Tuesday, July 24, 2007

How can i come up with passwords that are complex and easy to remember? My short term memory is shot Help!

Unique and complex passwords are great and easy to come up with but remembering them - Now that's a totally different story! Have you ever considered using password phrases instead? Full sentences are easier to remember than obscure characters and have many benefits. Keep on reading grasshopper...

Did you know that Windows allows you to use passwords with up to 127 characters?

How does that help you Young Admin with a bad memory?

Its quite simple actually. I don't use passwords anymore. I will wait for the gasps to stop.

Yes, I have phased passwords out in favor of password phrases.

Why would you want to remember a password like BeDffd123cSwsspO0s129 when you could just remember a sentence like "suck giant monkey balls","Piss Off Wanker!" or "How much does this job suck!" (Well maybe not that last one if you need to document it!)

You can use uppercase, lowercase, special characters, or even spaces… but you are using them in context, which makes it much more natural to remember.

Post-it notes on your monitor are not secure and very 1999. Sorry Buddy.

It turns out that it is very difficult for a computer to break a password string containing more than 20 characters. It certainly couldn't be done on the fly. Most windows passwords can be cracked in no more than a few minutes and in most cases seconds.

If a skilled hacker can get physical access to your machine, they can boot to Knoppix or Ubuntu, and have your password in seconds. Even with multiple machines running brute force cracking programs, there is no possible way that someone could crack a password that long in a reasonable amount of time. Even if somebody had the super computing power to do so hopefully you change your password every few months or so.

It may be difficult to use password phrases on other operating systems, or especially on websites, because they don't properly handle spaces in the password, or have a small password length limit. One of the tricks that I usually do is use a password phrase without the spaces, if I possibly can.

Ok I'll wait while you go change your password ;)