Google+
Showing posts with label facebook. Show all posts
Showing posts with label facebook. Show all posts

Saturday, 22 February 2014

Why you need to start using a password manager.

I bought against using one for ages...but my brain has failed me... I can only re-hash, re-formulate, completely re-define passwords so many times before things become impossible...

In the end people either start doing a few simple things... Using repeat passwords or worst of all, writing them down! More commonly they also use really simple passwords... That ones always been a mystery to me as to why as it's easy to come up with at least one good complex password.

So in steps some password managers:
KeePass & LastPass

There are a lot more out there. These are the best known to me.

LastPass uses the cloud and personally, I find it the easiest to use as a switch devices a lot.

For those not as happy with the cloud being used there is also KeePass.

So why use them?

Cracking passwords is becoming easier with more computational power and large lists of breaches becoming more increasingly available. The tools for cracking them are also getting a lot better. Examples being; RockYou.txt coming in around 60MB (Yes that's a .txt file).

Also think about this expert from a Ars Technica article:

"A PC running a single AMD Radeon HD 7970 GPU, for instance, can try on average an astounding 8.2 billion password combinations each second, depending on the algorithm used to scramble them. Only a decade ago, such speeds were possible only when using pricey supercomputers.


So whats the key to a half decent password these days? Length combine with complexity.Don't just pick a really long word. 

i.e. Defenestration (A favourite word of mine for some random reason)

Now the character length is good but it's bound to get found on a dictionary brute force attack.. 

Next found would be passwords like Defenestration13 or Defenestration231127

Then D3f3n3str4t10n

Now we're getting into the area of a more solid password: 

45%D3fe[3str4t^on#!1731 (Not so heavy with the l33t speak, miss some characters on purpose)

So you're happy with your genius password that you think is uncrackable. 6 months down the line its in some dictionary because Tescos, Sony, Twitter or whom ever had a breach that month was not taking enough care to hash, salt their data. 

So this is why those password managers are becoming important and I've moved over. I;ve never had a breach of security (that I know of) but with unique complex random and long passwords on my logins I will certainly minimise any damage that could be done. I would make the password to your email account particularly complex! 

A lot of services are now starting to also use 2 step authentication where your mobile / email gets sent a verification code to input at login... it costs you a little more time but it's well worth it. Get used to using them as they can also be invaluable if your password is compromised. Facebook and Google have been using these for a while and they work pretty smoothly.  MMO games such as World of Warcraft and Guild Wars 2 also make extensive use of this tech as well so it's becoming increasingly popular.

Some good links worth a read:
Wikipedia -Password cracking
ArsTechnica - The secret to online safety: Lies, random characters, and a password manager

Tuesday, 26 June 2012

Facebook changing your displayed E-mail

Beware that a recent change on Facebook is putting your @facebook.com e-mail address as the displayed default instead of your original one.

There is reason for this in that if they keep traffic within the Facebook ecosystem and more people use the @facebook.com e-mail addresses then Facebook increase their marketing value even further.

For people like me with their own custom domain (alpagot.co.uk among lots of others), i'm sure they won't be happy that there was not a more 'in your face' warning. It's easy to go into your settings and 'reveal' your current normal email address again.

It seems the media outlets have picked this up as well and comparing it to what Google did with their Buzz service which failed horribly.

Tuesday, 10 April 2012

Everything's now $1 BILLION DOLLARS!

So Microsoft go and buy 800+ patents from AOL for a cool $1bn which although is a lot, probably makes good business sense in today's hostile business climate. Article: here

What does Facebook do? It buys a photo app for $1bn... Article: here

Tuesday, 8 November 2011

Tip: Facebook permissions.

With Facebook being well established and users having used it for a good few years now it's well worth checking over your security settings regularly to protect what to do and do not want to share.

It's also worth making sure your doing as much as possible to protect unwanted access to that data. It's also wise to limited what can access that data.

What page that deals with your app's permissions is found here:

https://www.facebook.com/settings?tab=applications

You'll be surprised at what might be on there. I had app's listed form years ago that I'd forgotten about (Graffiti, Yahoo, game promotion apps). Even with only the ones I wanted it's a pretty hefty list:




I'll cover other checks another time but I found this a rather quick and easy thing to tidy up & just felt like sharing it.