UnlockGsM

Welcome To UnlockGsm Forum,

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to Register before you can post, click the register box below to proceed. To start posting messages, select the forum that you want to visit from the selection below.



Enjoy & Have Fun!

UnlockGsM Staff


Join the forum, it's quick and easy

UnlockGsM

Welcome To UnlockGsm Forum,

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to Register before you can post, click the register box below to proceed. To start posting messages, select the forum that you want to visit from the selection below.



Enjoy & Have Fun!

UnlockGsM Staff

UnlockGsM

Would you like to react to this message? Create an account in a few clicks or log in to continue.
UnlockGsM

WELCOME TO UnlockGsM FORUM

Log in

I forgot my password

Latest topics

» V3X NOT CHARGING(no response)sulotion done
YahooNews: A Strong Password Isn’t the Strongest Security I_icon_minitimeThu 26 Jul 2012, 10:48 am by paulian

» unlockgsm RULES
YahooNews: A Strong Password Isn’t the Strongest Security I_icon_minitimeTue 28 Jun 2011, 4:04 pm by D'MasteR™

» SL3 Unlocking & Dead boot Services by: NuNuY
YahooNews: A Strong Password Isn’t the Strongest Security I_icon_minitimeWed 18 May 2011, 8:18 pm by UnlockGsm

» Mobile Chat Avacs
YahooNews: A Strong Password Isn’t the Strongest Security I_icon_minitimeSun 03 Apr 2011, 8:58 pm by not

» musta na mga kabaro
YahooNews: A Strong Password Isn’t the Strongest Security I_icon_minitimeMon 21 Mar 2011, 1:31 pm by hymtone

» newbie po...
YahooNews: A Strong Password Isn’t the Strongest Security I_icon_minitimeMon 21 Mar 2011, 1:26 pm by hymtone

» SE R300 phone lock! Done by SEtool
YahooNews: A Strong Password Isn’t the Strongest Security I_icon_minitimeSun 13 Mar 2011, 11:38 am by tekamots

» Arieth Mu Online
YahooNews: A Strong Password Isn’t the Strongest Security I_icon_minitimeSat 19 Feb 2011, 1:16 am by MartinX-ariethAD

» SE w350a AT&T lock. unlock by setool smoothly
YahooNews: A Strong Password Isn’t the Strongest Security I_icon_minitimeTue 15 Feb 2011, 1:21 pm by tekamots

Navigation

Keywords

RSS feeds


Yahoo! 
MSN 
AOL 
Netvibes 
Bloglines 

    YahooNews: A Strong Password Isn’t the Strongest Security

    IPE_1202
    IPE_1202
    Product Specialist
    Product Specialist


    Male Posts : 11
    Join date : 2010-05-15
    Age : 36
    Location : santigao city

    YahooNews: A Strong Password Isn’t the Strongest Security Empty YahooNews: A Strong Password Isn’t the Strongest Security

    Post by IPE_1202 Wed 08 Sep 2010, 4:29 pm

    "Palala lang po ito sa mga Password natin na ginagamit gusto ko lang po maishare. Wag po sana haluan ng masamang halo"





    MAKE your password strong, with a unique jumble of letters, numbers and punctuation marks. But memorize it — never write it down. And, oh yes, change it every few months.

    These instructions are supposed to protect us. But they don’t.

    Some computer security experts are advancing the heretical thought that passwords might not need to be “strong,” or changed constantly. They say onerous requirements for passwords have given us a false sense of protection against potential attacks. In fact, they say, we aren’t paying enough attention to more potent threats.

    Here’s one threat to keep you awake at night: Keylogging software, which is deposited on a PC by a virus, records all keystrokes — including the strongest passwords you can concoct — and then sends it surreptitiously to a remote location.

    "Keeping a keylogger off your machine is about a trillion times more important than the strength of any one of your passwords,” says Cormac Herley, a principal researcher at Microsoft Research who specializes in security-related topics. He said antivirus software could detect and block many kinds of keyloggers, but “there’s no guarantee that it gets everything.”


    After investigating password requirements in a variety of settings, Mr. Herley is critical not of users but of system administrators who aren’t paying enough attention to the inconvenience of making people comply with arcane rules. “It is not users who need to be better educated on the risks of various attacks, but the security community,” he said at a meeting of security professionals, the New Security Paradigms Workshop, at Queen’s College in Oxford, England. “Security advice simply offers a bad cost-benefit tradeoff to users.”

    One might guess that heavily trafficked Web sites — especially those that provide access to users’ financial information — would have requirements for strong passwords. But it turns out that password policies of many such sites are among the most relaxed. These sites don’t publicly discuss security breaches, but Mr. Herley said it “isn’t plausible” that these sites would use such policies if their users weren’t adequately protected from attacks by those who do not know the password.

    Mr. Herley, working with Dinei Florêncio, also at Microsoft Research, looked at the password policies of 75 Web sites. At the Symposium on Usable Privacy and Security, held in July in Redmond, Wash., they reported that the sites that allowed relatively weak passwords were busy commercial destinations, including PayPal, Amazon.com and Fidelity Investments. The sites that insisted on very complex passwords were mostly government and university sites. What accounts for the difference? They suggest that “when the voices that advocate for usability are absent or weak, security measures become needlessly restrictive.”

    Donald A. Norman, a co-founder of the Nielsen Norman Group, a design consulting firm in Fremont, Calif., makes a similar case. In “When Security Gets in the Way,” an essay published last year, he noted the password rules of Northwestern University, where he then taught. It was a daunting list of 15 requirements. He said unreasonable rules can end up rendering a system less secure: users end up writing down passwords and storing them in places that can be readily discovered.

    “These requirements keep out the good guys without deterring the bad guys,” he said.

    Northwestern has reduced its password requirements to eight, but they still constitute a challenging maze. For example, the password can’t have more than four sequential characters from the previous seven passwords, and a new password is required every 120 days.

    By contrast, Amazon has only one requirement: that the password be at least six characters. That’s it. And hold on to it as long as you like.

    A short password wouldn’t work well if an attacker could try every possible combination in quick succession. But as Mr. Herley and Mr. Florêncio note, commercial sites can block “brute-force attacks” by locking an account after a given number of failed log-in attempts. “If an account is locked for 24 hours after three unsuccessful attempts,” they write, “a six-digit PIN can withstand 100 years of sustained attack.”

    Roger A. Safian, a senior data security analyst at Northwestern, says that unlike Amazon, the university is unfortunately vulnerable to brute-force attacks in that it doesn’t lock out accounts after failed log-ins. The reason, he says, is that anyone could use a lockout policy to try logging in to a victim’s account, “knowing that you won’t succeed, but also knowing that the victim won’t be able to use the account, either.” (Such thoughts may occur to a student facing an unwelcome exam, who could block a professor from preparations.)

    VERY short passwords, taken directly from the dictionary, would be permitted in a password system that Mr. Herley and Stuart Schechter at Microsoft Research developed with Michael Mitzenmacher at Harvard.

    At the Usenix Workshop on Hot Topics in Security conference, held last month in Washington, the three suggested that Web sites with tens or hundreds of millions of users, could let users choose any password they liked — as long as only a tiny percentage selected the same one. That would render a list of most often used passwords useless: by limiting a single password to, say, 100 users among 10 million, the odds of an attacker getting lucky on one attempt per account are astronomically long, Mr. Herley explained in a conversation last month.

    Mr. Herley said the proposed system hadn’t been tested and that users might become frustrated in trying to select a password that was no longer available. But he said he believed an anything-is-permitted password system would be welcomed by users sick of being told, “Eat your broccoli; a strong password is good for security.”





    SOURCE:
    http://finance.yahoo.com/news/A-Strong-Password-Isnt-the-nytimes-3369144559.html?x=0






    IPE

      Current date/time is Wed 08 May 2024, 11:55 am