internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet |Refer-It

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / Tips & Tutorials

Download of the day
Internet Explorer 8

Most Popular Software Downloads
Mozilla Firefox 3.0
Ad-Aware 2008 Free
Internet Explorer 7
QuickTime for Windows
Paint Shop Pro
Mozilla Firefox Portable Edition 3
AVG Anti-Virus Free
Windows XP Service Pack 3
Ashampoo WinOptimizer
Adobe Flash Player
Windows Live Suite

Most Popular Software Articles
Windows Vista Tips & Tricks, Part 1
Windows Vista: Worthy of the Hype?
Windows Wireless Zero Configuration: Five Steps to Sanity


Software Reviews

Security Tips: The Password Game
Alternatives to Playing the Password Security Game
Michael Hall

Networking Notes The recent public humiliation of a company called MediaDefender brings to light the very important topic of password security.

Here's the story:

MediaDefender is a company that specializes in file sharing. It doesn't actually share files: It makes life hard for people who do. Sometimes that involves planting files on p2p networks that aren't what they claim to be (aka "cuckoo eggs") with the hope that the files will proliferate faster than the actual songs. Other times that involves keeping tabs on file-sharing networks and alerting clients to new material.

Much of the company's inner workings were exposed recently when more than 700MB of internal messages stored in a Gmail account held by one of the company's employees were leaked. The messages were distributed over file-sharing networks, and sites like Ars Technica have been slowly sifting through the stockpile.

All sorts of details have already been exposed through the compromise, including spreadsheets with salaries and other employee information such as social security numbers and home addresses. It's a PR nightmare for the company, and it's a privacy nightmare for its employees.

How were the messages compromised? There are plenty of ways to do that. Ars Technica suggests a fairly obvious:

One popular theory holds that the MediaDefender employee probably used his Gmail login to sign up with one of the file-sharing services he was monitoring, and used the same password as on his Gmail account. Then, so goes the theory, someone with administrative access to the account traced his IP address to MediaDefender, and then either decided to log in and take a look at the the employee's e-mail or provided the login information to a hacker.

That laughter you hear is the marketing departments in security companies that specialize in blocking workplace access to Web services like Gmail, who will be pleased to add this to their list of scare anecdotes. Maybe they should, but the nature of the compromise, if that was truly the angle of attack, suggests that any company without a password complexity policy that makes reusing passwords too painful to contemplate could be similarly compromised. But we all know that, and that's why every Web service, e-mail account, and workplace sign-on we use has a unique password, right? Right?

Most people are aware of how poor their password regimen is: Lots of people have only one password, plenty have two (one for important things like e-mail and one for less important things like newspaper site sign-ons), a few probably have three or more, especially if they have access to servers.

Because IT departments frequently say that writing down a password is bad, we're taught early on that we need to do the impossible when it comes to accessing the many services that might be encountered over the course of the day: Create and memorize a unique password for each and every one.

For starters, those preaching the "no-writedowns" gospel are probably wrong to do so. Security expert Bruce Schneier approvingly cited a Microsoft Senior Security Strategist who said as much:

"We're all good at securing small pieces of paper. I recommend that people write their passwords down on a small piece of paper, and keep it with their other valuable small pieces of paper: in their wallet."

A Handy Alternative to Writing Down Passwords

But there's another way to handle multiple passwords that lets you remember just one master password while generating unique passwords for every site or service you use.

You can check it out in its simplest form at the homepage of Nic Wolff, a New York City programmer who admitted his own weakness for weak passwords and set out to remedy it with some Javascript and ingenuity. "I feel stupid," he wrote, "knowing that one SQL Server exploit or disgruntled admin could cost me my whole identity."

So here's how it works:

  • Think up a root password. It can be a tough one because it'll be the only one you need, but you definitely need to remember it.
  • Visit the password generator page
  • Fill out the form using your master password and the name of the site you're registering for.
  • Get a password unique to that site thanks to a cryptographic hash generated from the password and site name.

So, suppose my root password is something hard to guess. We could use, for instance, the old "first letter of each word in a book title" trick. I so happen to have Leonard Nimoy's classic "I Am NOT Spock" sitting here. It's only four letters on its own, so we'll add the "L" and "N" from "Leonard" and "Nimoy" to the beginning and throw in an exclamation mark at the end to give it a little extra trickiness: lnians!

Perfect. It's not an actual word, which is good. And I know that book will never leave my sight, so I'll always have a discrete reminder.

So we take our new root password to the password generator form and try it out for a couple of sites:

When we feed it our root password and use "practicallynetworked" as the site, we get "qiwn2VuY1a" as our new password. When we feed it our root password and use "gmail" as the site, we get "q2fS0i0r1a."

Those are both tough, secure passwords (and the script slipped in a "1a" at the end of each to meet the requirements for at least one number some sites have). In addition, nothing about one gives away anything about the other. So if you're an executive for a bustling anti-p2p company who runs afoul of some malicious hackers and a torrent site admin with an axe to grind, your Gmail password remains safe.

If you're sold on the approach, you might have already thought up the one big drawback: Those passwords are really hard to remember, which means you either return to that site every time you need to remember your password, or you write them all down (which is OK if you do it responsibly, but we're trying to avoid that).

I don't like the thought of going back to that site over and over and over, either, so it's a relief that people have taken the idea and run with it.

The author provides a bookmarklet, for instance, which allows you to generate and retrieve passwords without leaving the site you're visiting.

And there's the Password Composer page, which provides not only a Web form and bookmarklet, but a shell script in case you're using a Linux or Unix terminal, and a Greasemonkey script for Firefox users.

Or just try writing all your very complex passwords down on a piece of paper you keep in your wallet. That guy from MediaDefender is probably wishing he had.

Adapted from Practically Networked

Contents:
1. Alternatives to Playing the Password Security Game






JupiterOnlineMedia

internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

Jupitermedia Corporate Info


Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers

Solutions
Whitepapers and eBooks
IBM eBook: Planning a Service Oriented Architecture
IBM eBook: Choosing the Right Architecture--What It Means for You and Your Business
Microsoft Article: Will Hyper-V Make VMware This Decade's Netscape?
Avaya Article: Using Intelligent Presence to Create Smarter Business Applications
Intel Go Parallel Article: Getting Started with TBB on Windows
Microsoft Article: 7.0, Microsoft's Lucky Version?
Avaya Article: How to Feed Data into the Avaya Event Processor
IBM Article: Developing a Software Policy for Your Organization
Microsoft Article: Managing Virtual Machines with Microsoft System Center
Intel Go Parallel Article: Intel Threading Tools and OpenMP
HP eBook: Storage Networking , Part 1
Microsoft Article: Solving Data Center Complexity with Microsoft System Center Configuration Manager 2007
MORE WHITEPAPERS, EBOOKS, AND ARTICLES
Webcasts
HP Video: StorageWorks EVA4400 and Oracle
HP Webcast: Storage Is Changing Fast - Be Ready or Be Left Behind
Microsoft Silverlight Video: Creating Fading Controls with Expression Design and Expression Blend 2
MORE WEBCASTS, PODCASTS, AND VIDEOS
Downloads and eKits
Red Gate Download: SQL Toolbelt and free High-Performance SQL Code eBook
Iron Speed Designer Application Generator
MORE DOWNLOADS, EKITS, AND FREE TRIALS
Tutorials and Demos
Silverlight 2 App and Walkthrough: Leverage Silverlight 2 with SQL Server and XML
IBM Article: Enterprise Search--Do You Know What's Out There?
HP Demo: StorageWorks EVA4400
Microsoft Article: The Progress and Promise of Deep Zoom
Microsoft How-to Article: Get Going with Silverlight and Windows Live
MORE TUTORIALS, DEMOS AND STEP-BY-STEP GUIDES