Security Information

Passwords or Pass Phrase? Protecting your Intellectual Property


Much has been said on the theory of password protection for files, computer login, and other network access. In the past we used a combination of letters, special characters, and other techniques to try and prevent unwanted or unauthorized access to our computers, resources, and networks. A new theory on passwords is emerging that may help us remember our access codes, be more secure, and generally keep hackers and thieves out of our networks.

A password is a combination of words, letters, and special characters that only the user knows, allowing access to a computer or other information resources. As humans we have a large number of codes and numbers we need to remember every day - such as the key lock on our apartment entries, national identification numbers, automobile license or tag numbers, telephone numbers - it is a large and confusing suite of items we need to memorize.

When selecting a new password or pass code for access to a computer system, most of us understand how difficult it is to remember complex codes, and thus we select something already know n to us, such as names, birthdays, national identifiers, or other known items, and then place a number or character in front of the name or number thinking it is secure. This is easy to understand, as most of us simply do not have an ability to instantly recall large numbers of complex codes.

In a worst case we simply write down the complex code on a piece of paper, and leave it in a desk, our pocketbook, or in many cases taped to the front of our computer monitor.

However, to a hacker this makes access to your network or computer much easier, at they generally only have to learn a couple things about you, and add a few numbers to the front or ending of your personal data - you would be surprised how often this grants access to computers and networks. Ad some good "cracking utilities" to the hacker's suite of tools, and you can understand the threat.

PassPhrases are a concept that will help us create more secure, easy to remember safeguards for our computer and network resource protection. A passphrase is a selection of words and/or numbers that are 15 characters or more in length, and are easy for us to remember. A couple examples of a good pass phrases are:

? igotodalaieejdaily

? shehasbeautifulhair

? surfinginhawaiiisgreat

According to Mark Minasi, a noted security consultant, a 15 character pass phrase will require a cracking program the following number of computations to try and break a 15 character pass phrase:

? 15 lowercase letters = 1,677,259,342,285,725,925,376 possibilities

? Try a million a second, it'll take 531,855 centuries/years to break the code

As you can see, this is a pretty good level of security for your resource.

Another concern with passwords is if you forget or lose the password, and are using a utility like Microsoft's Encrypting File System (EFS), you run the risk of losing all access to your important files if you require a hardware reset of your password. All EFS encrypted files are linked to your login profile, meaning if you encrypt a directory or file with EFS, and you do a hardware reset on your computer, those files and directories are lost FOREVER.

For Microsoft Windows users you can now also use spaces within your pass phrase, however we would not recommend embedding spaces in your pass phrase, as that actually does allow a cracker better access to getting your code - it may help them crack it in 100,000 years rather than 250,000!

(About the Author - John Savageau is a managing director at CRG-West, responsible for managing operations and architecture for several of the largest telecommunications interconnect facilities in the US, including One Wilshire in Los Angeles)


MORE RESOURCES:

How the NSA Took Linux To the Next Level
Slashdot - 7 hours ago
In RBAC, permissions are provided based on roles that are granted by the security system. The concept of a role differs from that of a traditional group in ...
Anatomy of Security-Enhanced Linux (SELinux) OS News
all 1,730 news articles


Private security firms say no way to meet demand of 2010 Winter Games
The Canadian Press, VANCOUVER - 10 hours ago
VANCOUVER — There's no way the private security industry can meet the demands from either Olympic organizers or the RCMP for help during the 2010 Winter ...
RCMP checking into downtown Vancouver hotel for 2010 Olympic Games The Canadian Press
all 32 news articles


No need to check background of cabinet spouses, partners, says Day
The Canadian Press, OTTAWA - 8 hours ago
OTTAWA — Public Safety Minister Stockwell Day says there's no need to run security checks on the spouses or partners of federal cabinet ministers, ...
Foreign Affairs Minister Maxime Bernier under fire CTV.ca
Minister to face grilling by Commons over judgment Globe and Mail
Bloc calls for Bernier security probe Toronto Star
Canada.com - The Gazette (Montreal)
all 322 news articles


Secure Computing delivers security gateway virtual appliances for ...
Al-Bawaba, Jordan - 3 hours ago
Secure Computing Corporation (Nasdaq: SCUR), a leading enterprise gateway security provider, has announced it is working with VMware to provide customers ...


Rebate excludes many taxpayers with foreign spouses
The Associated Press - 9 hours ago
But Shelat is married to a foreigner who still hasn't completed the often years-long process that allows her to apply for a Social Security number. ...


China's biggest city beefs up subway security check
Xinhua, China - 1 hour ago
The increased workforce was expected to help speed up security checks during work day rush hours to ensure smooth traffic flow as well as improve Metro ...


NDTV.com

IB blames 'slack' BSF for infiltration
Times of India, India - 7 hours ago
It is fairly common for security forces engaged in counter-terrorism operations to lower their guard during periods of lull. What is also common is that ...
Jammu terrorist attack defies BSF claims Merinews
Hostage crisis over in Jammu, 2 terrorists killed CNN-IBN
Militants strikes back: Heavy Firing along LoC Little About
Reuters India - CNN-IBN
all 130 news articles


China's energy security moves it closer to the Middle East
Daily Star - Lebanon, Lebanon - 6 hours ago
Therefore China has a significant interest in the Middle East, and any changes in the situation there will affect China's energy security. ...


Xinhua

Security source: Terrorists firing mortars to avoid retaliation
Ynetnews, Israel - 5 hours ago
'We cannot continue living under fire without proper fortification,' one resident says The problem, according to a security source, stems from the ...
Negev council head: Government busy with investigations instead of ... Ynetnews
all 47 news articles


Turkish Press

Gov't of Sudan to lodge complaint to UN Security Council against Chad
Xinhua, China - 6 hours ago
KHARTOUM, May 11 (Xinhua) -- Sudan announced on Sunday it would lodge an official complaint to the United Nations Security Council against Chad's government ...
Sudan steps up security, says Darfur rebels advance Reuters
Sudan Imposes Curfew to Hunt for Darfur Rebels in Capital; Cuts ... Voice of America
Sudan cuts ties with Chad The Associated Press
Yahoo! Italia Notizie - The Media Line
all 750 news articles

Security - Google News

home | site map

Visit our other sites:
GamesBlog | GamingDepot | GimmeaRide | GimmeNetwork | Golf Biz | HotorNotGame | I Want Computers | I Want Games | I Want Hosting | I Want Music | I Want Security | JokeBox | ScriptShock | Wantedfonts | Webalize
© 2006