How secure is your password and PIN?

Do you always use a secure password?

  • Yes

    Votes: 39 67.2%
  • No

    Votes: 19 32.8%

  • Total voters
    58
Prefer alpha numeric passphrases but also have several passwords similar to below (always minimum of 12 characters).

GK<%G%2h3t!a?

Nice type of base but often systems don't handle special characters well.

The other side of the coin is to let your browser remember your Password, however it is trivial to find software to extract saved passwords too.
 
My password is secure though I change them depending on how important things are.
 
With the recent Lulzsec hacks occurring and lots of accounts finding their way onto the net, I decided it was time to tighten up my security. Every site I have an account with now has a unique 15 character password containing upper and lower case alphanumeric characters, as well as a few special characters, with the password sometimes having to be adjusted to fit the sites constraints. All these passwords are then stored in my LastPass vault, which has its own unique 15 character password (which I actually remember), and two factor authentication with my YubiKey.

So yeah, my passwords are pretty safe (for online accounts).
 
Looks like women is responsible for most weak passwords if that list is anything to go by. Why no manly weak passwords like racecar, horsepower, bigbazooka, extralargenunus, jessicaalbanakednow or such? :D
 
Nice type of base but often systems don't handle special characters well.

The other side of the coin is to let your browser remember your Password, however it is trivial to find software to extract saved passwords too.

I freaking hate outdated systems like that (including SARS, SABC and Mweb's email password policies) in that case it usually ends up with me changing characters for letters and numbers.
 
this is one of the best passwords I have ever used: braaiVleisandpap_2Go... Had to change it due to the fact that I had to ask my girlfriend to log into my account ... It's pretty easy to come-up with a strong password, protecting it agains phishing, spyware and the likes is the difficult part... I always make it unique by using slang, symbols and numbers ...
 
I was wondering, "Brute force attack at 1000 guesses per second" makes sense on paper, but if someone is sitting remotely attempting passwords, even at milliseconds lag, it surely takes some time to send a password, authenticate, then receive positive/negative feedback. Heck if someone adds a half second delay to their authentication code then boom, you are limited to two attempts a second, without much impact on regular users who wouldn't notice a half second delay??
 
I was wondering, "Brute force attack at 1000 guesses per second" makes sense on paper, but if someone is sitting remotely attempting passwords, even at milliseconds lag, it surely takes some time to send a password, authenticate, then receive positive/negative feedback. Heck if someone adds a half second delay to their authentication code then boom, you are limited to two attempts a second, without much impact on regular users who wouldn't notice a half second delay??
The problem is a bit more complicated than that.
For starters the basic security measures gets ignored by sysadmins making for softer targets. Not blocking unused ports, weak firewall implementation, weak maintenance, etc.
Even the strongest fort will fall if you continue chipping away at it with a hammer.

They do not use just one computer, they attack the source from infected hosts, and you will have a jaw dropping moment if you have any idea of how many PC's are infected throughout the world.
Symantec said there were 6.2 million such PC's in 2010, while another firm strongly disagreed with them and said it is closer to 20 million. The study is a bit old, but it could have only gotten worse:
http://lastwatchdog.com/6-8-million-24-million-botted-pcs-internet/

Now a couple of million of PC's hacking away at a password at (lets be conservative) 500 requests per second? Not good!

Now give that hacker physical access to the internal network with weak WIFI security or heaven forbid he actually gets a lan connection, GAME OVER!
 
How do you digesr a password before saving to database. How secure is Firefox's password storage if you use a strong password as the master password ?
 
My PIN will be pretty easy to crack. Based on a special date - broke rule no. 1 of creating strong PINs. My passwords not so easy crack - thanks to Roboform. But I don't even trust Roboform with my banking password. That stays in my mind. It's very strong and does not have to change - no need.

Info Sec pros have got the responsibility to educate users on how to create strong passwords which are easy to remember. Organisations should be on SSO! I know there are downsides to this approach. I think there are more (+)s than (-)s. Passwords should be changed every 60 days, 30 is an overkill but >100 days is also too relaxed, depending on the type of industry, of course.
 
I generally use a variation of the same password. Very bad practice I know.
 
I use different passwords for everything, although i do have a few 'default' passwords i use for non-threatening sites/forums etc.

But mainly, I use Passwordsafe. To both store AND generate my passwords - with a master key obviously for that.

Forcing people to change their passwords on a regular basis is asking for trouble. They resort to things they see on their desk or something. Like "Mecerscreen" if they have a mecer LCD for example. It ends up being like a game of 'I-spy' (or eye-spy? lol)!
 
Top
Sign up to the MyBroadband newsletter
X