Patterns</strong></p><p>
One of the interesting points in the article is that hacking relies on patterns. Adding numbers and symbols you might think will help but if you stick to a common pattern for your passwords it really makes little difference. Avoid using typical password patterns like &lt;word&gt;+&lt;3 numbers&gt; or following the same one as your colleagues, once a hacker knows the pattern of one password they can pretty much expect all other accounts to follow the same rules.</p><p> </p><p>
<strong>Expanding Pool of Words</strong></p><p>
The number of words in the Oxford English dictionary exceeds well over 100,000 but the words used in most passwords is limited to a small subset of this the same set you'll find in wordlists used by hacking tools. Avoid using common everyday words, consider words that are not common, everyday words.</p><p>
</p><p><strong>
Getting Everyone On-Board</strong></p><p>
Its all too common to find only some end users following password policies and it's usually the ones that don't who have the most to lose. If you're having trouble convincing people then show them how quickly these guys were able to hack <a href="http://arstechnica.com/security/2013/05/how-crackers-make-minced-meat-out-of-your-passwords/" rel="external nofollow">16,000 passwords</a>! Getting everyone's buy-in on using more complex password policies improves your network security and your users all round.</p><p> </p><p>
Connect with us on <a href="http://www.linkedin.com/company/nervepoint-technologies-limited" rel="external nofollow">LinkedIn</a>, <a href="http://www.spiceworks.com/nervepointtechnologies" rel="external nofollow">Spiceworks</a>, <a href="https://www.facebook.com/NervepointTechnologies" rel="external nofollow">Facebook</a>, <a href="http://twitter.com/NervepointTech" rel="external nofollow">Twitter</a> or <a href="http://plus.google.com/103508159172539405640/" rel="external nofollow">Google+</a></p>]]></description><guid isPermaLink="false">879</guid><pubDate>Thu, 11 Jul 2013 19:18:34 +0000</pubDate></item></channel></rss>
