Your guide to safe passwords/account options
basilmarket.com forums :
Tech Talk
| 15 posts archived
thread starter xlrAcer5 Jun 17 2009
+ PM | QUOTE | PERMALINK | REPORT
| Many websites these days are frauds, whose goal is to steal password/account information. It's good to get a new password every few months, or other periods of time. In this guide, I'll give you tips on how to keep a hard to guess password, as well as making sure that account information isn't easy to find out. Your Password What are some qualities found in a good password? • Length of the password • Particularly over 6 characters long, holding numbers AND letters. Why is this good? Short passwords usually include words, which can make them easy to guess. • Not something that could easily be guessed by people you know • We've all had passwords that have included our first names, middle names, etc. Passwords containing interests aren't going to fly either. If you're going to use a password based on something important to you, add numbers and letters to the end. • Numbers and letters rather than words • This first occurred to me as useful when I first made a Nexon account. The password they assigned to me was long, and contained only letters and numbers--no words. What's good about these passwords? The only way they can be discovered is if you're being keylogged. What's bad about them? They take a while to remember, but soon pay off after you never find your accounts disturbed. • Case Sensitive Passwords • The hacker may think he knows your password, when boom. He didn't capitalize the "b" in BaSiLMaRKET86. This comes in handy if you absolutely have to live with a simple password. DONT pattern capitalizations such as: BaSiLmArKeT • Using Symbols along with letters and numbers • The more variety of characters in your password, the harder it is to guess--Pretty straight forward B@SiLMaRKET86! > BaSiLMaRKET86 > BaSiLMaRKET > basilmarket Thanks to Enwove for that helpful tip. He also created this diagram. What if your password is found stolen? Deactivating it and making another is probably the safest way to keep people out of your accounts. If a website doesn't give the option to deactivate, just change the password. Before you change it, make sure the email linked to the account is yours, because if it's not, the new information you've given will be sent to a criminal. Account Recovery and other Options When you register for online services, they'll usually ask you for a security question, birthday, last name, etc. Here's some tips for following these directions wisely: • The Security Question • Usually the options they give you are too simple for friends and family to guess, which defeats the purpose of having a security question. Giving false information is usually what I do. The thing is, you have to remember it. If the question asks what your dogs name is, putting the word "dog" would definitely throw people off, thus working. • Giving your birthday to websites you don't believe need to know it • Giving tweaks to your birthday is the easiest way to keep obvious information out of a criminal's use. Instead of giving your real birthday, give a half |
SomeWierdGuy Jun 17 2009
+ PM | QUOTE | PERMALINK | REPORT
| I didn't read any of it but I saw the birthday thing.. Who can ruin your life by knowing your b-day? I'm sure you have told a lot of your friends already, it's not a big thing.. and it's the easiest to remember. and you should add the best password are words that aren't real, don't know if you already have that. ex: gfrt5456 |
xlrAcer5 06/17/09
+ PM | QUOTE | PERMALINK | REPORT
| SomeWierdGuy said: "I didn't read any of it but I saw the birthday thing.. Who can ruin your life by knowing your b-day? I'm sure you have told a lot of your friends already, it's not a big thing.. and it's the easiest to remember. and you should add the best password are words that aren't real, don't know if you already have that. ex: gfrt5456" Yep, already included. Thanks though. |
Enwove 06/18/09
+ PM | QUOTE | PERMALINK | REPORT
| You forgot to include symbols. Passwords that include various symbols are generally not bothered with, when it comes to brute forcing a password. When it comes to password strength: B@SiLMaRKET86! > BaSiLMaRKET86 > BaSiLMaRKET > basilmarket |
skaii345 06/18/09
+ PM | QUOTE | PERMALINK | REPORT
| About the postal code... if people want to participate in a event and they win and get a prize like key chain then they need your postal code to send you it |
xlrAcer5 Jun 18 2009
+ PM | QUOTE | PERMALINK | REPORT
| Enwove said: "You forgot to include symbols. Passwords that include various symbols are generally not bothered with, when it comes to brute forcing a password. When it comes to password strength: B@SiLMaRKET86! > BaSiLMaRKET86 > BaSiLMaRKET > basilmarket" Thanks, I'll add it. I didn't think websites allowed that. @Skaii, I would use a separate account for prizes--I guess that could be added. |
skye09 06/18/09
+ PM | QUOTE | PERMALINK | REPORT
| Isnt there already something else like this? |
walridge3 06/18/09
+ PM | QUOTE | PERMALINK | REPORT
| Another very common, but helpful tip is to not use words, even when varied; Use things like the first letter of each word in a sentence, such as "Every other day I frequent BasilMarket using Firefox 3" --> Eod1fBMuFF3 for instance. |
rbbbehal 06/19/09
+ PM | QUOTE | PERMALINK | REPORT
| is twitter a scam cause it says u need email and email pass |
Enwove 06/19/09
+ PM | QUOTE | PERMALINK | REPORT
| rbbbehal said: "is twitter a scam cause it says u need email and email pass" Yes. One of the most widely used internet services is a scam. |
xlrAcer5 06/19/09
+ PM | QUOTE | PERMALINK | REPORT
| Enwove said: " Yes. One of the most widely used internet services is a scam." That made me laugh. |
Dull 06/21/09
+ PM | QUOTE | PERMALINK | REPORT
| I found this and this useful. |
skye09 06/21/09
+ PM | QUOTE | PERMALINK | REPORT
| Dull said: "I found this and this useful." In the second link, the post by "Rob Begbie" made me lol xD |
okmjin Jun 27 2009
+ PM | QUOTE | PERMALINK | REPORT
| Personally, I never understood the need in extremely complicated passwords, for example A12#j23/azS&. This is why: 1.No one can brute force a password over the internet. Brute forcing a 6 chars password on your own computer would take about 10 mins, on a speed of 1,000,000 passwords per second (the general speed of local password crackers). Over the internet, you should be able to try no more than 10 passwords a second. Do the math and you will understand why is it impossible. 2.Since brute forcing is not an option, dictionary attacks are often used. These attacks are based on trying all the passwords from a huge list of (usually around 1.5m) common passwords, most of them being real words. So as long as your password is not common, obvious, or a real word, it cannot be cracked this way. 3.Extremely complicated passwords are hard to remember, which often either leads you to forgetting your password or writing it somewhere, typically on your real or virtual desktop. Thats a security flaw that is even bigger than using the password "password". 4.The only use of very long or complicated passwords is against hash cracking, which is the last stage of hacking into a website's database. But seriously, if nexon's database gets hacked, we have bigger problems than our accounts. |
xlrAcer5 07/03/09
+ PM | QUOTE | PERMALINK | REPORT
| okmjin said: "Personally, I never understood the need in extremely complicated passwords, for example A12#j23/azS&. This is why: 1.No one can brute force a password over the internet. Brute forcing a 6 chars password on your own computer would take about 10 mins, on a speed of 1,000,000 passwords per second (the general speed of local password crackers). Over the internet, you should be able to try no more than 10 passwords a second. Do the math and you will understand why is it impossible. 2.Since brute forcing is not an option, dictionary attacks are often used. These attacks are based on trying all the passwords from a huge list of (usually around 1.5m) common passwords, most of them being real words. So as long as your password is not common, obvious, or a real word, it cannot be cracked this way. 3.Extremely complicated passwords are hard to remember, which often either leads you to forgetting your password or writing it somewhere, typically on your real or virtual desktop. Thats a security flaw that is even bigger than using the password "password". 4.The only use of very long or complicated passwords is against hash cracking, which is the last stage of hacking into a website's database. But seriously, if nexon's database gets hacked, we have bigger problems than our accounts." If nobody can brute force it, then isn't it better to have? And about remembering passwords, they usually come to the users desire. |
BasilMarket is Copyright 2004-2008 BasilMarket.com (archive reconstruction). Data recovered from the Internet Archive Wayback Machine for the Classic MapleStory community.