http://faerye.net/post/reality-gap-passwords Comments on "Reality Gap: Passwords" - Faerye Net 2003-09-22T14:29:00+00:00 http://faerye.net/post/reality-gap-passwords#comment-569 Re: Strip and Smart Cards 2003-09-22T14:29:00+00:00 2003-09-22T14:29:00+00:00 <p>The French (and most of the rest of Europe) use smart cards extensively. A couple of the norse countries have national id cards that are smart cards. I really like the idea of pervasive smart-card authentication. It just makes more sense than the myriad of different mechanisms in use at present. Passwords are far too cumbersome for the average joe. <br /> <br /> The concern of course, is privacy. It&#8217;s easier to collect info on a person if electronic ID is connected to everything they do. Something like this would make TIA a really easy thing to do, not that it&#8217;s so hard now. But I feel that we could overcome the privacy concerns with appropriate legislation and that the benefits would be enough to outweigh the potential detriments.</p> Mithrandir http://faerye.net/post/reality-gap-passwords#comment-566 Re: Strip and Smart Cards 2003-09-19T12:29:59+00:00 2003-09-19T12:29:59+00:00 <p>Ah. Fleas*.<br /> <br /> *This is the literal translation for the French word for microchip. I do not make this up!</p> felicity http://faerye.net/post/reality-gap-passwords#comment-565 Re: Strip and Smart Cards 2003-09-19T12:28:44+00:00 2003-09-19T12:28:44+00:00 <p>A smart card is a card (credit card-sized or smaller) with an embedded secure cyptoprocessor. The SIM card in your cell phone is a smart card, as are some newer credit cards and ATM cards. Basically, it&#8217;s a super-secure high-tech key.</p> wonko http://faerye.net/post/reality-gap-passwords#comment-564 Re: Mary had a little lamb... 2003-09-19T11:36:24+00:00 2003-09-19T11:36:24+00:00 <p>I think when it comes down to it, one or both of the following are true:<br /> <br /> 1. Boss does not have the capacity to remember passwords.<br /> 2. Boss thinks or feels that remembering passwords is &#8220;beneath him&#8221; or otherwise ridiculous.</p> felicity http://faerye.net/post/reality-gap-passwords#comment-563 Re: Remembering passwords 2003-09-19T11:32:28+00:00 2003-09-19T11:32:28+00:00 <p>Well, for most things there&#8217;s a work-around. Websites have the ever-popular reset or e-mail password, if it&#8217;s your own box, I understand rooting it is fairly easy when you have physical access&#8230;</p> felicity http://faerye.net/post/reality-gap-passwords#comment-562 Re: Strip and Smart Cards 2003-09-19T11:30:57+00:00 2003-09-19T11:30:57+00:00 <p>Smart cards. What is this?</p> felicity http://faerye.net/post/reality-gap-passwords#comment-561 Re: Strip and Smart Cards 2003-09-19T11:30:48+00:00 2003-09-19T11:30:48+00:00 <p>I can certainly see how a program like Strip would be very convenient, and I can even concede that it looks very secure, but the problem I have with that is that no matter how well-encrypted all that information is, there&#8217;s still just one point of failure: the password used to gain access to Strip itself.<br /> <br /> It&#8217;s like a nice big armored vault that you put all your eggs in, with a huge iron door protecting the only entrance, but with only a single little deadbolt keeping all that iron in place. It&#8217;s real secure until someone finds the deadbolt key.</p> wonko http://faerye.net/post/reality-gap-passwords#comment-560 Strip and Smart Cards 2003-09-19T09:13:11+00:00 2003-09-19T09:13:11+00:00 <p>I have tons of passwords. I write them all down. I feel that it&#8217;s more important to use different passwords in different places than to avoid recording one&#8217;s passwords. However, one must take pains to keep recorded passwords secure. So I use <a href="http://www.zetetic.net/products.html">Strip</a>. It&#8217;s nice, it works well, it employs solid algorithms, it&#8217;s free and its portable. Plus, it solves the related problems of which username I used at a given site, which is as big a problem for me as passwords.<br /> <br /> This sort of thing is a big problem, particularly for small businesses. Large companies have full-time IT staff and well-designed authentication structures such than there are a number of IT support people who can reset the passwords of various users. Thus, as long one of the IT guys remembers his password, life goes on. But small businesses don&#8217;t have IT staff, and they usually don&#8217;t have lots of tech-savvy users either. <br /> <br /> This is why I think smart card authentication is important. Biometrics are too easy to fake. Smart cards are pretty hard to break into in the first place, and you have to steal the physical card first. <br /> <br /> I don&#8217;t know if Apple has a smart card authentication solution. I know NT can be made to work with them. In the Unix world, there&#8217;s some really cool stuff that uses them, like <a href="http://wwws.sun.com/sunray/sunray1/features.html">Sun Ray</a> thin clients. There&#8217;s also a various linux projects that are working on this sort of thing. Some of them work with OS X, and some sound quite mature.</p> Mithrandir http://faerye.net/post/reality-gap-passwords#comment-559 Mary had a little lamb... 2003-09-19T00:33:07+00:00 2003-09-19T00:33:07+00:00 Although not as systematic as Wonko, I do have a somewhat similar approach to passwords. And I, too, have great trouble remembering which password I used for what, but try to keep things simple by using different classes of passwords matching whatever security level is required. And I try to keep passwords meaningful &#8211; at least to me. Things like &#8220;AN/ALQ-162&#8221;. Look it up, and it&#8217;ll make sense when I tell you that I was in the Air Force. <p> When it has to be safe, though, I like to remember sentences instead of just meaningless alphanumeric sequences. A sentence like &#8220;When it comes to Hard Work, Everyone must pull Their own Weight&#8221; becomes the password &#8220;WictHWE1htpToW8&#8221;. This makes it a lot easier to remember long passwords &#8211; perhaps you should try that on your boss?</p> GreyStork http://faerye.net/post/reality-gap-passwords#comment-557 Remembering passwords 2003-09-18T16:56:38+00:00 2003-09-18T16:56:38+00:00 <p>I have no trouble at all remembering long, complex, alphanumeric passwords with mixed case and special characters, but I have a <i>huge</i> problem remembering which password I&#8217;ve used where.</p> <p> To make things easier on myself, I&#8217;ve started using a three-tier system. Each tier contains three passwords, and the complexity of the passwords rises with each tier, so that the bottom tier is secure but relatively simple, whereas the top tier tends to be 15+ characters long and extremely convoluted. Needless to say, the tier 1 passwords are used for websites and throwaway things that I don&#8217;t care much about, tier 2 passwords for email and other moderate security concerns, and tier 3 passwords for high risk things like bank accounts and root logins. </p> <p> Now all I have to remember is which tier I used, which is pretty easy to figure out. If I forget which password I used for Faerye.net, all I need to do is try my three tier 1 passwords until one works. Most login forms allow at least three tries before locking you out, so that&#8217;s no problem. </p> <p> Oh yeah, and none of my passwords are ever written down anywhere. If I ever forget them, I&#8217;m screwed, but at least my data is safe. </p> wonko