Development Password Security

Discussion in 'Software' started by BennieboyUK, 5 Oct 2011.

  1. BennieboyUK

    BennieboyUK CPC Folder of the Month Sep 2011

    Joined:
    24 Nov 2010
    Posts:
    1,710
    Likes Received:
    113
    Hi Bit Tech'ers

    I am lucky enough (well for some it would be hell) to be part of a team at work, that looks at current security measures for the corporate environment. We look at everything from perimeter network to the user access layer. I wont bore you with the details, but we had a demonstration of the new CUDA password cracking tools that can now be used to crack some very complex passwords in short period of time.

    In a nut shell the previous number, hash, lower and caps recommendation still stand, although the password length recommendation has now increased from 7 to 10

    I just thought I would share this information with you lot in case anyone cared!

    There is ALOT of information, some different, available on this subject and I am sure lots of people have different views, which I fully respect so please avoid flaming. This is purely FYI and individuals can make they own choices on the passwords they use.

    I am unsure of the forum policy about linking to hacking websites to give you further information, so I will refrain.


    Bennie
     
    brave758 and Jeevus like this.
  2. Sp!

    Sp! Minimodder

    Joined:
    6 Dec 2002
    Posts:
    1,543
    Likes Received:
    30
  3. RichCreedy

    RichCreedy Hey What Who

    Joined:
    24 Apr 2009
    Posts:
    4,699
    Likes Received:
    172
    You maybe interested in testing your passwords here
     
  4. wolfticket

    wolfticket Downwind from the bloodhounds

    Joined:
    19 Apr 2008
    Posts:
    3,331
    Likes Received:
    463
    I'm going to create an online password checker that when you type your password in it simply pops up with a message that says:

    "If this was your real password then it is not secure as you just typed it into a potentially malicious website."
     
  5. sp4nky

    sp4nky BF3: Aardfrith WoT: McGubbins

    Joined:
    15 Jul 2009
    Posts:
    1,706
    Likes Received:
    53
    What I find frustrating about passwords is where they restrict the maximum size of the password. My current one for work is 14 characters but I know some places that won't accept more than 11.
     
  6. RichCreedy

    RichCreedy Hey What Who

    Joined:
    24 Apr 2009
    Posts:
    4,699
    Likes Received:
    172
    you havent heard of gibson research then?
    he (steve gibson) specialises in security projects
     
  7. brave758

    brave758 Minimodder

    Joined:
    16 Apr 2009
    Posts:
    1,142
    Likes Received:
    29
    Thanks for the heads up bennieboy
     
  8. wolfticket

    wolfticket Downwind from the bloodhounds

    Joined:
    19 Apr 2008
    Posts:
    3,331
    Likes Received:
    463
    I know, I know.

    But I bet most people don't carefully check the legitimacy of a password checking website, and the potential for abuse pretty substantial.

    I think a blanket policy of not typing your password into any website other than the one it is for is a pretty good idea for most people, and one I follow.
     
  9. Big_malc

    Big_malc Minimodder

    Joined:
    7 Sep 2010
    Posts:
    1,626
    Likes Received:
    83
    Kill the gibson :worried:
     

Share This Page