- It's the applications, stupid
- Will a whitelist save personal computing?
- Thousands of Web sites under attack
- To solve the unsolvable problem
- Re-thinking the security of virtual machines
- Security Development Lifecycle trumps code complexity
- Is your Web site FIPS compliant?
- Computer security: Why have least privilege?
- Strategic security: Get a handle on authentication
- Control user installs of software
November 13, 2006 | Comments: (0)
Comments to my password contest column
Readers write in about my password contest column
--------------
From: Bacchu, Anjan
Sent: Friday, November 10, 2006 9:15 PM
Hi roger,
Nice to know that your challenge was taken and [someone] succeed[ed].
"No one has cracked the two larger challenges as of press time, although I know there are several hundred computer teams -- one with over 1,000 computers --working on the challenges."
Sometime in the future, for those who cannot afford to have their own 1000 computer nodes OR use cracked machines on the 'net, the Amazon EC2 might be a good resort. Keep adding more machines till the problem is solved!
Can your 10 char password cracker tell you his methodology ?
Thank you,
BR,
~A
-------------
Roger's reply:
Tony used Linux-based John the Ripper on two machines with a custom john.ini
file.
-----------
Hi Roger,
Chunking is the key to a good password, in my humble opinion. String together a few obscure "chunks" of 4 to 7 characters-things like acronyms, numbers or misspelled words-and you can create devilish passwords that are not all that hard to remember. I routinely carry in my head at least four passwords of 16 characters or longer. I feel pretty safe from getting guessed.
MJH
------------
Posted by Roger Grimes on November 13, 2006 05:17 PM
RATE THIS ARTICLE:
-

- COMMENTS
TOP STORIES
Sun to clarify JavaFX planMS's dev tool service packs
HP in talks to buy EDS
Developers' role shifting
MS: XP SP3 reboots OEMs' fault
Apple: iPhone out of stock
Can Sun rejuvenate Java?
Powerset unveils Google-killer
FBI worried about Cisco gear
AMD updates quad-core Opterons
ADDITIONAL RESOURCES

- Application Security: Threats and How to Counter Them
- Why Linux Threats Mean Business
- Minding the Machines: PC Disaster Recovery for the Enterprise

- Protect Your Data with SSL
- Prevent Your Next Microsoft Exchange Outage
- 11 Myths About Microsoft Exchange Backup & Recovery





