<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: How strong is your password?</title>
	<atom:link href="http://weblogtoolscollection.com/archives/2007/06/07/how-strong-is-your-password/feed/" rel="self" type="application/rss+xml" />
	<link>http://weblogtoolscollection.com/archives/2007/06/07/how-strong-is-your-password/</link>
	<description>Weblog Tools Blogging Tools Blog</description>
	<pubDate>Fri, 29 Aug 2008 03:56:33 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
		<item>
		<title>By: Mark Mathson</title>
		<link>http://weblogtoolscollection.com/archives/2007/06/07/how-strong-is-your-password/#comment-1162409</link>
		<dc:creator>Mark Mathson</dc:creator>
		<pubDate>Wed, 20 Jun 2007 20:02:43 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/06/07/how-strong-is-your-password/#comment-1162409</guid>
		<description>"...the weakest link in our security chain is the common stuff we tend to overlook."

I couldn't agree more.  It can be difficult to teach someone the importance of using a 'strong' password. It comes down to education, and systems such as the one Wordpress.com and other sites implement to suggest using stronger passwords.</description>
		<content:encoded><![CDATA[<p>&#8220;&#8230;the weakest link in our security chain is the common stuff we tend to overlook.&#8221;</p>
<p>I couldn&#8217;t agree more.  It can be difficult to teach someone the importance of using a &#8217;strong&#8217; password. It comes down to education, and systems such as the one Wordpress.com and other sites implement to suggest using stronger passwords.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Martin Wright</title>
		<link>http://weblogtoolscollection.com/archives/2007/06/07/how-strong-is-your-password/#comment-1161840</link>
		<dc:creator>Martin Wright</dc:creator>
		<pubDate>Thu, 14 Jun 2007 21:37:25 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/06/07/how-strong-is-your-password/#comment-1161840</guid>
		<description>If you need to get a strong password you can use &lt;a href="http://www.passpub.com" title="PassPub" rel="nofollow"&gt; for uniquely generated, strong passwords&lt;/a&gt;.

Thanks
Martin</description>
		<content:encoded><![CDATA[<p>If you need to get a strong password you can use <a href="http://www.passpub.com" title="PassPub"> for uniquely generated, strong passwords</a>.</p>
<p>Thanks<br />
Martin</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Around the web &#124; alexking.org</title>
		<link>http://weblogtoolscollection.com/archives/2007/06/07/how-strong-is-your-password/#comment-1161523</link>
		<dc:creator>Around the web &#124; alexking.org</dc:creator>
		<pubDate>Sun, 10 Jun 2007 15:18:32 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/06/07/how-strong-is-your-password/#comment-1161523</guid>
		<description>[...] How strong is your password? [...]</description>
		<content:encoded><![CDATA[<p>[...] How strong is your password? [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chemistry in password &#187; Â§hÂªÂ®dz Ã¸f mÃ°Ã¯ LÃ¯fÂ£</title>
		<link>http://weblogtoolscollection.com/archives/2007/06/07/how-strong-is-your-password/#comment-1161412</link>
		<dc:creator>Chemistry in password &#187; Â§hÂªÂ®dz Ã¸f mÃ°Ã¯ LÃ¯fÂ£</dc:creator>
		<pubDate>Fri, 08 Jun 2007 13:09:36 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/06/07/how-strong-is-your-password/#comment-1161412</guid>
		<description>[...] look at this post&#8217;s comments and found this: I figured the chemical formula approach, coupled with a very [...]</description>
		<content:encoded><![CDATA[<p>[...] look at this post&#8217;s comments and found this: I figured the chemical formula approach, coupled with a very [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Willem</title>
		<link>http://weblogtoolscollection.com/archives/2007/06/07/how-strong-is-your-password/#comment-1161396</link>
		<dc:creator>Willem</dc:creator>
		<pubDate>Fri, 08 Jun 2007 00:27:34 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/06/07/how-strong-is-your-password/#comment-1161396</guid>
		<description>what's the use of strong passwords when your no using an encrypted transport (like SSL). The WP installation from WP.org should have an integrated SSL solution instead of those plugins etc. Most of them are not that easy to install. Lots of bloggers blog 'on the road' and are vulnerable to sniffing.

Back on the strong password topic; try using passphrases. Those are generally longer than 8 to 10 characters, and pretty easy to remember</description>
		<content:encoded><![CDATA[<p>what&#8217;s the use of strong passwords when your no using an encrypted transport (like SSL). The WP installation from WP.org should have an integrated SSL solution instead of those plugins etc. Most of them are not that easy to install. Lots of bloggers blog &#8216;on the road&#8217; and are vulnerable to sniffing.</p>
<p>Back on the strong password topic; try using passphrases. Those are generally longer than 8 to 10 characters, and pretty easy to remember</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Titel</title>
		<link>http://weblogtoolscollection.com/archives/2007/06/07/how-strong-is-your-password/#comment-1161389</link>
		<dc:creator>Titel</dc:creator>
		<pubDate>Thu, 07 Jun 2007 22:01:03 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/06/07/how-strong-is-your-password/#comment-1161389</guid>
		<description>The degree of vulnerability of automated systems is not given by technology, but by human error. Successful crackers rely on social engineering instead of brute force; technology is simply much more powerful than people.

I believe it's wrong to look only at the password's complexity and say when it is secure and when not. If the user doesn't change the password for years, it's just as bad as an easy to guess password. If the password is written on a post-it on the screen or under the keyboard, it's useless. If the password is "password", the user should pack the computer and send it back to the store.

A good password is one that: is difficult to memorize (not a word, not a number, definitely not something in the dictionary), is changed periodically, is not written down in clear. For their own convenience, people make the mistake of choosing easy to remember passwords, but these are also easy to guess or easy to be remembered by others who happen to take a glimpse at the password written down in your Moleskin. Make it hard for others to accidentally learn your password; you'll be typing it every day, and you'll learn it in a few days, but others should not be able to reproduce it even after staring at it for 10 seconds.

Try this: 8 lowercase characters and no vowels (more difficult to learn, unable to pronounce), having symbols on alternating sides of the keyboard (so you can type them fast with both hands). Examples: t8zj2yqk, wj4nv9qh, mrj1yvp3. Yeah, they don't make sense, and that's the point. Type them 20-30 times over 2 or 3 days, and you'll be surprised how easy they come back to mind.

Want to write your password somewhere in plain sight but hidden from untrained eyes? Write a block of 8 lines, 8 characters per line - also numbers and consonants. Write your password on the sixth column, from the bottom up. Don't tell anyone what those letters and numbers are, why you carry them in your wallet, and how the block should be read.

Voila!</description>
		<content:encoded><![CDATA[<p>The degree of vulnerability of automated systems is not given by technology, but by human error. Successful crackers rely on social engineering instead of brute force; technology is simply much more powerful than people.</p>
<p>I believe it&#8217;s wrong to look only at the password&#8217;s complexity and say when it is secure and when not. If the user doesn&#8217;t change the password for years, it&#8217;s just as bad as an easy to guess password. If the password is written on a post-it on the screen or under the keyboard, it&#8217;s useless. If the password is &#8220;password&#8221;, the user should pack the computer and send it back to the store.</p>
<p>A good password is one that: is difficult to memorize (not a word, not a number, definitely not something in the dictionary), is changed periodically, is not written down in clear. For their own convenience, people make the mistake of choosing easy to remember passwords, but these are also easy to guess or easy to be remembered by others who happen to take a glimpse at the password written down in your Moleskin. Make it hard for others to accidentally learn your password; you&#8217;ll be typing it every day, and you&#8217;ll learn it in a few days, but others should not be able to reproduce it even after staring at it for 10 seconds.</p>
<p>Try this: 8 lowercase characters and no vowels (more difficult to learn, unable to pronounce), having symbols on alternating sides of the keyboard (so you can type them fast with both hands). Examples: t8zj2yqk, wj4nv9qh, mrj1yvp3. Yeah, they don&#8217;t make sense, and that&#8217;s the point. Type them 20-30 times over 2 or 3 days, and you&#8217;ll be surprised how easy they come back to mind.</p>
<p>Want to write your password somewhere in plain sight but hidden from untrained eyes? Write a block of 8 lines, 8 characters per line - also numbers and consonants. Write your password on the sixth column, from the bottom up. Don&#8217;t tell anyone what those letters and numbers are, why you carry them in your wallet, and how the block should be read.</p>
<p>Voila!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jenny</title>
		<link>http://weblogtoolscollection.com/archives/2007/06/07/how-strong-is-your-password/#comment-1161387</link>
		<dc:creator>Jenny</dc:creator>
		<pubDate>Thu, 07 Jun 2007 21:12:55 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/06/07/how-strong-is-your-password/#comment-1161387</guid>
		<description>I need to think about this too on some stuff. I tend to choose stuff that's easy for ME to remember. I guess I could be setting myself up for disaster.</description>
		<content:encoded><![CDATA[<p>I need to think about this too on some stuff. I tend to choose stuff that&#8217;s easy for ME to remember. I guess I could be setting myself up for disaster.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Bradley</title>
		<link>http://weblogtoolscollection.com/archives/2007/06/07/how-strong-is-your-password/#comment-1161384</link>
		<dc:creator>David Bradley</dc:creator>
		<pubDate>Thu, 07 Jun 2007 19:48:23 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/06/07/how-strong-is-your-password/#comment-1161384</guid>
		<description>I figured the chemical formula approach, coupled with a very simple algorithm, like reverse the formula would basically be unforgettable and produce relatively complex passwords that would generally not succumb to bruteforce attacks, unless someone has a chemical dictionary to hand of course. But, then you could always pick a compound like vancomycin tack on its molecular weight to several significant figures and then apply your algo. e.g start with C66H75Cl2N9O24 add the molecular weight, 1449.2536 without the decimal point and apply your personal system, chop of the ends, reverse it, remove the numbers and put them at the front, whatever...

db</description>
		<content:encoded><![CDATA[<p>I figured the chemical formula approach, coupled with a very simple algorithm, like reverse the formula would basically be unforgettable and produce relatively complex passwords that would generally not succumb to bruteforce attacks, unless someone has a chemical dictionary to hand of course. But, then you could always pick a compound like vancomycin tack on its molecular weight to several significant figures and then apply your algo. e.g start with C66H75Cl2N9O24 add the molecular weight, 1449.2536 without the decimal point and apply your personal system, chop of the ends, reverse it, remove the numbers and put them at the front, whatever&#8230;</p>
<p>db</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mario</title>
		<link>http://weblogtoolscollection.com/archives/2007/06/07/how-strong-is-your-password/#comment-1161383</link>
		<dc:creator>Mario</dc:creator>
		<pubDate>Thu, 07 Jun 2007 19:19:31 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/06/07/how-strong-is-your-password/#comment-1161383</guid>
		<description>I did several internal assessment over password strength in my company and usually at least 30-40% of the passwords are too weak (things like you name, you surname, you company ID and so on)....
Passwords ARE the weak point. I also run penetration test and the other source of weakness are the software maintenance. You cannot do a lot against unpatched vulnerability, but the lack of update is often the key to break system security....
So, a check to your password is a good point to start....</description>
		<content:encoded><![CDATA[<p>I did several internal assessment over password strength in my company and usually at least 30-40% of the passwords are too weak (things like you name, you surname, you company ID and so on)&#8230;.<br />
Passwords ARE the weak point. I also run penetration test and the other source of weakness are the software maintenance. You cannot do a lot against unpatched vulnerability, but the lack of update is often the key to break system security&#8230;.<br />
So, a check to your password is a good point to start&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jason</title>
		<link>http://weblogtoolscollection.com/archives/2007/06/07/how-strong-is-your-password/#comment-1161381</link>
		<dc:creator>Jason</dc:creator>
		<pubDate>Thu, 07 Jun 2007 18:56:37 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/06/07/how-strong-is-your-password/#comment-1161381</guid>
		<description>Chemical compositions ... why haven't I thought of it before?!?!?!

After having my password hacked in high school (back in 1994 ...) I started using phrases at least 14 characters in length made up of names, the greek alphabet, numbers and, in some cases, punctuation marks.  To keep things secure, these passwords are changed every month and never used twice.

So far, I've only forgotten one password ....</description>
		<content:encoded><![CDATA[<p>Chemical compositions &#8230; why haven&#8217;t I thought of it before?!?!?!</p>
<p>After having my password hacked in high school (back in 1994 &#8230;) I started using phrases at least 14 characters in length made up of names, the greek alphabet, numbers and, in some cases, punctuation marks.  To keep things secure, these passwords are changed every month and never used twice.</p>
<p>So far, I&#8217;ve only forgotten one password &#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Bradley</title>
		<link>http://weblogtoolscollection.com/archives/2007/06/07/how-strong-is-your-password/#comment-1161374</link>
		<dc:creator>David Bradley</dc:creator>
		<pubDate>Thu, 07 Jun 2007 17:10:24 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/06/07/how-strong-is-your-password/#comment-1161374</guid>
		<description>I thought of a neat way to create memorable passwords if you are a scientist (or actually anyone else for that matter)

http://www.sciencetext.com/passwords-for-scientists.html

Anyone care to create such a password for a complex compound and test it with the strength meter?

db</description>
		<content:encoded><![CDATA[<p>I thought of a neat way to create memorable passwords if you are a scientist (or actually anyone else for that matter)</p>
<p><a href="http://www.sciencetext.com/passwords-for-scientists.html">http://www.sciencetext.com/pas.....tists.html</a></p>
<p>Anyone care to create such a password for a complex compound and test it with the strength meter?</p>
<p>db</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark Ghosh</title>
		<link>http://weblogtoolscollection.com/archives/2007/06/07/how-strong-is-your-password/#comment-1161371</link>
		<dc:creator>Mark Ghosh</dc:creator>
		<pubDate>Thu, 07 Jun 2007 16:39:26 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/06/07/how-strong-is-your-password/#comment-1161371</guid>
		<description>:) I do assume, but I thought "someone guessed my not-at-all secure password to this blog" said it all.</description>
		<content:encoded><![CDATA[<p> <img src='http://weblogtoolscollection.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> I do assume, but I thought &#8220;someone guessed my not-at-all secure password to this blog&#8221; said it all.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lloyd Budd</title>
		<link>http://weblogtoolscollection.com/archives/2007/06/07/how-strong-is-your-password/#comment-1161370</link>
		<dc:creator>Lloyd Budd</dc:creator>
		<pubDate>Thu, 07 Jun 2007 16:36:26 +0000</pubDate>
		<guid isPermaLink="false">http://weblogtoolscollection.com/archives/2007/06/07/how-strong-is-your-password/#comment-1161370</guid>
		<description>You assume what Matt's problem was. What if at the time it was insecure for some other reason  ;-)</description>
		<content:encoded><![CDATA[<p>You assume what Matt&#8217;s problem was. What if at the time it was insecure for some other reason  <img src='http://weblogtoolscollection.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
</channel>
</rss>
