Password Reuse
xkcd.com
xkcd.com
</preamble>
Usually submitting XKCD is frowned on, but I'm pleased to see this one submitted. This attack vector is so seldom recognised as a real potential problem. It neatly explains the problem of password re-use.
As an aside, it's known that One-Time-Pad is provably secure. What's less well known is that during WW2 OTP systems were occasionally broken, because in the real world they ended up being Two-Time-Pads. People re-used a pad because they didn't get a new pad in time, etc. This was going to be one of my greybeard stories, but I'm still getting closer to the information source.
http://news.ycombinator.com/item?id=1333934
http://news.ycombinator.com/item?id=996250
http://news.ycombinator.com/item?id=994358
http://news.ycombinator.com/item?id=1001262
I really have to find time to go back and organise them properly.
But the most important thing I learned is this: email account passwords are worth their weight in gold! As soon as you have an email address and password, you have access to a searchable list of logins and password confirmations.
This is even more worrying than the example the comic utilises. You still have to (manually or automatically) go to these sites and guess the username (is it bob101 or is it 101bob this time?) and try the various passwords. As soon as you're into an email account you have quite the dangerous list. All of which are confirmed and ready to go.
-- This is entirely a work of fiction, and in no means describes my teenage years.
This is of course pure evil and we never figured a way in which it had a return apart from publishing lists of common passwords.
We need to train people to behave more securely.
Still, I don't think this is a great idea. You could harvest a lot of passwords with a page like this.
* It might not be in future
* It's not using SSL, so anybody in between can make it stop being client side only whenever they like
* It's a terrible, terrible idea to teach users to trust things like this.
People use the same user/pass combo for every site they visit, except when one of them forces them to use a complicated password that they can't remember. So they send themselves an email with the site name, username and password so that they can find it next time they need to log into their bank.
So once your registry cleaning website has their email password, you also have a nice list of all their strong passwords too.
Adding to the irony, most people know that they need a different password for their bank, so if you just let them pick one without forcing complexity, they'll choose something they can remember, and their bank account will be safe.
Loosen complexity and you can eliminate that post-it. That's a huge overall win.
Complexity in itself isn't actually that bad. It's arbitrary complexity that spawns all those post-its. You can come up with a strong password that you and only you can remember, but it's useless if your bank rejects it due to its own silly complexity policy. There are sites out there that I regularly fail to log in with using my standard "strong" passwords, and it's not until I make it all the way through the Reset Password process to where it tells me its complexity requirement that I'm reminded which password I must have used last time I went through the process.
The only real solution is to let people use the word "password" if they really want. It's still orders of magnitude safer than having them keep a file/email/post-it full of plain text passwords sitting around in plain view.
> The only real solution is to let people use the word "password" if they really want. It's still orders of magnitude safer than having them keep a file/email/post-it full of plain text passwords sitting around in plain view.
If I have "password" as password for my work webmail/remote login, it can be broken by any yokel on the internet with five minutes free time. If I have "ge.9u30!ey0" written on a post-it note on my desk, it can only be "cracked" people with physical access to my office.
Also note that people who have physical access to my office already have security privileges similar to mine own, mitigating the actual risk - they can't do much more damage with my password than they could without. And if they wanted my private stuff, they could just as well nab my harddisk.
Not that I'm justifying passwords on post-its in any means whatsoever, by the way. :-)
People claim money won't make them happy. That is because they buy the wrong things...
I figure a bunch of Russian and Chinese hackers are skimming off cents at a time or something because they don't want to kill their golden goose by being too overt.
It's imperative for me to recall all of my passwords as I need them both at work and at home. Currently I am rotating between three different passwords but this is an area I am becoming increasingly paranoid over.
if you write down some passwords on paper and put them in your wallet, rc4-encrypt them with a master password and write down the base64 equivalent. there should be plenty of free javascript decoders for base64 and rc4 so you can decode them wherever you can find a browser. (yes this is paranoid, but if people know you keep passwords in your wallet it's trivial to get your pocket picked)
I wrote a bit about KeePass and various tricks here, if you're interested: http://www.loopycode.com/solving-sign-up-anxiety/.
And then sync the data in the cloud with dropbox: http://help.agile.ws/1Password3/cloud_syncing_with_dropbox.h...
1Password is integrated in the browser using a plugin (mainly safari under OS X, where it started, but I use it with Chrome with no problem).
Highly recommended
Is the binary stored at dropbox, or the data file? If you store the binary at dropbox how can you be sure it hasn't been modified?