 |
 |
 |
 |
| Security and Privacy Sadly, malware, spyware, hackers and privacy threats abound in today's world. Let's be paranoid and secure our penguins, and slam the doors on privacy exploits. |

18th May 2012, 11:12 AM
|
 |
Un-Retired Administrator
|
|
Join Date: Mar 2004
Location: Salem, Mass USA
Posts: 13,924

|
|
|
Changing all passwords
I just completed the self-imposed task of changing all passwords for all users (root + glenn) on all computers / all OS's. What a pain! Three computers, the desktop, the laptop and the server (another desktop). The server only boots Fedora 16 so that wasn't a big deal, however, the laptop and the desktop are both multi-boot with 4-8 OS's each! Crikey! I thought I'd never finish changing passwords.
Why did I do it? I've been using the same passwords for several years and thought it was time for newer and stronger passwords. It's a good thing I wrote both passwords on my forehead, backwards, with a sharpie because it is getting increasingly harder to remember things, not to mention the new passwords are considerably longer than the old ones were. Now, if I forget a password all I need to do is to go look in a mirror. Since they're written backwards no one else could ever figure out what they are, even though they're hidden in plain sight
So, how often do you change your passwords?
__________________
Glenn
The Bassinator © ®
Laptop: Toshiba Satellite / Intel Core 2 Duo 1.73 GHz / 2GB / 160GB / Intel Mobile 945GM/GMS/GME/943/940GML Integrated Graphics
Desktop: BioStar MCP6PB M2+ / AMD Phenom 9750 Quad Core / 4GB / 1TB SATA / 500GB SATA / EVGA GeForce 8400 GS 1GB
|

18th May 2012, 11:17 AM
|
 |
Administrator (yeah, back again)
|
|
Join Date: Jul 2004
Location: Colton, NY; Junction of Heaven & Earth (also Routes 56 & 68).
Age: 67
Posts: 21,202

|
|
|
Re: Changing all passwords
1996. If "they" haven't figured it out by now, it's because:
1). My passwords are far too clever and complex for hackers to break. Or...
2). They've broken them, checked my files and realized they've stolen trash.
__________________
Linux & Beer - That TOTALLY Computes!
Registered Linux User #362651
Don't use any of my solutions on working computers or near small children.
|

18th May 2012, 11:20 AM
|
 |
Banned (for/from) behaving just like everybody else!
|
|
Join Date: Jul 2007
Location: Beijing, China
Posts: 1,307

|
|
|
Re: Changing all passwords
I only change my password when I am told I must (e.g. the aftermath of Fedora build system breach, etc).
I think it's safe enough for most of my needs just to choose a long password and stick with that.
__________________
I believe in nerditarianism. I read FedoraForum for the Fedora-related posts.
|

18th May 2012, 11:41 AM
|
 |
Registered User
|
|
Join Date: Mar 2009
Location: Lancaster, UK
Posts: 883

|
|
|
Re: Changing all passwords
I usually change it 10 times every 450 or so days.
|

18th May 2012, 12:14 PM
|
 |
"Shells" (of a sub world)
|
|
Join Date: May 2011
Location: Helvetic Federation (Swissh)
Age: 33
Posts: 2,600

|
|
|
Re: Changing all passwords
I have a set of passwords, which each its own lifecycle of 1-4 years.
* Forums: 8 - 12 char pw
* root/admin OS: 12-20 chars
* user / dummy OS: 8-16 chars
* Emails: 8-18 chars
* mail lists: 8-12 chars
* (online) games: 8-18 chars
* social media 8-20 chars
Gotta say i like that link, ty Aleph: https://www.grc.com/haystack.htm
Code:
Online Attack Scenario:
(Assuming one thousand guesses per second) 12.13 trillion trillion centuries
Offline Fast Attack Scenario:
(Assuming one hundred billion guesses per second) 1.21 hundred thousand trillion centuries
Massive Cracking Array Scenario:
(Assuming one hundred trillion guesses per second) 1.21 hundred trillion centuries
__________________
Fedora Manual: http://docs.fedoraproject.org
Script-Tools: https://sourceforge.net/projects/script-tools/
sudo st tweak repo toggle fedora-rawhide ; st iso dl-fed -respin && st iso usb
|

18th May 2012, 12:18 PM
|
|
Registered User
|
|
Join Date: Aug 2009
Location: Waldorf, Maryland
Posts: 6,092

|
|
|
Re: Changing all passwords
Not very often. Cracking my passwords could be done, but they are of limited use, and don't get you anywhere (I don't trust banks), and I don't shop online (not directly anyway - use it for catalog/review, yes. Actual purchase - rarely, once every 3/4 years and those passwords, if any, are very different).
My method also obscures things. I like to use a phrase or sentence... but instead of using one letter from each word, I might use the first one, or two, or even three from each word.
BTW, you are not safe from the dyslexic - they just might read things backwards as forwards....
And don't forget the head banging moments - you might leave prints of the password in plaintext
Last edited by jpollard; 18th May 2012 at 12:20 PM.
|

18th May 2012, 01:01 PM
|
 |
Un-Retired Administrator
|
|
Join Date: Mar 2004
Location: Salem, Mass USA
Posts: 13,924

|
|
|
Re: Changing all passwords
I wonder how long password cracking would take if we applied it to the old TV game show "Password".
__________________
Glenn
The Bassinator © ®
Laptop: Toshiba Satellite / Intel Core 2 Duo 1.73 GHz / 2GB / 160GB / Intel Mobile 945GM/GMS/GME/943/940GML Integrated Graphics
Desktop: BioStar MCP6PB M2+ / AMD Phenom 9750 Quad Core / 4GB / 1TB SATA / 500GB SATA / EVGA GeForce 8400 GS 1GB
|

18th May 2012, 01:29 PM
|
|
Official Gnome 3 Sales Rep. (and Adminstrator)
|
|
Join Date: Jul 2011
Location: Leamington Spa, UK
Age: 30
Posts: 1,689

|
|
|
Re: Changing all passwords
Hardly ever. I've got a set of passwords of varying strengths that I use for systems/websites of different levels of security, and to my knowledge the stronger ones have never been broken or stolen (probably because it wouldn't be worth the effort and I never log in using untrusted machines).
I'm not at all convinced that constantly changing passwords and using passwords that can't be remembered really makes things more secure anyway; if there's something you need to protect that much, you need more than a mere password...
|

18th May 2012, 04:04 PM
|
 |
Formerly known as"professorrmd"
|
|
Join Date: Mar 2011
Posts: 2,603

|
|
|
Re: Changing all passwords
I change my password every six months or so. My passwords (for important accounts) are typically 10 characters or longer and the last time I setup my password, I used GRC (incidentally) to test the "strength" of a similar password .... That was fun!
The reason I change the password twice a year is because my work place mandates it and since I use "patterns", it is more convenient to change all passwords so that they all belong to the same "pattern".
Of course, none of these would stand key loggers - but then I use no computer other than my own - so ... haven't had problems .... yet!
|

19th May 2012, 11:20 AM
|
|
Registered User
|
|
Join Date: Jul 2009
Location: England, UK
Posts: 821

|
|
|
Re: Changing all passwords
Wow, people change their passwords!
I used to have to on the university network because passwords timed out after 90 days. All that meant was that the sys admins were bombarded constantly by users who were locked out because they couldn't remember the new password.
As another thought, could we ever implement a dynamic password system -- something where the user enters a bit they remember plus an easy (human-computable) hash of the current date? Would that be any more secure than a fixed password?
Or: the banks in the UK now all use little card readers to provide one-time codes for access to internet banking. Is there anything like that to replace static passwords?
|

20th May 2012, 02:53 AM
|
|
Registered User
|
|
Join Date: Aug 2009
Location: Waldorf, Maryland
Posts: 6,092

|
|
|
Re: Changing all passwords
Less secure.
And you are referring to the SecurID card - which requires a server to keep track of each card in use, and (due to clock sync problems) resynchronize the card when the clocks get too far apart.
SecurID has a PAM module for that.
The major problem is the expense. Each card costs between 30-75 dollars (US) depending on which version you buy.
Cheaper ones exist - Cryptocard for instance. But it works differently.
|
| Thread Tools |
Search this Thread |
|
|
|
| Display Modes |
Linear Mode
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
Current GMT-time: 08:35 (Sunday, 19-05-2013)
|
|
 |
 |
 |
 |
|
|