Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

The Password Pandemic: A password “classification scheme” for the home or small business user
Stronghold Cyber Security ^ | November 13, 2017 | Jason McNew

Posted on 11/13/2017 8:22:15 AM PST by Gennie

Humanity has a massive password problem. We might call it The Password Pandemic. Computers keep getting faster and cheaper, making passwords easier to crack, while human operators do not change their bad password habits. This is a losing proposition, with the advantage clearly toward hackers and cyber criminals.

Most users of the Internet now know that they need to use “strong” passwords, and that they should use a different password for each site. With a dozen or several dozen online accounts, this quickly becomes unmanageable. Exasperated, people just use the same (usually weak) password across several accounts. Hackers know this, and take full advantage. This is why “password dumps” are so useful to cyber criminals.

(Excerpt) Read more at strongholdcybersecurity.com ...


TOPICS: Business/Economy; Computers/Internet; Miscellaneous
KEYWORDS: cyber; hackers; hacking; internet; passwords; security; tech; windows
Navigation: use the links below to view more comments.
first 1-2021-36 next last
This is a good overview on how to create passwords for different types of online accounts.
1 posted on 11/13/2017 8:22:15 AM PST by Gennie
[ Post Reply | Private Reply | View Replies]

To: Gennie
I finally got a password management tool, LastPass, and it's wonderful. You can use it to generate a long random password for every account. At the very least, it's easy to set up a different (and less random) password for each account.

LastPass
2 posted on 11/13/2017 8:27:28 AM PST by CatQuilt (Lover of cats =^..^= and quilts)
[ Post Reply | Private Reply | To 1 | View Replies]

To: CatQuilt

Link doesn’t work.

Are your LastPass passwords in the cloud? If so, what if your main password to your account is compromised and then changed? Then what?

Just asking.


3 posted on 11/13/2017 8:32:35 AM PST by Perseverando (For Progressives, Islamonazis & other Totalitarians: It's all about PEOPLE CONTROL!)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Perseverando

Get a password manager and change your life.

I don’t even know my passwords anymore. Just the main one - which I tell to nobody. Use Ben Franklin’s aphorism, “Three can keep a secret if two of them are dead”


4 posted on 11/13/2017 8:38:23 AM PST by glorgau
[ Post Reply | Private Reply | To 3 | View Replies]

To: glorgau

I’ve been using Norton Security’s Identity Safe for at least 5 years. However I have refrained from using the cloud option so far. I want to keep my PW’s on my PC.

I’m inclined to believe the theory that “if it’s in the cloud, is it really yours?”


5 posted on 11/13/2017 8:45:58 AM PST by Perseverando (For Progressives, Islamonazis & other Totalitarians: It's all about PEOPLE CONTROL!)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Gennie

Password Bookmark


6 posted on 11/13/2017 8:47:59 AM PST by jonno (Having an opinion is not the same as having the answer...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Gennie

Of course really smart people like John Podesta create passwords which are impossible to guess or crack.


7 posted on 11/13/2017 8:53:41 AM PST by Verginius Rufus
[ Post Reply | Private Reply | To 1 | View Replies]

To: Gennie

I have a system that remains somewhat random, some things stay the same, other things change for each site and capitalization changes.

If I forget which variation I have used on that site I have just 4 alternatives to check out.


8 posted on 11/13/2017 8:54:21 AM PST by tiki
[ Post Reply | Private Reply | To 1 | View Replies]

To: Perseverando

Don’t forget - ‘The Cloud is just someone else’s computer.’ haha


9 posted on 11/13/2017 8:54:35 AM PST by bboop (does not suffer fools gladly)
[ Post Reply | Private Reply | To 3 | View Replies]

To: bboop

My system - 3 or 4 weak passwords with variations that I can never remember. I write them on a piece of paper and put them in a manila folder. Total Chaos. However, I believe that others, including my scientist husband, us a variation of the same. Oh, and I curse a lot.


10 posted on 11/13/2017 8:56:22 AM PST by bboop (does not suffer fools gladly)
[ Post Reply | Private Reply | To 9 | View Replies]

To: glorgau

I’m partial to this password manager:

https://www.pwsafe.org/


11 posted on 11/13/2017 8:57:12 AM PST by kosciusko51
[ Post Reply | Private Reply | To 4 | View Replies]

To: Gennie

Even NIST now recommends permanent pass phrases as opposed to the typical corporate “8-14 character with caps and specials” changed every 30-90 days.

https://pages.nist.gov/800-63-3/sp800-63-3.html

And you can run crack progs against your own phrases to see how secure they are before you put them in use.


12 posted on 11/13/2017 8:59:59 AM PST by DBG8489
[ Post Reply | Private Reply | To 1 | View Replies]

To: glorgau

I use a pw manager and it is great.


13 posted on 11/13/2017 9:05:09 AM PST by Karoo
[ Post Reply | Private Reply | To 4 | View Replies]

To: Gennie

Tech Bookmark.


14 posted on 11/13/2017 9:09:41 AM PST by Sergio (An object at rest cannot be stopped! - The Evil Midnight Bomber What Bombs at Midnight)
[ Post Reply | Private Reply | To 1 | View Replies]

To: bboop

While doing a little research as a result of this thread, it appears PC Mag just did its updated “The Best Password Managers of 2017” - https://www.pcmag.com/article2/0,2817,2407168,00.asp

The list appears to be the premium (paid) list. I think they do a free list as well.


15 posted on 11/13/2017 9:10:45 AM PST by Perseverando (For Progressives, Islamonazis & other Totalitarians: It's all about PEOPLE CONTROL!)
[ Post Reply | Private Reply | To 9 | View Replies]

To: Perseverando

Found it:

The Best Free Password Managers of 2017 - https://www.pcmag.com/article2/0,2817,2475964,00.asp


16 posted on 11/13/2017 9:13:15 AM PST by Perseverando (For Progressives, Islamonazis & other Totalitarians: It's all about PEOPLE CONTROL!)
[ Post Reply | Private Reply | To 15 | View Replies]

To: Gennie

Stop using pass WORDS!

Folks, you need to use pass PHRASES!!!!

For example:

“I love red roses!” = 17 characters and it is easy to remember. For many, it is easier than “Redr0ses” and significantly harder to brute force crack.


17 posted on 11/13/2017 9:24:10 AM PST by taxcontrol (Stupid should hurt)
[ Post Reply | Private Reply | To 1 | View Replies]

To: CatQuilt

Another vote for last pass. I use it on my PC and on my phone. Made password storage 1000 times easier.


18 posted on 11/13/2017 9:25:23 AM PST by JohnyBoy (The GOP Senate is intentionally trying to lose the majority.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Perseverando

>Are your LastPass passwords in the cloud? If so, what if your main password to your account is compromised and then changed? Then what?

They’re stored in the cloud. Last pass does not have access to the passwords as your master password encrypts them. I make backup copies of the full list to an encrypted drive from time to time.


19 posted on 11/13/2017 9:33:48 AM PST by JohnyBoy (The GOP Senate is intentionally trying to lose the majority.)
[ Post Reply | Private Reply | To 3 | View Replies]

To: JohnyBoy

> They’re stored in the cloud. Last pass does not have access to the passwords as your master password encrypts them. I make backup copies of the full list to an encrypted drive from time to time.

My only concern is about the loss of control should the master password be hacked on LastPass’s site, and then the list is downloaded and the master PW is changed.

How do you begin to recover from this?


20 posted on 11/13/2017 9:41:00 AM PST by Perseverando (For Progressives, Islamonazis & other Totalitarians: It's all about PEOPLE CONTROL!)
[ Post Reply | Private Reply | To 19 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-36 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson