Presentations‎ > ‎

Password presentation references

This is the raw material I used when making the Passwords presentation. In that talk, I have already sifted, organized and summarized the lessons learned from these links. If you have found your way in here without having seen the presentation, please contact me to set it up! I can help make sense of it all. Unfortunately, this is a fast-changing topic; if I spoke with your group more than a few months ago, chances are the advice has been updated.

In summary, you should consider a password manager program to store your web account passwords. Those passwords should be long and complex. For those systems where that's impractical (like Windows logins, and the password that lets you into your password manager), you should use a minimum of ten characters that look like alphabet soup when written out. In the presentation, I try to make composing such passwords much easier; and we practice that a bit.

Password cracking chart:

http://www.itworld.com/security/280486/how-long-would-it-take-crack-my-password?page=0,1

See also:

https://www.grc.com/haystack.htm
http://daleswanson.org/things/password.htm

Markov chains:

http://arstechnica.com/security/2013/05/how-crackers-make-minced-meat-out-of-your-passwords/

Other password cracking:

http://arstechnica.com/security/2012/08/passwords-under-assault/
http://www.schneier.com/blog/archives/2012/09/recent_developm_1.html
http://www.schneier.com/essay-246.html
http://xkcd.com/936/ - but the usefulness of this method is currently the subject of some debate.
http://www.lightbluetouchpaper.org/2012/09/03/password-cracking-part-i-how-much-has-cracking-improved/
http://www.lightbluetouchpaper.org/2012/09/04/password-cracking-part-ii-when-does-password-cracking-matter/

Schneier on making good passwords

Password programs

from the demo:  http://keepass.info/
In the cloud:  https://lastpass.com
For smart phones:  http://www.ascendo-inc.com/DataVault.html
Review:  http://www.infoworld.com/d/security/review-7-password-managers-windows-mac-os-x-ios-and-android-189597
Diceware:  http://world.std.com/~reinhold/diceware.html