Passwords Aren't As Secure As We Think - How to Fix That
lifehacker.com
lifehacker.com
I'm sorry but this is bullshit. The reason for the (admittedly weak) obfuscation is to keep out the casual snooper, e.g. your little brother or sister who shares the family computer. It's not meant to keep out a skilled cracker, nor to protect those savvy enough to think about these issues.
Why do we geeks tend to only think about things from our perspective? I think we should coin a phrase for it. Maybe the myth of the "sufficiently smart user".
I was baffled but there are people out there - not senior citizens but 20 year olds - that really don't understand or care to understand any of that stuff. It's a magic box to them. They have no idea chat histories are stored on disk even though they see them in MSN. The fact that they have logged in makes them think no one else can see them. Likewise the fact that their saved password is stored is over their head unless someone explains it to them. Not everyone has someone to tell them these things.
Oh also, someone with physical access could just as well install a keylogger. It's a pretty difficult threat to guard against.
"Having our passwords in plaintext is more secure than obfuscating them precisely because, when a user is not misled by a false sense of security, he is likely to use the software in a more secure manner."...
...is completely laughable. I'd be willing to bet that the VAST majority of Pidgin users have no idea that their passwords aren't stored securely. To make matters worse, I don't recall Pidgin ever warning me that its storage was insecure, so they're not even trying to educate their users.
And TrueCrypt is an awesome concept + tool. Gotta love the ability to have an entire hard drive look like it's just random data. You can't get much better security than that, as you can deny there's anything there, and "they" don't even know where to begin.
http://blog.sucuri.net/2009/10/password-security-without-pas...
A javascript app for that would be good, btw :)
echo “qwerty http://www.facebook.com” | md5
That will appear in plain text in your terminal history file. And, if you are on a multi-user machine, even non-privileged users will be able to see your command line.You should never put any password or private key on a command line (any command line, not just in your terminal). Instead, use the unix-standard getpass function or it's equivalent in your language/library of choice.
./pass-site.sh http://facebook.com
" #!/bin/sh
SITE=$1 stty -echo read UPASS stty echo PASS=`sha1 "$SITE $UPASS"` echo "PASS: $PASS" "
A determined attacker with physical access to your system is basically impossible to stop. There are a myriad of ways they can figure out your password or log your keystrokes or memory to find it.
I feel that the real value in passwords is in securing network communications. In that case you simply need to be sure the protocol is secure and does not send the password over the wire (or air) in plain text or an easily extractable format.
The chance of someone trying to brute force your online accounts or sniffing your network traffic is much more likely than someone sneaking into your office and booting your desktop from a live CD. So I would rather have a very strong network password and a reasonably weak password manager passwords than not store my passwords and thus feel the pressure to make my online passwords easy to remember.