sketchucation logo sketchucation
    • 登入
    Oops, your profile's looking a bit empty! To help us tailor your experience, please fill in key details like your SketchUp version, skill level, operating system, and more. Update and save your info on your profile page today!
    ⚠️ Important | Libfredo 15.6b introduces important bugfixes for Fredo's Extensions Update

    Passphrases over passwords

    已排程 已置頂 已鎖定 已移動 Corner Bar
    21 貼文 12 Posters 689 瀏覽 12 Watching
    正在載入更多貼文
    • 從舊到新
    • 從新到舊
    • 最多點贊
    回覆
    • 在新貼文中回覆
    登入後回覆
    此主題已被刪除。只有擁有主題管理權限的使用者可以查看。
    • thomthomT 離線
      thomthom
      最後由 編輯

      Interesting article on passwords:
      http://www.zdnet.com/blog/identity/your-passwords-dont-suck-its-your-policies/482

      http://passfault.com/


      And off course:

      http://imgs.xkcd.com/comics/password_strength.png

      😉

      Thomas Thomassen — SketchUp Monkey & Coding addict
      List of my plugins and link to the CookieWare fund

      1 條回覆 最後回覆 回覆 引用 0
      • Rich O BrienR 離線
        Rich O Brien Moderator
        最後由 編輯

        that's crazy...

        most my passwords were cracked withing a year and these were LastPass auto-generated things. I tried ihearmonkeyscodinginethedark and it was pretty secure so I recommend people using that one 👍

        Download the free D'oh Book for SketchUp 📖

        1 條回覆 最後回覆 回覆 引用 0
        • HieruH 離線
          Hieru
          最後由 編輯

          I use the supposedly easy to guess encryption method, but for my most used password the crack time came in at 7768924 centuries.

          www.davidhier.co.uk

          1 條回覆 最後回覆 回覆 引用 0
          • thomthomT 離線
            thomthom
            最後由 編輯

            I've begun to use pass phrases - several words, with spaces if possible - makes it easier to remember and it makes them difficult to crack. Especially if I use a sentence with a number occurring naturally along with punctuation. On top of that I use Norwegian phrases.

            Thomas Thomassen — SketchUp Monkey & Coding addict
            List of my plugins and link to the CookieWare fund

            1 條回覆 最後回覆 回覆 引用 0
            • HieruH 離線
              Hieru
              最後由 編輯

              Yes, I certainly think that pass phrases are the way to go and I'll be using them in the future. My example is probably the exception to the rule.

              www.davidhier.co.uk

              1 條回覆 最後回覆 回覆 引用 0
              • Dave RD 離線
                Dave R
                最後由 編輯

                According to Passfault, my password for here would take 33 years to crack. It says there are 1000 trillion passwords in the pattern. I suppose I should look for a more secure password. If I add a number at the end it says it would take 44 centuries to crack and there are 132 quadrillion passwords in the pattern. Of course how would we know that's true?

                Etaoin Shrdlu

                %

                (THERE'S NO PLACE LIKE)

                G28 X0.0 Y0.0 Z0.0

                M30

                %

                1 條回覆 最後回覆 回覆 引用 0
                • E 離線
                  Ecuadorian
                  最後由 編輯

                  But, but... Wouldn't a multi-language dictionary attack crack any passphrase... ?

                  -Miguel Lescano
                  Subscribe to my house plans YouTube channel! (30K+ subs)

                  1 條回覆 最後回覆 回覆 引用 0
                  • thomthomT 離線
                    thomthom
                    最後由 編輯

                    @ecuadorian said:

                    But, but... Wouldn't a multi-language dictionary attack crack any passphrase... ?

                    Within what time?
                    All passwords can be cracked - but the key is to make them so time-consuming it's virtually impossible. See the XKCD cartoon I embedded. It explains the pass phrase entropy.

                    Thomas Thomassen — SketchUp Monkey & Coding addict
                    List of my plugins and link to the CookieWare fund

                    1 條回覆 最後回覆 回覆 引用 0
                    • mitcorbM 離線
                      mitcorb
                      最後由 編輯

                      [off:3pqnnh45]When you open Sketchup, it phones home. How secure is that?[/off:3pqnnh45]

                      I take the slow, deliberate approach in my aimless wandering.

                      1 條回覆 最後回覆 回覆 引用 0
                      • thomthomT 離線
                        thomthom
                        最後由 編輯

                        @mitcorb said:

                        [off:glmffd5e]When you open Sketchup, it phones home. How secure is that?[/off:glmffd5e]

                        It checks for software updates. What is your security concern against phoning home?

                        Thomas Thomassen — SketchUp Monkey & Coding addict
                        List of my plugins and link to the CookieWare fund

                        1 條回覆 最後回覆 回覆 引用 0
                        • mitcorbM 離線
                          mitcorb
                          最後由 編輯

                          I was just wondering in general how secure that channel might be, not necessarily Sketchup, but any software that uses this method.

                          I take the slow, deliberate approach in my aimless wandering.

                          1 條回覆 最後回覆 回覆 引用 0
                          • EscapeArtistE 離線
                            EscapeArtist
                            最後由 編輯

                            I thinks it's a fine idea to use pass phrases instead of passwords, but we need to get website security on board as well. Many limit the length of password you can use, 6-18 characters or so. 18 characters isn't bad, but I've some limited to 12 or less.

                            1 條回覆 最後回覆 回覆 引用 0
                            • pilouP 離線
                              pilou
                              最後由 編輯

                              And what is your certitude of this site http://passfault.com/ is not made by little astucious clever unfair people ???

                              Very practical for recover some of them without effort! 😒
                              Make a data base with them and launch this list first so some times won in brute force for research to break secret paswords! 🤓

                              So don't test your own passward but a variation! 💚
                              And even with that it's more easy to find some thing than from nothing! 😉

                              Frenchy Pilou
                              Is beautiful that please without concept!
                              My Little site :)

                              1 條回覆 最後回覆 回覆 引用 0
                              • A 離線
                                Aerilius
                                最後由 編輯

                                Pilou is right to be skeptical (about things on the internet). It's unlikely that that site fools people to believe their passwords are secure (therefore the algorithm is enough comprehensible). But:
                                • I wouldn't submit my real passwords to check them (only analogue patterns).
                                • And I wouln't use online password generators (even if they are not evil, what if they are once cracked themselves? What if the served passwords are reproducible after it was cracked?)

                                1 條回覆 最後回覆 回覆 引用 0
                                • thomthomT 離線
                                  thomthom
                                  最後由 編輯

                                  @escapeartist said:

                                  I thinks it's a fine idea to use pass phrases instead of passwords, but we need to get website security on board as well. Many limit the length of password you can use, 6-18 characters or so. 18 characters isn't bad, but I've some limited to 12 or less.

                                  I recently sent a frustrated email to my bank - they limited the password to a-z,A-Z,0-9 ... a banking site! FFS!

                                  Thomas Thomassen — SketchUp Monkey & Coding addict
                                  List of my plugins and link to the CookieWare fund

                                  1 條回覆 最後回覆 回覆 引用 0
                                  • brookefoxB 離線
                                    brookefox
                                    最後由 編輯

                                    Ah, banks.

                                    They already have your money.

                                    [off:a2hfkqdz]I just finished my second bite back of one which tried to screw me out of the full, if modest, value of a checking account. Then with their new charges they put the account into negative territory and threatened collection which they said would ding my credit rating. The federal Office of the Comptroller and then their later morph took my form letters and the banks came around, the last time with a call form a special rep of the CEO, acknowledging the mistake....right.[/off:a2hfkqdz]

                                    ~ Brooke

                                    1 條回覆 最後回覆 回覆 引用 0
                                    • pilouP 離線
                                      pilou
                                      最後由 編輯

                                      and the code of your credit card is not 4 numbers ? 😉

                                      Frenchy Pilou
                                      Is beautiful that please without concept!
                                      My Little site :)

                                      1 條回覆 最後回覆 回覆 引用 0
                                      • TIGT 離線
                                        TIG Moderator
                                        最後由 編輯

                                        Here's an interesting thought about your ID... and how we've all been sucked into way of thinking that is counter productive, and less secure as a result...
                                        http://www.ted.com/talks/lang/en/david_birch_identity_without_a_name.html
                                        For example, why does your bank card need your name, branch code and account number on it ?
                                        This is only useful to a thief trying to steal your identity... but it's of no use to any one taking your card details for a legitimate transaction... 😲

                                        TIG

                                        1 條回覆 最後回覆 回覆 引用 0
                                        • E 離線
                                          Ecuadorian
                                          最後由 編輯

                                          I keep hearing about identity theft in the US. Never heard of it down here (fingers crossed). 😕 Maybe it's because here you always have to show your original citizen ID (called "cédula") when doing transactions, and some banks even digitize your fingerprint when cashing a cheque? Our ID card has more security features than a passport...


                                          cedula.JPG

                                          -Miguel Lescano
                                          Subscribe to my house plans YouTube channel! (30K+ subs)

                                          1 條回覆 最後回覆 回覆 引用 0
                                          • Chris FullmerC 離線
                                            Chris Fullmer
                                            最後由 編輯

                                            passfault didn't work for me. How does it return the result? does it take 550 years to return the answer? Or am I just not seeing it?

                                            Lately you've been tan, suspicious for the winter.
                                            All my Plugins I've written

                                            1 條回覆 最後回覆 回覆 引用 0
                                            • 1
                                            • 2
                                            • 1 / 2
                                            • 第一個貼文
                                              最後的貼文
                                            Buy SketchPlus
                                            Buy SUbD
                                            Buy WrapR
                                            Buy eBook
                                            Buy Modelur
                                            Buy Vertex Tools
                                            Buy SketchCuisine
                                            Buy FormFonts

                                            Advertisement