Go to Post We were the "oooh, neat, fire!" robot that year. - pfreivald [more]
Home
Go Back   Chief Delphi > ChiefDelphi.com Website > Extra Discussion
CD-Media   CD-Spy  
portal register members calendar search Today's Posts Mark Forums Read FAQ rules

 
Reply
 
Thread Tools Rate Thread Display Modes
  #1   Spotlight this post!  
Unread 15-06-2007, 09:09
DonRotolo's Avatar
DonRotolo DonRotolo is offline
Back to humble
FRC #0832
Team Role: Mentor
 
Join Date: Jan 2005
Rookie Year: 2005
Location: Atlanta GA
Posts: 6,979
DonRotolo has a reputation beyond reputeDonRotolo has a reputation beyond reputeDonRotolo has a reputation beyond reputeDonRotolo has a reputation beyond reputeDonRotolo has a reputation beyond reputeDonRotolo has a reputation beyond reputeDonRotolo has a reputation beyond reputeDonRotolo has a reputation beyond reputeDonRotolo has a reputation beyond reputeDonRotolo has a reputation beyond reputeDonRotolo has a reputation beyond repute
paper: Basic Password Security

Thread created automatically to discuss a document in CD-Media.

Basic Password Security by Don Rotolo
Reply With Quote
  #2   Spotlight this post!  
Unread 15-06-2007, 09:13
Jeff Rodriguez Jeff Rodriguez is offline
Too young to be an 'old guy'
FRC #0155 (Technonuts)
Team Role: Teacher
 
Join Date: Jun 2001
Rookie Year: 1999
Location: Newington, CT
Posts: 1,943
Jeff Rodriguez has a reputation beyond reputeJeff Rodriguez has a reputation beyond reputeJeff Rodriguez has a reputation beyond reputeJeff Rodriguez has a reputation beyond reputeJeff Rodriguez has a reputation beyond reputeJeff Rodriguez has a reputation beyond reputeJeff Rodriguez has a reputation beyond reputeJeff Rodriguez has a reputation beyond reputeJeff Rodriguez has a reputation beyond reputeJeff Rodriguez has a reputation beyond reputeJeff Rodriguez has a reputation beyond repute
Send a message via AIM to Jeff Rodriguez Send a message via Yahoo to Jeff Rodriguez
Re: paper: Basic Password Security

Good topic.
You may also want to listen to episode 4 of Security Now. They discuss this same topic and coming up with a personal password policy.
Edit: They talk more in episode 5 also.

Admittedly, I use about 3 or 4 passwords for all my different accounts. I'm going to try and come up with a good password policy.
__________________
173, student: 1999-2002
173, mentor: 2005-2010
155, teacher: 2011-

Last edited by Jeff Rodriguez : 15-06-2007 at 09:22.
Reply With Quote
  #3   Spotlight this post!  
Unread 15-06-2007, 09:21
vivek16's Avatar
vivek16 vivek16 is offline
Whoa! college pilot.
AKA: vivek
FRC #2264 (trojan robotics)
Team Role: Alumni
 
Join Date: Jan 2007
Rookie Year: 2007
Location: plymouth, minnesota
Posts: 1,227
vivek16 has a reputation beyond reputevivek16 has a reputation beyond reputevivek16 has a reputation beyond reputevivek16 has a reputation beyond reputevivek16 has a reputation beyond reputevivek16 has a reputation beyond reputevivek16 has a reputation beyond reputevivek16 has a reputation beyond reputevivek16 has a reputation beyond reputevivek16 has a reputation beyond reputevivek16 has a reputation beyond repute
Send a message via AIM to vivek16 Send a message via MSN to vivek16
Re: paper: Basic Password Security

brings up some good points. i personally have a weak password for all the sites that do not matter as much but i have a stronger form of it (using capitalization and numbers) for the websites like my email and stuff like that. i think i will change them.

thanks, vivek
Reply With Quote
  #4   Spotlight this post!  
Unread 15-06-2007, 10:17
GaryVoshol's Avatar
GaryVoshol GaryVoshol is offline
Cogito ergo arbitro
no team
 
Join Date: Aug 2005
Rookie Year: 2000
Location: Royal Oak, MI
Posts: 5,725
GaryVoshol has a reputation beyond reputeGaryVoshol has a reputation beyond reputeGaryVoshol has a reputation beyond reputeGaryVoshol has a reputation beyond reputeGaryVoshol has a reputation beyond reputeGaryVoshol has a reputation beyond reputeGaryVoshol has a reputation beyond reputeGaryVoshol has a reputation beyond reputeGaryVoshol has a reputation beyond reputeGaryVoshol has a reputation beyond reputeGaryVoshol has a reputation beyond repute
Re: paper: Basic Password Security

The problem of having a basic password with variations based on the site, account, etc is that some sites have their own rules for passwords. It must be exactly X characters long or some other such restriction. I like the concept though - I sure have difficulty remembering all my passwords when I go to pay my monthly bills online.
__________________
(since 2004)
Reply With Quote
  #5   Spotlight this post!  
Unread 15-06-2007, 10:38
Pavan Dave's Avatar
Pavan Dave Pavan Dave is offline
Busy in College
AKA: I am John Gault.
FRC #1745 (P-51 Mustangs) FRC #118 (Robonauts)
Team Role: Mentor
 
Join Date: Jan 2006
Rookie Year: 2006
Location: Richardson, Texas
Posts: 1,387
Pavan Dave has a reputation beyond reputePavan Dave has a reputation beyond reputePavan Dave has a reputation beyond reputePavan Dave has a reputation beyond reputePavan Dave has a reputation beyond reputePavan Dave has a reputation beyond reputePavan Dave has a reputation beyond reputePavan Dave has a reputation beyond reputePavan Dave has a reputation beyond reputePavan Dave has a reputation beyond reputePavan Dave has a reputation beyond repute
Send a message via AIM to Pavan Dave
Re: paper: Basic Password Security

Quote:
Originally Posted by GaryV1188 View Post
The problem of having a basic password with variations based on the site, account, etc is that some sites have their own rules for passwords. It must be exactly X characters long or some other such restriction. I like the concept though - I sure have difficulty remembering all my passwords when I go to pay my monthly bills online.
I've been using the same password since I started the internet and my father gave me my first E-mail account. Than for gaming i started using another set of passwords due to security reasons. I think now that I have quit gaming I need to mod up my regular passwords. I like the 'system' you mentioned. Its a great idea, and even if you have a 'core' word and you don't modify it between sites, at least remember there are different types of security involved with different types of sites. Although even if somebody gets your password on CD they can ruin your name, most of us might know who you are, or we have logs to check. But certain sites have strict systems of instant banning and at that, for many sites it is hard to vouch who you really are in the first place. And than don't get me started on your banks and other VERY important passwords. Those should be a class all of their own and should never be copied anywhere. That might be part of my system if I get tired of 100000 passwords: three or four levels of security requiring different types of passwords. EX: L1 - Same pass, L2 - Different but similar, L3 - Different, no link what so ever.

Also keep in mind that although it has been common for gaming and clans, there has been an exponential increase in the amount of brute force programs being created and being used, so keep that in mind next time you make your password, characters like "Æ, æ, ™ " are not usually put in those algorithms. For more information on ALT + NUM keys click here.


Peace.
__________________
Times change. People change. Teams change.
---
2008-Present: FRC1745, P51-Mustangs - Mentor
2005-2008: FRC118, Robonauts - Alumni
National Director of Philanthropy - Delta Epsilon Psi Fraternity, Inc.
1745 - 118 - ΔΕΨ

Last edited by Pavan Dave : 15-06-2007 at 10:40. Reason: Bolded Important Information
Reply With Quote
  #6   Spotlight this post!  
Unread 15-06-2007, 12:19
Travis Schuh Travis Schuh is offline
Registered User
FRC #0971 (Spartan Robotics)
Team Role: Engineer
 
Join Date: Dec 2006
Rookie Year: 1999
Location: Los Altos, CA
Posts: 123
Travis Schuh has a brilliant futureTravis Schuh has a brilliant futureTravis Schuh has a brilliant futureTravis Schuh has a brilliant futureTravis Schuh has a brilliant futureTravis Schuh has a brilliant futureTravis Schuh has a brilliant futureTravis Schuh has a brilliant futureTravis Schuh has a brilliant futureTravis Schuh has a brilliant futureTravis Schuh has a brilliant future
Re: paper: Basic Password Security

Quote:
Originally Posted by Pavan View Post

Also keep in mind that although it has been common for gaming and clans, there has been an exponential increase in the amount of brute force programs being created and being used, so keep that in mind next time you make your password, characters like "Æ, æ, ™ " are not usually put in those algorithms. For more information on ALT + NUM keys click here.
Thanks for the site. This opens up lots of new password opportunities, as now I can put in symbols formed by ALT + (Team number).

-Travis
Reply With Quote
  #7   Spotlight this post!  
Unread 15-06-2007, 14:18
Quzarx Quzarx is offline
Electrical/Programming
AKA: Kyle
FRC #1718 (The Fighting Pi)
Team Role: Electrical
 
Join Date: Feb 2006
Rookie Year: 2006
Location: Richmond, Michigan
Posts: 4
Quzarx is an unknown quantity at this point
Re: paper: Basic Password Security

I personally prefer using a md5 hash of an md5 hash of a word for my passwords. Yes, bit harder to memorize, but quite difficult to crack.
Such as, the md5 of "test"
098f6bcd4621d373cade4e832627b4f6
The md5 of that:
fb469d7ef430b0baf0cab6c436e70375
Reply With Quote
  #8   Spotlight this post!  
Unread 15-06-2007, 19:59
fimmel's Avatar
fimmel fimmel is offline
Founding Mentor, Team 2370
AKA: Forest Immel
FRC #2370 (iBots 2370)
Team Role: Mentor
 
Join Date: Dec 2005
Rookie Year: 2005
Location: Castleton, Vermont
Posts: 325
fimmel has a reputation beyond reputefimmel has a reputation beyond reputefimmel has a reputation beyond reputefimmel has a reputation beyond reputefimmel has a reputation beyond reputefimmel has a reputation beyond reputefimmel has a reputation beyond reputefimmel has a reputation beyond reputefimmel has a reputation beyond reputefimmel has a reputation beyond reputefimmel has a reputation beyond repute
Re: paper: Basic Password Security

Quote:
Originally Posted by Quzarx View Post
I personally prefer using a md5 hash of an md5 hash of a word for my passwords. Yes, bit harder to memorize, but quite difficult to crack.
Such as, the md5 of "test"
098f6bcd4621d373cade4e832627b4f6
The md5 of that:
fb469d7ef430b0baf0cab6c436e70375
i may try doing that. sounds like fun memorizing hashes.

also i set up a website one time and when i went into phpmyadmin to look at the user table. the passwords were in PLAIN TEXT. that means that any admin or even a hacker that got access to that table in the database would have all of the user names, passwords, emails etc of the users. anyway i decided to not use that script for the login.

/forest
__________________



Reply With Quote
  #9   Spotlight this post!  
Unread 16-06-2007, 14:36
DonRotolo's Avatar
DonRotolo DonRotolo is offline
Back to humble
FRC #0832
Team Role: Mentor
 
Join Date: Jan 2005
Rookie Year: 2005
Location: Atlanta GA
Posts: 6,979
DonRotolo has a reputation beyond reputeDonRotolo has a reputation beyond reputeDonRotolo has a reputation beyond reputeDonRotolo has a reputation beyond reputeDonRotolo has a reputation beyond reputeDonRotolo has a reputation beyond reputeDonRotolo has a reputation beyond reputeDonRotolo has a reputation beyond reputeDonRotolo has a reputation beyond reputeDonRotolo has a reputation beyond reputeDonRotolo has a reputation beyond repute
Re: paper: Basic Password Security

Quote:
Originally Posted by GaryV1188 View Post
It must be exactly X characters long or some other such restriction. I like the concept though - I sure have difficulty remembering all my passwords when I go to pay my monthly bills online.
Yep, there might be some excpetions - but I never have trouble remembering any of my passwords, so far...
Quote:
Originally Posted by Pavan View Post
even if somebody gets your password on CD they can ruin your name
Yes, and if you're dumb enough to use the same password for everything, they can do quite a bit more... Maybe not to a high school kid, but think mid-life engineer and what "ruined" might entail.

Also, with no extra effort - actually less effort than your layer system - you can use strong and unique passwords everywhere. Why not then?
Quote:
Originally Posted by Quzarx View Post
I personally prefer using a md5 hash of an md5 hash of a word for my passwords.
You, my friend, win the Uber-geek award for today.
(Anyone who knows what he means is a runner-up)

Don
__________________

I am N2IRZ - What's your callsign?
Reply With Quote
  #10   Spotlight this post!  
Unread 16-06-2007, 19:48
Protronie's Avatar
Protronie Protronie is offline
Have big wrench...and will use it!
no team
 
Join Date: Dec 2006
Rookie Year: 2006
Location: North Carolina
Posts: 617
Protronie has much to be proud ofProtronie has much to be proud ofProtronie has much to be proud ofProtronie has much to be proud ofProtronie has much to be proud ofProtronie has much to be proud ofProtronie has much to be proud ofProtronie has much to be proud of
Send a message via ICQ to Protronie Send a message via Yahoo to Protronie
Re: paper: Basic Password Security

I don't care how "strong" a password you use... if someone wants the info enough they will get it. There are always backdoors the industry and government agencies have embedded into your O/S.

If theres something you don't want someone to see... don't trust it to the internet or a computer thats hooked up to it.
__________________
Protronie rule 5 - When the big wrench starts swinging, get out of the way!
Reply With Quote
Reply


Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
paper: Basic Tagging Guide to CD-Media (Pictures) Michelle Celio Extra Discussion 9 23-07-2006 16:40
White Paper Discuss: Basic PHP Tutorial AIBob Extra Discussion 0 07-03-2005 15:11
White Paper Discuss: Basic HTML Tutorial AIBob Extra Discussion 2 13-02-2005 20:49
White Paper Discuss: 2004 Visual Basic 6 Dashboard Control CD47-Bot Extra Discussion 2 01-02-2005 01:56


All times are GMT -5. The time now is 01:10.

The Chief Delphi Forums are sponsored by Innovation First International, Inc.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2017, Jelsoft Enterprises Ltd.
Copyright © Chief Delphi