How secure is your password?

DeathmageDeathmage Banned Posts: 2,496

Comments

  • gc8dc95gc8dc95 Member Posts: 206 ■■□□□□□□□□
    That is a fun site. I am too paranoid to put in an actual password, but used a mutated form of one that I may use = 4 trillion years.
  • snadamsnadam Member Posts: 2,234 ■■■■□□□□□□
    'cat' is secure, right?
    **** ARE FOR CHUMPS! Don't be a chump! Validate your material with certguard.com search engine

    :study: Current 2015 Goals: JNCIP-SEC JNCIS-ENT CCNA-Security
  • alias454alias454 Member Posts: 648 ■■■■□□□□□□
    I always use the same one ************ ;)
    “I do not seek answers, but rather to understand the question.”
  • MooseboostMooseboost Member Posts: 778 ■■■■□□□□□□
    157 billion years, good to see that aliens will know my password.
  • JockVSJockJockVSJock Member Posts: 1,118
    alias454 wrote: »
    I always use the same one ************ ;)

    For multiple accounts, including banking, investement and credit card websites.
    ***Freedom of Speech, Just Watch What You Say*** Example, Beware of CompTIA Certs (Deleted From Google Cached)

    "Its easier to deceive the masses then to convince the masses that they have been deceived."
    -unknown
  • knownheroknownhero Member Posts: 450
    333 Sextillion years.

    Not bad
    70-410 [x] 70-411 [x] 70-462[x] 70-331[x] 70-332[x]
    MCSE - SharePoint 2013 :thumbup:

    Road map 2017: JavaScript and modern web development

  • mweaver84mweaver84 Member Posts: 44 ■■■□□□□□□□
    snadam wrote: »
    'cat' is secure, right?

    I hope so...
  • PristonPriston Member Posts: 999 ■■■■□□□□□□
    We'll since my old passwords "admin", "password", and "123456" are Instant I guess I'll have to use "adminpassword123456" which should last me 2 trillion years.
    A.A.S. in Networking Technologies
    A+, Network+, CCNA
  • MeanDrunkR2D2MeanDrunkR2D2 Member Posts: 899 ■■■■■□□□□□
    It's the same as my luggage password.

    1 2 3 4 5
  • DevilWAHDevilWAH Member Posts: 2,997 ■■■■■■■■□□
    Mooseboost wrote: »
    157 billion years, good to see that aliens will know my password.

    Or the first guy with a Quantum computer ;)

    Funny to play with that site, as Priston shows, just because it says a password is secure does not mean it is. This is showing how long it takes to brute force the password, not how easy it is to guess. And most passwords are either guessed / social engineered to tell the password. Or a mixture of both where the attacker has an idea of the password make up to seed any brute force cracking tool. Which is a good reason not to go for common lengths like 12 which I have seen as a standard in some companies. If a hacker knows the rules that go in to shaping your passwords then it can significantly reduce the time taken to brute force it.
    • If you can't explain it simply, you don't understand it well enough. Albert Einstein
    • An arrow can only be shot by pulling it backward. So when life is dragging you back with difficulties. It means that its going to launch you into something great. So just focus and keep aiming.
  • tpatt100tpatt100 Member Posts: 2,991 ■■■■■■■■■□
    I roll my face across my keyboard and have Chrome remember the password. Doesn't work for sites that make me confirm what I rolled the first time though.
  • bermovickbermovick Member Posts: 1,135 ■■■■□□□□□□
    Good news for xkcd readers! HorseBatteryStapleCorrect would take 62 septillion years.
    Latest Completed: CISSP

    Current goal: Dunno
  • SephStormSephStorm Member Posts: 1,731 ■■■■■■■□□□
    My password is **********. Huh, the website automatically blocks it!
  • --chris----chris-- Member Posts: 1,518 ■■■■■□□□□□
    bermovick wrote: »
    Good news for xkcd readers! HorseBatteryStapleCorrect would take 62 septillion years.

    lol, I understand the reference.

    I have not done much research, is it possible that comic is correct?
  • E Double UE Double U Member Posts: 2,233 ■■■■■■■■■■
    It's the same as my luggage password.

    1 2 3 4 5

    That never gets old lol
    Alphabet soup from (ISC)2, ISACA, GIAC, EC-Council, Microsoft, ITIL, Cisco, Scrum, CompTIA, AWS
  • ShdwmageShdwmage Member Posts: 374
    109 quattuordecillion years.

    Whatever that means.
    --
    “Hey! Listen!” ~ Navi
    2013: [x] MCTS 70-680
    2014: [x] 22-801 [x] 22-802 [x] CIW Web Foundation Associate
    2015 Goals: [] 70-410
  • iBrokeITiBrokeIT Member Posts: 1,318 ■■■■■■■■■□
    2019: GPEN | GCFE | GXPN | GICSP | CySA+ 
    2020: GCIP | GCIA 
    2021: GRID | GDSA | Pentest+ 
    2022: GMON | GDAT
    2023: GREM  | GSE | GCFA

    WGU BS IT-NA | SANS Grad Cert: PT&EH | SANS Grad Cert: ICS Security | SANS Grad Cert: Cyber Defense Ops SANS Grad Cert: Incident Response
  • dave0212dave0212 Member Posts: 287
    I use this site to generate examples of secure passwords in security awareness training to show differences in the old convention of complex passwords vs passphrases that are easier to remember
    This week I have achieved unprecedented levels of unverifiable productivity


    Working on
    Learning Python and OSCP
  • jibbajabbajibbajabba Member Posts: 4,317 ■■■■■■■■□□
    Doesn't look like the universe will live long enough for someone to crack my password.

    And old 'actual' password apparently takes 166 Trillion years to hack.

    Mind you, I never use single words with special characters I can never remember. Just make up sentences related to the site or use popular phrases. Easier, yet more secure.

    Like

    TechexamsNetIsEffinAwesome

    Takes 62 Septillion years icon_smile.gif
    My own knowledge base made public: http://open902.com :p
  • DevilWAHDevilWAH Member Posts: 2,997 ■■■■■■■■□□
    jibbajabba wrote: »
    Doesn't look like the universe will live long enough for someone to crack my password.

    And old 'actual' password apparently takes 166 Trillion years to hack.

    Mind you, I never use single words with special characters I can never remember. Just make up sentences related to the site or use popular phrases. Easier, yet more secure.

    Like

    TechexamsNetIsEffinAwesome

    Takes 62 Septillion years icon_smile.gif


    I always have a concern about pass phrases as they can be cracked with brute force if you apply simple rule of grammar and a dictionary. The average person uses about 2,000 words, Arranging them in to phrases that are 4-8 words in length that make sense and allowing for Capital letters you end up with a quite restrictive dictionary of possibilities.

    I prefer to take a longer phase of 12 or more words.

    the cable on my desk is a dark Purple one in a plastic bag from excel.

    take the first letters

    TCOMDIADPOIAPBFE

    Substitute a few number and cases and stick some random(ish) symbols on the end on the end. (but not consistently so if as above I have 2 I then only substitute one with a number)

    Tc0md1adpoiapbf3£!

    But what is interesting according to that site is

    TechexamsNetIsEffinAwesome = 62 Septillion

    Tc0md1adpoiapbf3£! = 123 sextillion years.

    can some one run a brute force on both and see which is quicker in reality ?? :)
    • If you can't explain it simply, you don't understand it well enough. Albert Einstein
    • An arrow can only be shot by pulling it backward. So when life is dragging you back with difficulties. It means that its going to launch you into something great. So just focus and keep aiming.
  • MeanDrunkR2D2MeanDrunkR2D2 Member Posts: 899 ■■■■■□□□□□
    Honestly, I don't see why more banks don't use 2 factor password set ups like how Google does it for Gmail, etc. An unknown device happens to get the password right? Well, they aren't getting that text message sent to my phone to actually access my account since they would be unable to change the settings to another phone number or a different email address for that. Add in a difficult password that is hard to crack, and it makes it even more unlikely.
  • SephStormSephStorm Member Posts: 1,731 ■■■■■■■□□□
    It can be very annoying for the users depending on how it is implemented. Take XBox Live's system, God i'd get 6 or 7 text/email messages to determine that year I was the one who had access, ect.

    The fact is that generally banks don't need 2FA for most access needs. We aren't seeing people's accounts hacked all day, we see more issues with identity theft.
  • DevilWAHDevilWAH Member Posts: 2,997 ■■■■■■■■□□
    Honestly, I don't see why more banks don't use 2 factor password set ups like how Google does it for Gmail, etc. An unknown device happens to get the password right? Well, they aren't getting that text message sent to my phone to actually access my account since they would be unable to change the settings to another phone number or a different email address for that. Add in a difficult password that is hard to crack, and it makes it even more unlikely.

    We use two factor authentication for VPN access, but we use RSA tags. We have tried text messages and email, but there is on big issue. Our staff travel the world and the worst thing is when you are in a small village with out a phone signal you can't sign in! Might only affect 1 in 100 users, but if they are trying to connect to access a powerpoint presentation for a important conference then it becomes a huge issue.

    Two factor is great, but often the system you most want to secure are the ones that you often need access to in critical and time sensitive situations. so if it does not work for what ever reason it can be so so so frustrating.
    • If you can't explain it simply, you don't understand it well enough. Albert Einstein
    • An arrow can only be shot by pulling it backward. So when life is dragging you back with difficulties. It means that its going to launch you into something great. So just focus and keep aiming.
Sign In or Register to comment.