Fedora Linux Support Community & Resources Center

Go Back   FedoraForum.org > Fedora 17/18 > Security and Privacy
FedoraForum Search

Forgot Password? Join Us!

Security and Privacy Sadly, malware, spyware, hackers and privacy threats abound in today's world. Let's be paranoid and secure our penguins, and slam the doors on privacy exploits.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 18th May 2012, 11:12 AM
glennzo's Avatar
glennzo Online
Un-Retired Administrator
 
Join Date: Mar 2004
Location: Salem, Mass USA
Posts: 13,924
linuxfirefox
Changing all passwords

I just completed the self-imposed task of changing all passwords for all users (root + glenn) on all computers / all OS's. What a pain! Three computers, the desktop, the laptop and the server (another desktop). The server only boots Fedora 16 so that wasn't a big deal, however, the laptop and the desktop are both multi-boot with 4-8 OS's each! Crikey! I thought I'd never finish changing passwords.

Why did I do it? I've been using the same passwords for several years and thought it was time for newer and stronger passwords. It's a good thing I wrote both passwords on my forehead, backwards, with a sharpie because it is getting increasingly harder to remember things, not to mention the new passwords are considerably longer than the old ones were. Now, if I forget a password all I need to do is to go look in a mirror. Since they're written backwards no one else could ever figure out what they are, even though they're hidden in plain sight

So, how often do you change your passwords?
__________________
Glenn
The Bassinator © ®


Laptop: Toshiba Satellite / Intel Core 2 Duo 1.73 GHz / 2GB / 160GB / Intel Mobile 945GM/GMS/GME/943/940GML Integrated Graphics
Desktop: BioStar MCP6PB M2+ / AMD Phenom 9750 Quad Core / 4GB / 1TB SATA / 500GB SATA / EVGA GeForce 8400 GS 1GB
Reply With Quote
  #2  
Old 18th May 2012, 11:17 AM
bob's Avatar
bob Offline
Administrator (yeah, back again)
 
Join Date: Jul 2004
Location: Colton, NY; Junction of Heaven & Earth (also Routes 56 & 68).
Age: 67
Posts: 21,202
linuxfirefox
Re: Changing all passwords

1996. If "they" haven't figured it out by now, it's because:

1). My passwords are far too clever and complex for hackers to break. Or...

2). They've broken them, checked my files and realized they've stolen trash.
__________________
Linux & Beer - That TOTALLY Computes!
Registered Linux User #362651


Don't use any of my solutions on working computers or near small children.
Reply With Quote
  #3  
Old 18th May 2012, 11:20 AM
aleph's Avatar
aleph Offline
Banned (for/from) behaving just like everybody else!
 
Join Date: Jul 2007
Location: Beijing, China
Posts: 1,307
linuxfirefox
Re: Changing all passwords

I only change my password when I am told I must (e.g. the aftermath of Fedora build system breach, etc).

I think it's safe enough for most of my needs just to choose a long password and stick with that.
__________________
I believe in nerditarianism. I read FedoraForum for the Fedora-related posts.
Reply With Quote
  #4  
Old 18th May 2012, 11:41 AM
Adunaic's Avatar
Adunaic Offline
Registered User
 
Join Date: Mar 2009
Location: Lancaster, UK
Posts: 883
linuxfirefox
Re: Changing all passwords

I usually change it 10 times every 450 or so days.
Reply With Quote
  #5  
Old 18th May 2012, 12:14 PM
sea's Avatar
sea Offline
"Shells" (of a sub world)
 
Join Date: May 2011
Location: Helvetic Federation (Swissh)
Age: 33
Posts: 2,600
linuxchrome
Re: Changing all passwords

I have a set of passwords, which each its own lifecycle of 1-4 years.
* Forums: 8 - 12 char pw
* root/admin OS: 12-20 chars
* user / dummy OS: 8-16 chars
* Emails: 8-18 chars
* mail lists: 8-12 chars
* (online) games: 8-18 chars
* social media 8-20 chars

Gotta say i like that link, ty Aleph: https://www.grc.com/haystack.htm
Code:
Online Attack Scenario:
(Assuming one thousand guesses per second)	        12.13 trillion trillion centuries
Offline Fast Attack Scenario:
(Assuming one hundred billion guesses per second)	1.21 hundred thousand trillion centuries
Massive Cracking Array Scenario:
(Assuming one hundred trillion guesses per second)	1.21 hundred trillion centuries
__________________
Fedora Manual: http://docs.fedoraproject.org
Script-Tools: https://sourceforge.net/projects/script-tools/
sudo st tweak repo toggle fedora-rawhide ; st iso dl-fed -respin && st iso usb
Reply With Quote
  #6  
Old 18th May 2012, 12:18 PM
jpollard Offline
Registered User
 
Join Date: Aug 2009
Location: Waldorf, Maryland
Posts: 6,092
linuxfirefox
Re: Changing all passwords

Not very often. Cracking my passwords could be done, but they are of limited use, and don't get you anywhere (I don't trust banks), and I don't shop online (not directly anyway - use it for catalog/review, yes. Actual purchase - rarely, once every 3/4 years and those passwords, if any, are very different).

My method also obscures things. I like to use a phrase or sentence... but instead of using one letter from each word, I might use the first one, or two, or even three from each word.

BTW, you are not safe from the dyslexic - they just might read things backwards as forwards....

And don't forget the head banging moments - you might leave prints of the password in plaintext

Last edited by jpollard; 18th May 2012 at 12:20 PM.
Reply With Quote
  #7  
Old 18th May 2012, 01:01 PM
glennzo's Avatar
glennzo Online
Un-Retired Administrator
 
Join Date: Mar 2004
Location: Salem, Mass USA
Posts: 13,924
windows_xp_2003chrome
Re: Changing all passwords

I wonder how long password cracking would take if we applied it to the old TV game show "Password".
__________________
Glenn
The Bassinator © ®


Laptop: Toshiba Satellite / Intel Core 2 Duo 1.73 GHz / 2GB / 160GB / Intel Mobile 945GM/GMS/GME/943/940GML Integrated Graphics
Desktop: BioStar MCP6PB M2+ / AMD Phenom 9750 Quad Core / 4GB / 1TB SATA / 500GB SATA / EVGA GeForce 8400 GS 1GB
Reply With Quote
  #8  
Old 18th May 2012, 01:29 PM
Gareth Jones Offline
Official Gnome 3 Sales Rep. (and Adminstrator)
 
Join Date: Jul 2011
Location: Leamington Spa, UK
Age: 30
Posts: 1,689
linuxfirefox
Re: Changing all passwords

Hardly ever. I've got a set of passwords of varying strengths that I use for systems/websites of different levels of security, and to my knowledge the stronger ones have never been broken or stolen (probably because it wouldn't be worth the effort and I never log in using untrusted machines).

I'm not at all convinced that constantly changing passwords and using passwords that can't be remembered really makes things more secure anyway; if there's something you need to protect that much, you need more than a mere password...
Reply With Quote
  #9  
Old 18th May 2012, 04:04 PM
nonamedotc's Avatar
nonamedotc Offline
Formerly known as"professorrmd"
 
Join Date: Mar 2011
Posts: 2,603
linuxfirefox
Re: Changing all passwords

I change my password every six months or so. My passwords (for important accounts) are typically 10 characters or longer and the last time I setup my password, I used GRC (incidentally) to test the "strength" of a similar password .... That was fun!

The reason I change the password twice a year is because my work place mandates it and since I use "patterns", it is more convenient to change all passwords so that they all belong to the same "pattern".

Of course, none of these would stand key loggers - but then I use no computer other than my own - so ... haven't had problems .... yet!
Reply With Quote
  #10  
Old 19th May 2012, 11:20 AM
marriedto51 Offline
Registered User
 
Join Date: Jul 2009
Location: England, UK
Posts: 821
linuxfirefox
Re: Changing all passwords

Wow, people change their passwords!

I used to have to on the university network because passwords timed out after 90 days. All that meant was that the sys admins were bombarded constantly by users who were locked out because they couldn't remember the new password.

As another thought, could we ever implement a dynamic password system -- something where the user enters a bit they remember plus an easy (human-computable) hash of the current date? Would that be any more secure than a fixed password?

Or: the banks in the UK now all use little card readers to provide one-time codes for access to internet banking. Is there anything like that to replace static passwords?
Reply With Quote
  #11  
Old 20th May 2012, 02:53 AM
jpollard Offline
Registered User
 
Join Date: Aug 2009
Location: Waldorf, Maryland
Posts: 6,092
linuxfirefox
Re: Changing all passwords

Less secure.

And you are referring to the SecurID card - which requires a server to keep track of each card in use, and (due to clock sync problems) resynchronize the card when the clocks get too far apart.

SecurID has a PAM module for that.

The major problem is the expense. Each card costs between 30-75 dollars (US) depending on which version you buy.

Cheaper ones exist - Cryptocard for instance. But it works differently.
Reply With Quote
Reply

Tags
changing, passwords

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
changing passwords jasmine Using Fedora 8 16th February 2009 01:55 AM
Users passwords keep changing?? daviddoria Using Fedora 6 5th January 2008 10:17 PM
Passwords passwords passwords! Jack.Straw Using Fedora 6 18th August 2006 06:58 PM
SMB with passwords pHx Servers & Networking 25 5th July 2005 07:16 PM
smbpasswd errors prevent changing passwords sstrong Servers & Networking 6 2nd September 2004 06:01 PM


Current GMT-time: 08:35 (Sunday, 19-05-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat