Sunday 14 July 2013

How elite security ninjas choose & safeguard their passwords

Security on the Internet: boring, often ignored, but too important to leave like that. This article includes links to other important Internet security related articles.

http://arstechnica.com/security/2013/07/how-elite-security-ninjas-choose-and-safeguard-their-passwords/ / feature hack hacker hacking hacked password crackers ransack long passwords numbers symbols punctuation upper-case lower-case upper lower case letters crack brea users password manager random randomly generate store long complex passcodes unique each site primer required reading Internet password security competing strategies contradictory imperatives encrypted password file cloud browser frequently used log-in credentials manage passwords variety computer operating systems different smartphone platforms checked five security experts learn approach choosing storing crack-resistant crack resistant passwords renowned cryptographer Bruce Schneier security futurologist BT Electronic Frontier Foundation board directors Adriel T. Desautels CEO Netragard firm gets paid hack large companies Jeremiah Grossman founder CTO WhiteHat Security;Jeffrey Goldberg defender against the dark arts AgileBits company develops developer develop developed 1Password password manager Jeremi Gosney password security expert Stricture Consulting experts password manager long complex unique password accounts variation store stores passwords plain text file stored encrypted virtual disk image physically encrypted USB key flash drive memory stick capable secure secured securing physical digita use plug copy and space paste copy-paste device LastPass KeePass dedicated managers home-made solution automatically generate random passwords meet specific site criteria maximum length passcodes do not don't contain special characters generate passwords banging on the keyboard random length letters number symbol cap very strong password storage strategy recall remember generate store most important passwords different products synchronizes passwords across major platforms he uses only exception FreeBSD systems Web browsing copy/pasting copy pasting paste SSH window PasswordSafe application develop LastPass memory recall remembering remember proximity tokens token one time one-time passwords log-in log in computer services offer password management built technology vulnerable at some level trust technology sensitive credentials choice use different passwords for each account passwords long as possible keeping easy for me to remember longest password 63 characters long benefits of a password manager in favor of passcodes that are easier to remember pick picking long memorable sentence blog post password cracking feature crackers word lists write passwords wallet other safe location diceware spaces specific password policy prevents prevent prevention strong strength something random process roll dice electronic equivalent word list external random process random number generator rolling dice misspell words long random randomness randomly generated passwords twenty three 23 characters character small smaller maximum truly randomly length guesses 128 bit 128-bit encryption key stronger several different common basewords various transformations applied sufficiently unique challenge synchronizing passcodes pass code codes across multiple devices run different platforms stated earlier tackles response challenge Windows Macintosh Mac OS X iOS Android operating systems system OS LastPass Linux iOS Android Windows Phone Blackberry advanced sync synchronisation synchronise synchronization synchronize settings in the Google Chrome browser encrypt encrypts saved passwords local database sync passwords Google account configured Chrome encrypt synced data separate sync password instead /