YOUR FRIENDS' ACTIVITY

    Advice from a Hacker on Picking a Good Password

    As mass hacks abound, it's hard to know the best way to handle our Internet security, so we went to a password expert to figure out how best to protect ourselves. Alex Horan is a proclaimed "white hat hacker," meaning he hacks "for good, not evil" in the words of the public relations liason for CORE Security, where Horan is a product manager. He, like us, believes the password system these days isn't ideal for people trying to protect their online info. Though hacks are happening more often for various reasons (as discussed here), there is one part of the dysfunctional system we can control: Our own password habits.

    RELATED: LulzSec Explains Itself, Sort Of

    But Horan does not blame us for not using ideal passwords. One of the biggest problems with passwords is the glut of sites that require them. "The end users are really in a bind," Horan said. "More and more things are online and there is no ability yet for me to have a single online ID where I can use the same user name and password to authenticate to some central database." Right now, people are asked to create new usernames and new passwords for everything. When our creativity wanes (and our memories dim) we often resort to reusing the same password. But that's unsafe. The biggest danger of a password hack is that a password found at one site can be used to get into other, more important accounts. (That's what happened to James Fallows' wife, as he explained in The Atlantic.) The other option is to have different codes for everything, which is unreasonable and annoying. A recent survey found 38 percent of respondents would rather clean a toilet than think of new combinations. Another 38 percent said they would rather tackle world peace. So what to do? Here's what Horan suggests.

    RELATED: LulzSec Disbands Before Its Members Are Outed

    Save brain space for the really important accounts. For the stuff that really matters, like bank accounts, for example, Horan suggests we use unique passwords for each and every one of them. For the less important stuff, it might make sense to choose a "dumb password," a suggestion we had a few weeks ago. That doesn't totally eliminate the so-many-things-to-remember issue, but it compartmentalizes things. Also, I sometimes forget which passwords I picked for what sites, this system would help me remember, at the very least, what type I picked. 

    RELATED: The Problem with Parents Helping Kids Lie to Get on Facebook

    Forget password, think passphrase. A password indicates some intricate combination of letters and numbers (and maybe symbols) that looks hard to guess. Those are hard to remember, and not always impenetrable. A passphrase, instead, consists of a string of whole words. Like, a line of a book, or a song lyric, Horan suggests. "The first line of my favorite book is very hard for someone to guess and also very hard for a computer to brute force." (A brute force attack is when a computer program does hyper-speed password guessing, which is what happened with LinkedIn.) One extra character makes it exponentially more difficult to crack, as this chart Horan provided shows.

    RELATED: The Internet Is Getting A 'Cat Signal'

    RELATED: Do You Even Care If Someone Has Your LinkedIn Password?

    Longer is better, but harder to remember if it's a nonsensical code. So Horan suggests making it something that isn't a single word someone would think of, but that's easy for you to remember. 

    Don't use the same login for everything. Hackers don't generally look for multiple email addresses that have the same password, but rather hope the username-password combo exists elsewhere. To avoid this, Horan suggests we don't think passwords, but rather usernames. "For LinkedIn, have linkedin.alexanderhoran@gmail.com," instead of the standard YourName@gmail.com, he told us.That involves creating the unique Gmail account and then linking it up with your standard mail address, which sounds like a lot of work to us. But it is just a one-time set-up and a lot easier to remember than a bunch of random letters and numbers.

    Update August, 30 1:52 p.m.: Though one could go through all the trouble to make new email addresses, Horan has clarified that Gmail allows it to appear as if you have multiple email addresses when you don't. For example the email address YourName@gmail.com can also use the following logins: YourName+LinkedIn@gmail.com and YourName+facebook@gmail.com and YourName+Twitter@gmail.com, etc. "All those email address will work, and they will all come to my inbox. I can then use filters and folders in gmail to organize them etc as well," Horan told us. 

    Our password picking habits aren't the only reason passwords have failed us. A lot of it has to do with the way websites do (or rather, do not) protect us. Not all these sites are using the most secure systems. The Yahoo Voices system, which was hacked last month, didn't use encryption, for example. LinkedIn added salting -- a system that inserts random characters into a password hash, making it harder for hackers -- not too long ago. Horan also has suggestions for how sites can do better. 

    Use a well known public encryption scheme. To sites that don't encrypt at all: Get on that. But, Horan says there is a misunderstanding that a homemade scheme does better than a mass-used one. He says that is wrong. "With a private one you might miss a problem. And then, even if you find it you've got to fix it." A well-vetted public one is a better bet. 

    Use a strong, long salt. The more intricate the salt, the harder it will be for a brute force attacker to crack it. Makes sense. 

    Be transparent. At this point, we just hand over our information to companies and trust them with our keys. If we knew what kind of protection these sites had, maybe we would think before locking important stuff up behind something that's about as secure as childproof medicine caps. "They should tell us the effort they make in general to protect the passwords," he said. Then, people like him could check for holes. And people like us could be conscious of what's what. Though, we offer a more cynical point of view than Horan. People don't read terms of service agreements, why would they bother with some technical password protection mumbo jumbo? 

    Image via Shutterstock by mkabakov

    Loading...
    • Soccer-Ferguson criticises City for Mancini sacking

      LONDON, May 18 (Reuters) - Manchester United's outgoing manager Alex Ferguson has criticised neighbours Manchester City for sacking Roberto Mancini. The Italian boss was sacked on Monday having failed to retain the Premier League title he won last season and after losing the FA Cup final to Wigan Athletic. Mancini took out a full-page advertisement in the Manchester Evening News on Saturday, thanking fans for their support during his time in charge. ...

    • Even Cavendish surprised by fourth stage win

      By Alasdair and Fotheringham CHERASCO, Italy, May 17 - A series of small but challenging climbs late on Friday's stage of the 2012 Giro d'Italia could not stop Britain's Mark Cavendish taking his fourth stage win and second in two days. Italy's Vincenzo Nibali remained overall leader but it was sprinter Cavendish who stole the show again after compatriot and pre-race favorite Bradley Wiggins failed to start the 254 kilometer stage, the longest in this year's Giro. In a bunch sprint finish Cavendish outgunned Italy's Giacomo Nizzolo and Slovenia's Luka Mezgec. ...

    • Winning ticket for $590.5 million Powerball lottery sold in Florida

      By Karen Brooks and Steve Gorman (Reuters) - A single winning ticket for a record U.S. Powerball lottery jackpot worth $590.5 million was sold in Florida, organizers said late on Saturday, but there was no immediate word about who won or where in the state the ticket was bought. The winning numbers from Saturday night's drawing were: 10, 13, 14, 22 and 52, with a Powerball number of 11, and the odds of winning were put at one in 175 million. The grand prize, accumulated after two months of drawings, surpassed the previous record Powerball payoff of $587. ...

    • Bea Arthur topless painting fetches $1.9M in NYC

      A painting of actress Bea Arthur topless has sold for $1.9 million at a New York City auction. The painting is by artist John Currin and is titled "Bea Arthur Naked." It sold at Christie's auction ...

    • Soccer-Real and Mourinho contemplate "disastrous" season

      By Iain Rogers MADRID, May 18 (Reuters) - Real Madrid and Jose Mourinho were sifting through the debris of what the Portuguese coach termed a "disastrous" 2012-13 campaign after Friday's King's Cup final defeat left the world's richest club without a major trophy for the season. The 2-1 reverse to Atletico Madrid at their own Bernabeu stadium meant Mourinho, widely expected to move on at the end of this term, finished a season without significant silverware for the first time in his otherwise glittering career. ...

    • A record Powerball jackpot isn't a record to celebrate

      When the 43-state Powerball lottery jackpot hit a record at $600 million Friday, many Americans who would otherwise not gamble rushed out to buy the $2 tickets. “Just on the off-chance,” many probably said.

    • NYers furious over photos taken through windows

      In one photo, a woman is on all fours, presumably picking something up, her posterior pressed against a glass window. Another photo shows a couple in bathrobes, their feet touching beneath a table. And ...

    • Marine daughter seeks dignity for 'Devil Dog pups'

      JACKSONVILLE, N.C. (AP) — As she flipped through the cemetery register, Mary Blakely's eyes filled with tears. On line after line, the entry read simply "Baby Boy" or "Baby Girl," followed by a surname and a burial date.

    Loading...

    Follow Yahoo! News