Write Down Your Password
schneier.com
schneier.com
Example: let's say that I need a password for hacker news.
- Let's say that I like dolphins, so my chosen token will be Dol
- I decide to take the second letter from each word in my username: exa (D e usE x M a china)
- I decide to take the third letter from each word in the domain name: wom
- I then choose some punctuation to mix in the password: #&%
Now I'm ready to assemble my password: Dol#exa&wom%
If I have an account on www.yahoo.com with ginger.roger as username, the password would be Dol#io&whm%
It's long enough (but I can making it longer, if I want), uses capital letters and special characters (you can also throw in some numbers, this was just an example) and if someone looks into a database the password is not distinguishable from a random one.
My algorithm is a bit simpler than the one you described though, I can figure out a password I don't remember in just a few seconds. That also makes it less secure of course, I just think its sufficiently secure.
Ex: howdoyoudoandwhatdidyoudohavetodayfordinner?345
<site> <username> <password>
And ~/bin/psw: #!/bin/sh
cat $HOME/passwords.gpg | gpg --decrypt | grep $1
Simple, done.What I haven't done yet is write a script to add/modify/delete items from the encrypted file. I keep meaning to.
Short, low security (simple passwords, e.g. a mashup of 2 words or an uncommon word with a typo/1337 edit): Memory
Very very long, or very very infrequently used: Paper slips. Stored somewhere less obvious than a wallet.
Lastly, my favorite: Long/High security: My hands. No joke. The muscle memory in my hands currently knows about 5 complex passwords that my brain has partially forgotten. The only way I can give someone the password is to pretend I'm typing on a keyboard and tell him what I'm typing.
Pah, I'm getting old.
It's true, things like my credit card number - I wouldn't be able to dictate for you, but I can enter it without whipping it out.
Happily, nothing ever said "maximum length exceeded" when I registered that. I think, like our move away from IE6, the short password days are mostly over.
That said, for things like PIN numbers for credit cards, etc, you can come up with some reasonably secure but still not easily guessed systems, such as using the last digit of each quad of digits on the card or two pre-decided groups of two. Different PINs everywhere, hard for anyone else to guess, and not hard for you to figure out :-)
For example, if I used 5p0ng3b0b, I would write "who lives in a pineapple under the sea?" or "Patrick"
http://blog.wkdown.com/2010/04/easy-to-remember-secure-passw...
... or maybe I'm missing how this would be easy to break? Dictionary wouldn't work, brute force would take too long, and idk enough about rainbow tables to know their time frame.
If your password gets stolen, you might be able to change it. But if the attacker gets there first, all you can do is get in touch with the website and say "my password got stolen and changed, please return my account" and hope they comply.
If you don't write down what your password is for, you're probably safe (but keep a backup, especially for email) - but only as long as most people don't do this.
The one single long password I have is 28 characters long; a random password I tapped on the keyboard and then wrote down on a piece of paper, used to administrate my ADSL modem's NAT/wifi/etc. which sadly can't be configured to allow only local login, hence the need for an "unguessable" password - however, not only have I inadvertently, from typing in the password many times, memorized the full password by the character, but I've also inadvertently memorized it motorically, and can without thinking repeat it on the keyboard in a second.
I agree fully on Schneier's advice, though, as the longer and the more random the password, the lower the chance for a dictionary or brute force success, but I'd store the piece of paper somewhere else than in my wallet :)