If you can read this, either the style sheet didn't load or you have an older browser that doesn't support style sheets. Try clearing your browser cache and refreshing the page.

(CNN) Sad It used to be that 8 was enough, but more and more it's starting to look like if you're not packing at least 12, you're just too small   (cnn.com) divider line 237
More: Sad  
•       •       •

39965 clicks; posted to Main » on 20 Aug 2010 at 3:27 PM   |  Favorite    |   share:  Share on Twitter share via Email Share on Facebook   more»   |    Get this fabulous T-Shirt and impress the methane out of your friends! shirt it!



237 Comments   (+0 »)
   

Archived thread

First | « | 1 | 2 | 3 | 4 | 5 | » | Last | Show all
 
2010-08-20 02:56:57 PM
Good thing I've got 14.
 
2010-08-20 02:57:31 PM
imgs.xkcd.com

Here you go.
 
2010-08-20 03:11:21 PM
tvphotogalleries.com

/hot

//is it me or does the lighting and shadow make their noses look really freaky?
 
2010-08-20 03:29:55 PM
I would post the

" Hey! Did you know that Fark automatically filters your password? Look: ******** "

joke, but with my luck some fool farker would fall for it and I'd get banned for a week...
 
2010-08-20 03:31:15 PM
KeePassX (new window)

And never struggle with passwords or worry about their strength or security again. It's free....You're welcome.
 
2010-08-20 03:31:57 PM
meh, I use passages from the bible for my password...

/JUST KIDDING!!!!!!
 
2010-08-20 03:32:25 PM
I love how they give no numbers, no real information, and just basically say "By using GPUs we can crack passwords faster!"

I want to see data. How many GPUs did they use? What type of password hashing algorithm were they attacking? What type of attack were they attempting?

I've searched online, and as far as I can tell, this is nothing more than "the sky is falling" and fear mongering, or at least, the media misconstruing the results of this "research."

If someone has a link to actual data, I'd LOVE it!
 
2010-08-20 03:32:41 PM
Each character in my password needs the "alt" key and 4 digits.
 
2010-08-20 03:32:51 PM
Sounds like your typical 'Merican theme wherein neocons channel the nazi mentality in a knee-jerk reaction to those who have different (aka: non Christian) beliefs. "Hate is enough" indeed...
 
2010-08-20 03:32:55 PM
Why wouldn't a 1 minute delay after every 5 failed attempts squash this in the bud?
 
2010-08-20 03:33:24 PM
Lt. Cheese Weasel: KeePassX (new window)

And never struggle with passwords or worry about their strength or security again. It's free....You're welcome.


man,.I don't want to know what assX is, let alone keep it...
 
2010-08-20 03:33:25 PM
vernonFL: /hot

//is it me or does the lighting and shadow make their noses look really freaky?


www.secure-power.com
 
2010-08-20 03:33:38 PM
It would be okay if it wasn't for the fact that everything wants you to have a damn password. The computers at my work require 4 passwords per action on average. Not everything needs to be so damn secure. I need passwords for the memberships to every damn store that harasses you until you get their free discount card.
 
2010-08-20 03:33:49 PM
My password is 12345
 
2010-08-20 03:35:52 PM
From the link in the article:
"Now take the first letter of every word in the [password generating] sentence, and include the punctuation. You can throw in extra punctuation, or turn numbers into digits for variety"

That is f*cking brilliant. It creates incredibly nonsensical passwords and is super easy to remember. I'm going to do this with all my passwords as soon as I get home.

/can't believe I haven't seen this anywhere before
 
2010-08-20 03:36:01 PM
I have a biometric breathalyzer on my computer. If it can't detect my DNA and at least a .04 BAC when I blow in the tube, it won't unlock.
 
2010-08-20 03:36:25 PM
Ninja Wicked: My password is 12345

great, now i have to change the combination on my luggage
 
2010-08-20 03:36:27 PM
rFarke: Lt. Cheese Weasel: KeePassX (new window)

And never struggle with passwords or worry about their strength or security again. It's free....You're welcome.

man,.I don't want to know what assX is, let alone keep it...


Gosh, that was funny.

*watching the clock*...get me outa here and into a vodka tonic...asap.
 
2010-08-20 03:36:38 PM
i34.tinypic.com
 
2010-08-20 03:36:49 PM
It doesn't matter how many characters are in it if you leave it on a post-it note stuck to the side of your monitor...
 
2010-08-20 03:37:05 PM
Ninja Wicked: My password is 12345

www.filmdope.com
 
2010-08-20 03:37:06 PM
Ninja Wicked: My password is 12345

That's the kind of thing an IDIOT has on their Luggage!
 
2010-08-20 03:37:08 PM
jaylectricity: Each character in my password needs the "alt" key and 4 digits.

I almost read that as "alt and F4" and I thought wow that's pretty l33t.
 
Nib
2010-08-20 03:37:15 PM
my 6 digits are just fine.
 
2010-08-20 03:37:21 PM
Ninja Wicked: My password is 12345

Liar! I trusted you!
 
2010-08-20 03:37:54 PM
So, password length is important, but the fact that when you're on a http:// link YOU ARE PASSING THAT PASSWORD IN THE CLEAR isn't? If there's a https:// option, use it, and if there isn't, bug the webmaster until there is
 
2010-08-20 03:37:57 PM
I'm really surprised more places aren't using two-factor authentication. It's great that I need an RSA token to access my work VPN, and phenomenal that I need one for WoW.. but why the hell doesn't my bank issue them? Weird.
 
2010-08-20 03:38:01 PM
El Morro: From the link in the article:
"Now take the first letter of every word in the [password generating] sentence, and include the punctuation. You can throw in extra punctuation, or turn numbers into digits for variety"

That is f*cking brilliant. It creates incredibly nonsensical passwords and is super easy to remember. I'm going to do this with all my passwords as soon as I get home.

/can't believe I haven't seen this anywhere before


So, now everyones password will be either LOL, OMG or STFU.
 
2010-08-20 03:38:20 PM
From QDB:

#136524 +(9577)- [X]

I tried setting my hotmail password to penis.
It said my password wasn't long enough. :(

/gotta love bash.org
 
2010-08-20 03:38:30 PM
Mine is 10. not ten characters. the number 10.
 
2010-08-20 03:39:22 PM
Old school: Bewbs1975
Grad School: GObama2008
Back to School: Unemplyd2008
 
2010-08-20 03:39:34 PM
palelizard: I have a biometric breathalyzer on my computer. If it can't detect my DNA and at least a .04 BAC when I blow in the tube, it won't unlock.

wouldn't your boyfriend be able to log in almost all the time then?
 
2010-08-20 03:41:27 PM
gludlow: I love how they give no numbers, no real information, and just basically say "By using GPUs we can crack passwords faster!"

I want to see data. How many GPUs did they use? What type of password hashing algorithm were they attacking? What type of attack were they attempting?

I've searched online, and as far as I can tell, this is nothing more than "the sky is falling" and fear mongering, or at least, the media misconstruing the results of this "research."


Plus, don't most sites lock you out after a relatively small number of failed attempts?

It's not like you can line up the GPUs and start doing your attempted "1 trillion password combinations per second" until you eventually break in, and have the site/system be none the wiser.
 
2010-08-20 03:41:28 PM
My password is ************
 
2010-08-20 03:41:37 PM
No one mentioned Lastpass (www.lastpass.com) yet? One password to rule them all, then just right-click on password fields to generate secure passwords of any length...

This saves me a good 30min every week I would imagine...
 
2010-08-20 03:41:41 PM
g4lt: So, password length is important, but the fact that when you're on a http:// link YOU ARE PASSING THAT PASSWORD IN THE CLEAR isn't? If there's a https:// option, use it, and if there isn't, bug the webmaster until there is

Port 80 is in the clear. 443/https is a handshake agreement to encrypt the data stream between browser and server via certificates.
 
2010-08-20 03:41:57 PM
Some websites allow for super-long passwords. The longest one Boyd has seen is at Fidelity.com, a financial site that lets users create 32-character passwords.

believe it or not, Univeristy of Alabama in Birmingham's career site had a user login that could take a hundred characters for both the username and the password.
 
2010-08-20 03:41:58 PM
img38.imageshack.us
 
2010-08-20 03:42:03 PM
Lt. Cheese Weasel: turn numbers into digits for variety

Never would've thought of that one on my own.
 
2010-08-20 03:42:06 PM
Ninja Wicked: My password is *****

Strange.. all I saw was "*****"

Guess FARK's filters are getting better.
 
2010-08-20 03:42:37 PM
g4lt: So, password length is important, but the fact that when you're on a http:// link YOU ARE PASSING THAT PASSWORD IN THE CLEAR isn't? If there's a https:// option, use it, and if there isn't, bug the webmaster until there is

Not quite. The protocol for the URL that processes the form needs ot be https - you can load the form unencrypted though, just sending your info to the server is the important part.
 
2010-08-20 03:42:43 PM
We could go to 12 digit passwords, or you know, we could design systems that respond when you type in the wrong password more then 15 or 30 times in a row... 30 attempts and your IP is banned for a week, then for the next hour any 3 failed password attempts gets from any IP gets an hour ban. (even just the 30 attempt thing) But no, we should be required to memorize passwords that get ever longer because there is no way to detect millions of failed password attempts against a single account!
 
2010-08-20 03:42:59 PM

vernonFL



/hot

//is it me or does the lighting and shadow make their noses look really freaky?


Could be the camera lens.
 
2010-08-20 03:43:00 PM
Number,Number, Crazy symbols for the end.

I mean seriously, how hard could it be?

69DEADmau5?! FTW
 
2010-08-20 03:43:04 PM
skyotter
great, now i have to change the combination on my luggage

Mine's 54321. It's twice as cunning.

/still prefers yaddayaddayadda
 
2010-08-20 03:43:13 PM
Because you wouldn't want anyone getting into your account at DeviantArt and deleting all your furry porn.
 
2010-08-20 03:45:29 PM
vernonFL: /hot

//is it me or does the lighting and shadow make their noses look really freaky?


That's how everyone's nose looked in the 70's.
 
2010-08-20 03:45:47 PM
On systems that matter, my ID is disabled after three invalid logon attempts.

You would think that would make it pretty hard to "crack".

Of course none of the internet crap cares how many times you try to login so probably should increase the length of those accounts.
 
2010-08-20 03:46:42 PM
Lt. Cheese Weasel: g4lt: So, password length is important, but the fact that when you're on a http:// link YOU ARE PASSING THAT PASSWORD IN THE CLEAR isn't? If there's a https:// option, use it, and if there isn't, bug the webmaster until there is

Port 80 is in the clear. 443/https is a handshake agreement to encrypt the data stream between browser and server via certificates.


don't confuse protocols with ports. http://example.com:443 can still be valid, if extremely stupid
 
d3
2010-08-20 03:46:53 PM
Pocket Ninja: Good thing I've got 14.

Too bad you still use LM hash though.
 
Displayed 50 of 237 comments

First | « | 1 | 2 | 3 | 4 | 5 | » | Last | Show all


This thread is closed to new comments.

Continue Farking
Submit a Link »