Background Story
A relative and a couple of friends have had email or their Facebook account hacked recently. Over the past eight weeks, I have been taking a Network Penetration Testing class for my final three credits of my degree. One of the things that I have learned is that the resources to do this kind of hacking is far too easily obtained. One of the tasks that I have done in a hands on was to extract password hashes and account information from a remote computer and run a cracking program to get the passwords.
For those that are not savvy, when someone attacks your system or a website like Facebook, the passwords are "hashed". Hashing is a cryptographic means of encrypting the passwords on the computer so that they do not appear in plain text.
For example:
The common password used in school labs tends to be:
"Pa$$w0rd."
When an attacker gets your account info they see the hashed version which is:
"3cc31cd246149aec68079241e71e98f6"
So, the hacker uses a "cracking" tool to make that hash value into your password. There are various types of cracks including but not limited to:
- Dictionary - uses a word list of common words and common misspellings.
- Hybrid - like a dictionary crack but adds more symbols and "l33t" spellings.
- Brute Force - every combination of characters is tried until the entire password is revealed.
- Rainbow Tables - the hash is compared to a huge list of passwords found on other systems.
How do I defend myself?
The complete answer to this is far too much for this blog. The solution includes hardware (routers and firewalls), software (antivirus suites and intrusion detection), best practices (what not to do on the web), and general user education. So for today, we will focus on good password practices.The following are tips and not to be considered a complete solution.
Jack.... I hate you....
You haven't said this yet, but you will. Why? Because the tips I give you today will make your passwords as much of a pain in the ass to you as it is for the hackers!
Password Re-Use.
Passwords should be different for every single site and program that you use. If that is too much for you, at least make sure that passwords for your bank accounts and financial dealings are different than your email and social media passwords.
Passwords should be changed any time there is a compromise, every 30 days on important sites, and every 90 days on lesser sites. You should not recycle a password that you used on another site, and you should not use any of your previous 10 passwords.
Password blunders.
Passwords should not actually be a word. Dictionary attacks make very short work of a password like "Mustang" and this would be horribly bad if you are posting pictures of your sporty car on your social media site. It would be only slightly better if you vary it up with special characters like "Mu$t@nG", but this is still not very secure.
Passwords also should not be keyboard combos like "qwerty" or "1234wert". I guarantee that these will be quickly cracked like any dictionary word.
Size Matters Ladies!
The more characters in the password the better! The more characters in the password the better! The more characters in the password the better!
No, that was not a copy & paste error. That was me making an annoying point. Many companies have figured this out, and require 8-10 character passwords. Some of the jobs I have had required 15 character passwords.
Is there a max?
There is no maximum for the purpose of this guide. That said, some programs or sites will have a maximum. In that case, use that maximum whenever possible. If you can use a 48-character password, do it! XKCD comics made a comical poke at this.
The Passphrase
Some folks will tell you that a passphrase is the way to go. In this method, you would make your password something like "HowNowBrownCow" or "SometimesYou FeelLikeANut". This is better than a single word because you are using more characters, but still not the best solution because dictionary words are being used still. Replacing some letters with special characters and numbers will help, but only a little.
Okay Jack, enough! WTF do you want me to do?
The PassPhrase Hybrid
Here we go. This is how we make a long password that you can remember and will slow down a password cracker.....
Step 1: Come up with a memorable phrase.
Don't ask what your country can do for you, ask what you can do for your country!
Step 2: Add a header piece. (Pretend your last name is Robinson here.)
At Casa de Robinson Don't ask what your country can do for you, ask what you can do for your country!
This is the phrase you will repeat in your mind to remember the password!
This is the phrase you will repeat in your mind to remember the password!
Step 3: Take the initials of each word....
ACDRDAWYCCDFYAWYCDFYC!
Step 4: Mix upper and lower case.
ACdRdawyccdfyAwycdfyc!
Step 5: Substitute numbers for like sounding words.
ACdRdawyccd4yAwycd4yc!
Step 6: Get some more special characters in there.
@CdR*dawyccd4y^Awycd4yc!
Ta-da!
Then go to http://www.passwordmeter.com/ and see how you rate!
Even my example above has room for improvement!
Ta-da!
Try it out.
Now that I have given some tips, come up with five passwords that you feel are strong.Then go to http://www.passwordmeter.com/ and see how you rate!
Even my example above has room for improvement!
Be safe in cyberspace everyone!
Comment below! See you soon!
No comments:
Post a Comment