How to choose a secure password

General conversation and chit chat - The place for non-shooting specific topics. Introduce yourself here.

How to choose a secure password

Post by Aster » 28 Aug 2014, 3:31 pm

We've had an instance of a members account being compromised - due to a weak password rather than any vulnerability of the site - so I thought a note on passwords is in order.

For the record: The site as a whole is backed up and protected, individual accounts are not. In the event that the whole site was compromised/brought down it would just be restored from a backup and business would continue as normal.

If someone accesses your account and deletes/edits your content as a logged in user it can not be restored. If someone uses your account to create large amount of spam content or messages the most viable solution at our end may be to delete the account to remove all offending content automatically.

As far as passwords go, they don't have to be nuclear launch codes but seemingly small additions increase the difficulty of cracking it exponentially. Some examples and thoughts on this:

Dictionary based passwords;
You'd be amazed how many people actually try to set their password as "password" or "secret" or something else painfully obvious. Obviously this isn't secure. If it's a common word or the kind of word you quickly came to when thinking of a password, it will quickly come to others as well. One practice for breaking into systems is to get a list of user accounts (your forum name which is publicly visible) and apply login attempts using a list of 10 most commonly used passwords. Don't use one of them.

Using at least a mixture of letters and number is desirable, and if you want to "go nuclear" with your password, used mixed case and symbols. To give you an idea, the following number of combinations are possible using the characters listed.

Numeric passwords (0-9 only) e.g 456132;
1,000,000 combinations are possible. Not a small number but with persistence they can be broken. More often than not people choose sequential formats as well like 345678 which are tried first and easily found.

Alpha passwords (a-z only) e.g ajbhgn;
308,915,776 combinations are possible.

Alphanumeric passwords (0-9 + letters a-z) e.g f7rgh4.
2,176,782,336 combinations are possible. A short combination of letters and numbers should be no more difficult to remember than any of the above weaker options. This is my recommended format for choosing a password without...

Going nuclear;

Case sensitive alphanumeric passwords e.g. F6hJ35
56,800,235,584 combinations are possible. Even better than the above.

Case sensitive alphanumeric passwords with symbols e.g. b%7Xd(
689,869,781,056 combinations are possible.

Huge numbers of combinations and these are only using 6 character passwords. If you password is 8 or 10 or more characters the combinations start getting bigger than I care to type out.

You get the idea.

So if your password is currently "password" or "password1", go and change it :P
See you on the firing line.
User avatar
Aster
Moderator
 
-

Re: How to choose a secure password

Post by greyghost » 28 Aug 2014, 4:19 pm

Just for fun, the forum password limit is 20 characters? How many combos if you do the last nuclear option with 20 characters? :lol:
Browning BLR .223
Sako 98 .270
User avatar
greyghost
Private
Private
 
Posts: 75
Queensland

Re: How to choose a secure password

Post by Aster » 28 Aug 2014, 4:21 pm

With a 20 character case sensitive alphanumeric password with symbols there are...

2,901,062,411,314,618,233,730,627,546,741,369,470,976 combinations.

Probably overkill...
See you on the firing line.
User avatar
Aster
Moderator
 
-

Re: How to choose a secure password

Post by Die Judicii » 28 Aug 2014, 9:25 pm

Good article Aster,

Really makes one think,,,, Why is it that Banks still persist with a basic 4 digit password at the ATMs ???

:roll: :roll: :roll:
I do not fear death itself... Only its inopportune timing!
I've come to realize that,,,,, the two most loving, loyal, and trustworthy females in my entire life were both canines.
User avatar
Die Judicii
Colonel
Colonel
 
Posts: 3729
Queensland

Re: How to choose a secure password

Post by dustin » 29 Aug 2014, 7:34 am

Aster wrote:With a 20 character case sensitive alphanumeric password with symbols there are...

2,901,062,411,314,618,233,730,627,546,741,369,470,976 combinations.


:lol:

Is that for real, or did you just mash the keyboard a bunch of times :D
User avatar
dustin
Private
Private
 
Posts: 92
New South Wales

Re: How to choose a secure password

Post by Aster » 29 Aug 2014, 7:37 am

Die Judicii wrote:Really makes one think,,,, Why is it that Banks still persist with a basic 4 digit password at the ATMs ???


It's definitely not what I'd call iron clad.

An extra couple of numbers there would do a lot.
See you on the firing line.
User avatar
Aster
Moderator
 
-

Re: How to choose a secure password

Post by Aster » 29 Aug 2014, 7:37 am

Dustin,

That's the real number ;)
See you on the firing line.
User avatar
Aster
Moderator
 
-

Re: How to choose a secure password

Post by disko » 29 Aug 2014, 5:27 pm

dustin wrote:Is that for real, or did you just mash the keyboard a bunch of times :D


It's not like anyone's going to check his math. Easily could have just made this up and saved the effort of working it out :lol:
Meopta Meopro 4-12x50mm on Fluted Howa Sporter.
.308 Winchester.
User avatar
disko
Private
Private
 
Posts: 60
Victoria

Re: How to choose a secure password

Post by 1290 » 29 Aug 2014, 7:28 pm

Someone found the nPr button on the casio! !! ;)
User avatar
1290
Warrant Officer C1
Warrant Officer C1
 
Posts: 1336
Victoria

Re: How to choose a secure password

Post by Aster » 30 Aug 2014, 8:25 am

1290 wrote:Someone found the nPr button on the casio! !! ;)


Nah all done in my head. Honestly... :ugeek:

*glances around conspicuously*
See you on the firing line.
User avatar
Aster
Moderator
 
-

Re: How to choose a secure password

Post by ailar » 30 Aug 2014, 8:27 am

Ok, now I can tell my mate who uses like 25 long passwords for his work computer screensaver he's officially being a tosser :lol:
User avatar
ailar
Recruit
Recruit
 
Posts: 48
Tasmania

Re: How to choose a secure password

Post by huccl » 30 Aug 2014, 8:29 am

Aster wrote:Nah all done in my head. Honestly... :ugeek:

*glances around conspicuously*


My head would explode with just doing it on the calculator :lol:
Browning A-Bolt M-1000 Eclipse 308 Win
CZ 453 Varmint 22LR
User avatar
huccl
Lance Corporal
Lance Corporal
 
Posts: 213
New South Wales

Re: How to choose a secure password

Post by inervate » 30 Aug 2014, 11:36 am

Aster wrote:So if your password is currently "password" or "password1", go and change it :P


Hu hu, huuu, Yeah. Only and idiot would use something like that.

:oops:

:lol:
Weatherby Varmintmaster .224 Wby Mag
Tikka T3 Hunter Fluted 30-06
Marlin 57M Levermatic .22 Win Mag
User avatar
inervate
Private
Private
 
Posts: 73
Victoria

Re: How to choose a secure password

Post by Aster » 30 Aug 2014, 11:37 am

There's always one :P
See you on the firing line.
User avatar
Aster
Moderator
 
-

Re: How to choose a secure password

Post by Redwood » 02 Apr 2015, 9:19 am

I'll admit I've been caught out with lazy passwords before. My own stupid fault and cost me a few bucks and some grief.

8 random symbols isn't much to remember. Turns out I picked a good set :D
Redwood
Lance Corporal
Lance Corporal
 
Posts: 152
Victoria


Back to top
 
Return to Off topic - General conversation