<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: How To Create A Good Password That You Will Not Forget</title>
	<atom:link href="http://www.makeuseof.com/tag/create-strong-password-forget/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.makeuseof.com/tag/create-strong-password-forget/</link>
	<description>Cool Websites, Software and Internet Tips</description>
	<lastBuildDate>Fri, 10 Feb 2012 23:43:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: OklyDokly</title>
		<link>http://www.makeuseof.com/tag/create-strong-password-forget/#comment-444386</link>
		<dc:creator>OklyDokly</dc:creator>
		<pubDate>Mon, 15 Mar 2010 15:10:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.makeuseof.com/?p=35102#comment-444386</guid>
		<description>So, I&#039;m curious as to why more companies aren&#039;t going the route of OTP + password for authorization...game companies are doing it, some banks are, but not all...

Sure, you have the risk of losing your OTP generator, but without your password, that OTP generator is useless, and vice versa.

The fact of the matter is this:  Try and try as hard as you might, you will never be able to completely prevent/thwart social engineering.  Yes, you can brute force or dictionary hack passwords in some cases, but the vast majority of security compromises occur through social engineering.</description>
		<content:encoded><![CDATA[<p>So, I&#8217;m curious as to why more companies aren&#8217;t going the route of OTP + password for authorization&#8230;game companies are doing it, some banks are, but not all&#8230;</p>
<p>Sure, you have the risk of losing your OTP generator, but without your password, that OTP generator is useless, and vice versa.</p>
<p>The fact of the matter is this:  Try and try as hard as you might, you will never be able to completely prevent/thwart social engineering.  Yes, you can brute force or dictionary hack passwords in some cases, but the vast majority of security compromises occur through social engineering.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: RAJ KIAN</title>
		<link>http://www.makeuseof.com/tag/create-strong-password-forget/#comment-440649</link>
		<dc:creator>RAJ KIAN</dc:creator>
		<pubDate>Tue, 02 Mar 2010 06:05:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.makeuseof.com/?p=35102#comment-440649</guid>
		<description>earlier i used to use pw as 123456 or even 123456789.
my frnd use qwertyuiop or zxcvbnm. 
but currently i hv 2 ytp of pw.or 3.
for myspace its 7letters tgen 3 nos.
fb,twitter etc. its 7+7=14 letters thats very big. Well its combo of 2 words. n i bliv dat its next 2 impossible to crack it. 
oh n the 3rd one is 7letters dats 2nd part of my earlier pw.

another thing which every1 shud keep in mind. Always make it a point to hv ur pw in CAPITAL LETTERS if u find it difficult 2 rember mix of upper n lower case.
i use caps. n dey say &quot;hey ur caps lock is on&quot;.</description>
		<content:encoded><![CDATA[<p>earlier i used to use pw as 123456 or even 123456789.<br />
my frnd use qwertyuiop or zxcvbnm.<br />
but currently i hv 2 ytp of pw.or 3.<br />
for myspace its 7letters tgen 3 nos.<br />
fb,twitter etc. its 7+7=14 letters thats very big. Well its combo of 2 words. n i bliv dat its next 2 impossible to crack it.<br />
oh n the 3rd one is 7letters dats 2nd part of my earlier pw.</p>
<p>another thing which every1 shud keep in mind. Always make it a point to hv ur pw in CAPITAL LETTERS if u find it difficult 2 rember mix of upper n lower case.<br />
i use caps. n dey say &#8220;hey ur caps lock is on&#8221;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Montana</title>
		<link>http://www.makeuseof.com/tag/create-strong-password-forget/#comment-440307</link>
		<dc:creator>Montana</dc:creator>
		<pubDate>Sun, 28 Feb 2010 13:59:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.makeuseof.com/?p=35102#comment-440307</guid>
		<description>You know what, these banks &amp; email hosts would be almost completely hacker-proof if they maybe did something where the password was encrypted with two layers of security -- one, SSL, the other, an encryption algorithm that uses IP addresses.  With so many different IP addresses, and the ability to change them every now and then, it would be hard for hackers to decipher the password.</description>
		<content:encoded><![CDATA[<p>You know what, these banks &amp; email hosts would be almost completely hacker-proof if they maybe did something where the password was encrypted with two layers of security &#8212; one, SSL, the other, an encryption algorithm that uses IP addresses.  With so many different IP addresses, and the ability to change them every now and then, it would be hard for hackers to decipher the password.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jay</title>
		<link>http://www.makeuseof.com/tag/create-strong-password-forget/#comment-440124</link>
		<dc:creator>jay</dc:creator>
		<pubDate>Sat, 27 Feb 2010 17:20:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.makeuseof.com/?p=35102#comment-440124</guid>
		<description>i use my dob as my pasword,easy to remember</description>
		<content:encoded><![CDATA[<p>i use my dob as my pasword,easy to remember</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael</title>
		<link>http://www.makeuseof.com/tag/create-strong-password-forget/#comment-440123</link>
		<dc:creator>Michael</dc:creator>
		<pubDate>Sat, 27 Feb 2010 17:06:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.makeuseof.com/?p=35102#comment-440123</guid>
		<description>Hi Buffet 
â€œTestâ€ your password? â€“ like Iâ€™m gonna fall for that! Please
Other people seem to have missed this point.
I love your comment of only 10 words.
Like love ,it changes everything.</description>
		<content:encoded><![CDATA[<p>Hi Buffet<br />
â€œTestâ€ your password? â€“ like Iâ€™m gonna fall for that! Please<br />
Other people seem to have missed this point.<br />
I love your comment of only 10 words.<br />
Like love ,it changes everything.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Versatile</title>
		<link>http://www.makeuseof.com/tag/create-strong-password-forget/#comment-440022</link>
		<dc:creator>Versatile</dc:creator>
		<pubDate>Fri, 26 Feb 2010 22:02:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.makeuseof.com/?p=35102#comment-440022</guid>
		<description>I currently use a great website called mashedlife.com. I use a yubikey to login for secure authentication, and all my passwords for all my online accounts are housed here.

I use the random system to generate random and complex passwords for each and every single online account I have.

When people ask me if I know my passwords, I literally say no I do not. In fact, if you asked me what my gmail password is off the top of my head, I honestly could not tell you because I have literally 0 passwords memorized except the main password I use to login to mashedlife.com with yubikey as the second form of online protection.

The mashedlife.com website is never down based on my usage, and the passwords are encrypted. Sure, lastpass.com is similar site, but in general I think these are good solutions.</description>
		<content:encoded><![CDATA[<p>I currently use a great website called mashedlife.com. I use a yubikey to login for secure authentication, and all my passwords for all my online accounts are housed here.</p>
<p>I use the random system to generate random and complex passwords for each and every single online account I have.</p>
<p>When people ask me if I know my passwords, I literally say no I do not. In fact, if you asked me what my gmail password is off the top of my head, I honestly could not tell you because I have literally 0 passwords memorized except the main password I use to login to mashedlife.com with yubikey as the second form of online protection.</p>
<p>The mashedlife.com website is never down based on my usage, and the passwords are encrypted. Sure, lastpass.com is similar site, but in general I think these are good solutions.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David</title>
		<link>http://www.makeuseof.com/tag/create-strong-password-forget/#comment-439986</link>
		<dc:creator>David</dc:creator>
		<pubDate>Fri, 26 Feb 2010 19:41:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.makeuseof.com/?p=35102#comment-439986</guid>
		<description>A comment on passwordmeter.com. I am currently working on a website for a large government agency. As part of the registration process, it is necessary to choose a password. The decision was made to incorporate the password meter into the sign-on page. In the  process of doing this, I discovered an enormous bug in the password strength algorithm - which is the root cause for 

&quot;However, if your password is too long, i.e. too safe, this test will actually fail.&quot;

It has to do with the way it calculates the number of repeated characters - which is a major deduction in the algorithm. Consider a password like &quot;EIDIDIFY&quot; from the beginning of the article.

There are 2 Ds and 3 Is in the password, for a total of 5 repeated characters. Deduction for 5 repeated characters is n*n-1 or 5*4 or 20. However, because the algorithm bug to count this determines the number by looking through the string starting at the first character and looks at each character in turn to find matches. Then looks at the next character in the string and parses again til the end, whenever there is more than 2 of any character, you get characters counted more than once. In this case the first I matches two other Is in the string. Then when you get to the second I (in pass 4), it matches the last I also. The result is the algorithm thinks there are 3 I&#039;s, 2 D&#039;s, and then another 2 I&#039;s, for a total of 7 repeated characters. 7*6=42 which is a huge deduction. If there was a third D as well, the algorithm would find 10 repeated characters for a deduction of 90. That explains why a STRONG password can turn into a WEAK password by making it longer.</description>
		<content:encoded><![CDATA[<p>A comment on passwordmeter.com. I am currently working on a website for a large government agency. As part of the registration process, it is necessary to choose a password. The decision was made to incorporate the password meter into the sign-on page. In the  process of doing this, I discovered an enormous bug in the password strength algorithm &#8211; which is the root cause for </p>
<p>&#8220;However, if your password is too long, i.e. too safe, this test will actually fail.&#8221;</p>
<p>It has to do with the way it calculates the number of repeated characters &#8211; which is a major deduction in the algorithm. Consider a password like &#8220;EIDIDIFY&#8221; from the beginning of the article.</p>
<p>There are 2 Ds and 3 Is in the password, for a total of 5 repeated characters. Deduction for 5 repeated characters is n*n-1 or 5*4 or 20. However, because the algorithm bug to count this determines the number by looking through the string starting at the first character and looks at each character in turn to find matches. Then looks at the next character in the string and parses again til the end, whenever there is more than 2 of any character, you get characters counted more than once. In this case the first I matches two other Is in the string. Then when you get to the second I (in pass 4), it matches the last I also. The result is the algorithm thinks there are 3 I&#8217;s, 2 D&#8217;s, and then another 2 I&#8217;s, for a total of 7 repeated characters. 7*6=42 which is a huge deduction. If there was a third D as well, the algorithm would find 10 repeated characters for a deduction of 90. That explains why a STRONG password can turn into a WEAK password by making it longer.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JoÃ£o Brito</title>
		<link>http://www.makeuseof.com/tag/create-strong-password-forget/#comment-439635</link>
		<dc:creator>JoÃ£o Brito</dc:creator>
		<pubDate>Wed, 24 Feb 2010 17:57:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.makeuseof.com/?p=35102#comment-439635</guid>
		<description>My system for passwords works like this: I created ONE huge password with TWENTY characters, and I remember this one easily. For things that aren&#039;t that important, I use the first six chars. For things that are somewhat important, I use the first ten chars. And for things that are really really important I use the whole 20 chars password. So far, so good.
But I liked the suggestion of using the three first letters of each service after the password, it will make my six chars password a little stronger.</description>
		<content:encoded><![CDATA[<p>My system for passwords works like this: I created ONE huge password with TWENTY characters, and I remember this one easily. For things that aren&#8217;t that important, I use the first six chars. For things that are somewhat important, I use the first ten chars. And for things that are really really important I use the whole 20 chars password. So far, so good.<br />
But I liked the suggestion of using the three first letters of each service after the password, it will make my six chars password a little stronger.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Buffet</title>
		<link>http://www.makeuseof.com/tag/create-strong-password-forget/#comment-439453</link>
		<dc:creator>Buffet</dc:creator>
		<pubDate>Tue, 23 Feb 2010 09:45:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.makeuseof.com/?p=35102#comment-439453</guid>
		<description>&quot;Test&quot; your password? - like I&#039;m gonna fall for that! Please.</description>
		<content:encoded><![CDATA[<p>&#8220;Test&#8221; your password? &#8211; like I&#8217;m gonna fall for that! Please.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Parand</title>
		<link>http://www.makeuseof.com/tag/create-strong-password-forget/#comment-439443</link>
		<dc:creator>Parand</dc:creator>
		<pubDate>Tue, 23 Feb 2010 04:45:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.makeuseof.com/?p=35102#comment-439443</guid>
		<description>It&#039;s easy to create strong passwords that you can also remember: 

http://parand.com/say/index.php/2006/03/09/choosing-a-good-password/

In short:

Think of a sentence you wonâ€™t forget. Hereâ€™s one:

I hate thinking of passwords, itâ€™s such a hassle.

If you really canâ€™t think of one, pick up the closest book to you, turn to a random page, and select a random sentence.

Now, create the password as the first letter of each word in the sentence:

Ihtop,isah

There you go. That is a password that is hard to crack, but easy to remember. Because you just remember the sentence.</description>
		<content:encoded><![CDATA[<p>It&#8217;s easy to create strong passwords that you can also remember: </p>
<p><a href="http://parand.com/say/index.php/2006/03/09/choosing-a-good-password/" rel="nofollow">http://parand.com/say/index.php/2006/03/09/choosing-a-good-password/</a></p>
<p>In short:</p>
<p>Think of a sentence you wonâ€™t forget. Hereâ€™s one:</p>
<p>I hate thinking of passwords, itâ€™s such a hassle.</p>
<p>If you really canâ€™t think of one, pick up the closest book to you, turn to a random page, and select a random sentence.</p>
<p>Now, create the password as the first letter of each word in the sentence:</p>
<p>Ihtop,isah</p>
<p>There you go. That is a password that is hard to crack, but easy to remember. Because you just remember the sentence.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached (Requested URI is rejected)
Database Caching 1/5 queries in 0.006 seconds using apc
Object Caching 300/300 objects using disk: basic
Content Delivery Network via main.makeuseoflimited.netdna-cdn.com

Served from: www.makeuseof.com @ 2012-02-10 23:58:59 -->
