Challenge: Guess the password to my encrypted files

Mark R

Diamond Member
Oct 9, 1999
8,513
14
81
People always use stupidly long codes for unimportant stuff.

The great thing about protecting important stuff, is that no one would ever expect you to use the stupidest code available.

The precursors of Permissive Action Links were simple mechanical combination locks that were set into the control systems of nuclear weapons, such as the Minuteman ICBM. There they could perform different functions: some blocked the cavity through which the nuclear materials were shot to create a reaction; other locks blocked circuits; and some simply prevented access to the control panel. For testing, some of these mechanisms were installed during 1959 in weapons stationed in Europe.[5]

For the Minuteman ICBM force, the US Air Force's Strategic Air Command worried that in times of need the codes would not be available, so they quietly decided to set them to 00000000. The missile launch checklists included an item confirming this combination until 1977.[7]
 

irishScott

Lifer
Oct 10, 2006
21,568
3
0
People always use stupidly long codes for unimportant stuff.

The great thing about protecting important stuff, is that no one would ever expect you to use the stupidest code available.

How long is stupidly long? I could probably use that password for my entire life. Even if quantum computing comes about it would be valid.
 

Fenixgoon

Lifer
Jun 30, 2003
31,811
10,346
136
there was an xkcd comic about how it may be better to have a sentence than some horribly complicated word.

A sentence will be composed of many characters. (47 characters)

versus

0mgWtfB8Q!1oneone (17 characters)

i havent done that math offhand, but the idea is that the increase in length offsets the lack of complication in the password.

IANAC (i am not a cryptologist) so from a true security standpoint, i don't know how effective that method really is.
 

lxskllr

No Lifer
Nov 30, 2004
57,659
7,892
126
there was an xkcd comic about how it may be better to have a sentence than some horribly complicated word.

A sentence will be composed of many characters. (47 characters)

versus

0mgWtfB8Q!1oneone (17 characters)

i havent done that math offhand, but the idea is that the increase in length offsets the lack of complication in the password.

IANAC (i am not a cryptologist) so from a true security standpoint, i don't know how effective that method really is.

 

irishScott

Lifer
Oct 10, 2006
21,568
3
0
there was an xkcd comic about how it may be better to have a sentence than some horribly complicated word.

A sentence will be composed of many characters. (47 characters)

versus

0mgWtfB8Q!1oneone (17 characters)

i havent done that math offhand, but the idea is that the increase in length offsets the lack of complication in the password.

IANAC (i am not a cryptologist) so from a true security standpoint, i don't know how effective that method really is.

True enough. Not sure about the "sentence" thing specifically but I watch "Security Now" with Steve Gibbs (the guy who created the webpage I posted) and apparently length is the single most important aspect of a password. I forget the specific example, but it was something like:

Which password is harder to crack?
$ayTr3Y&5;
or
po0ooooooooooooooooooool

The answer is the 2nd one, assuming the attacker knows nothing about your password ahead of time.
 

ultimatebob

Lifer
Jul 1, 2001
25,135
2,445
126
Try changing your Dropbox password to correcthorsebatterystaple, and see what happens...
 

amdhunter

Lifer
May 19, 2003
23,324
219
106
1.13 million trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion trillion centuries
 

ultimatebob

Lifer
Jul 1, 2001
25,135
2,445
126
I never understood why people put a huge effort in Making huge uncrackable passwords. Odds are that they won't get cracked, but some poorly run site will store when in cleartext or crap encryption and they'll get discovered that way.
 

Mark R

Diamond Member
Oct 9, 1999
8,513
14
81
Most sites don't store passwords in encrypted format. Instead, they store an irreversible hash.

If the password database is compromised, then a very fast brute-force cracking tool can be used against the file to recover the passwords.

The tool has to guess the password to verify it. By making the passwords long and complex, it makes the brute force search more difficult.
 

rh71

No Lifer
Aug 28, 2001
52,856
1,048
126
I don't know the passwd to one of my apps - I have it in notepad and just copy and paste it because it's a random string.
 

clamum

Lifer
Feb 13, 2003
26,255
403
126
I figure using KeePass to generate and store my passwords is good enough. I doubt anyone will guess or crack my 188 bit Google Account password it generated. It's not the strongest password in the world, but I'm not too fuckin worried about it.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |