<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: 123456 most common password?</title>
	<atom:link href="http://blogs.discovermagazine.com/gnxp/2010/01/123456-most-common-password/feed/" rel="self" type="application/rss+xml" />
	<link>http://blogs.discovermagazine.com/gnxp/2010/01/123456-most-common-password/</link>
	<description></description>
	<lastBuildDate>Thu, 23 May 2013 04:06:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.2</generator>
	<item>
		<title>By: ChristianK</title>
		<link>http://blogs.discovermagazine.com/gnxp/2010/01/123456-most-common-password/#comment-19404</link>
		<dc:creator>ChristianK</dc:creator>
		<pubDate>Sat, 30 Jan 2010 16:35:42 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.discovermagazine.com/gnxp/2010/01/21/123456-most-common-password/#comment-19404</guid>
		<description>You can combine one strong password that you remember with different suffixes for different websites and write down those suffixes on a piece of paper.
</description>
		<content:encoded><![CDATA[<p>You can combine one strong password that you remember with different suffixes for different websites and write down those suffixes on a piece of paper.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Manish</title>
		<link>http://blogs.discovermagazine.com/gnxp/2010/01/123456-most-common-password/#comment-19403</link>
		<dc:creator>Manish</dc:creator>
		<pubDate>Sat, 23 Jan 2010 09:58:00 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.discovermagazine.com/gnxp/2010/01/21/123456-most-common-password/#comment-19403</guid>
		<description>Its not surprising then that so many people keep getting their email accounts hacked into
</description>
		<content:encoded><![CDATA[<p>Its not surprising then that so many people keep getting their email accounts hacked into</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MIkE</title>
		<link>http://blogs.discovermagazine.com/gnxp/2010/01/123456-most-common-password/#comment-19402</link>
		<dc:creator>MIkE</dc:creator>
		<pubDate>Fri, 22 Jan 2010 22:03:22 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.discovermagazine.com/gnxp/2010/01/21/123456-most-common-password/#comment-19402</guid>
		<description>Here you can find nice method for custom and good paswodrd creation &lt;a href=&quot;http://www.goodpassword.info/how_to_create_a_password.php&quot; rel=&quot;nofollow&quot;&gt;http://www.goodpassword.info/how_to_create_a_password.php&lt;/a&gt;
</description>
		<content:encoded><![CDATA[<p>Here you can find nice method for custom and good paswodrd creation <a href="http://www.goodpassword.info/how_to_create_a_password.php" rel="nofollow">http://www.goodpassword.info/how_to_create_a_password.php</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anne</title>
		<link>http://blogs.discovermagazine.com/gnxp/2010/01/123456-most-common-password/#comment-19401</link>
		<dc:creator>Anne</dc:creator>
		<pubDate>Fri, 22 Jan 2010 20:21:06 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.discovermagazine.com/gnxp/2010/01/21/123456-most-common-password/#comment-19401</guid>
		<description>Of course I use my cat&#039;s name as a password! She&#039;s called &quot;k7;m2H8l&quot; and I change her name every six weeks.
</description>
		<content:encoded><![CDATA[<p>Of course I use my cat&#8217;s name as a password! She&#8217;s called &#8220;k7;m2H8l&#8221; and I change her name every six weeks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: RickD</title>
		<link>http://blogs.discovermagazine.com/gnxp/2010/01/123456-most-common-password/#comment-19400</link>
		<dc:creator>RickD</dc:creator>
		<pubDate>Fri, 22 Jan 2010 19:15:11 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.discovermagazine.com/gnxp/2010/01/21/123456-most-common-password/#comment-19400</guid>
		<description>&quot;Write all your passwords down on a piece of old-fashioned paper.&quot;
I&#039;d be far more concerned about somebody using that piece of paper (which has to be stored near the computer) than about somebody hacking my password.  It is much easier for me to use the same password for 135 different web sites than to have different passwords for each, which I then have to write down.
(And yes, I have different passwords for banking websites, but that is the exception, not the rule.)
</description>
		<content:encoded><![CDATA[<p>&#8220;Write all your passwords down on a piece of old-fashioned paper.&#8221;<br />
I&#8217;d be far more concerned about somebody using that piece of paper (which has to be stored near the computer) than about somebody hacking my password.  It is much easier for me to use the same password for 135 different web sites than to have different passwords for each, which I then have to write down.<br />
(And yes, I have different passwords for banking websites, but that is the exception, not the rule.)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Clark</title>
		<link>http://blogs.discovermagazine.com/gnxp/2010/01/123456-most-common-password/#comment-19399</link>
		<dc:creator>Clark</dc:creator>
		<pubDate>Fri, 22 Jan 2010 07:48:11 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.discovermagazine.com/gnxp/2010/01/21/123456-most-common-password/#comment-19399</guid>
		<description>If you use 1Password on a Mac it keeps track of all your passwords for you and can generate extremely strong passwords for every site and then access them via a master password on your computer.  It also has an iPhone version that syncs with the desktop.
I used to use strong passwords, but only kept a handful I could remember.  Now I use different passwords on each site.
Realistically you need something like that if you are going to have sufficient security.  Because frankly no one can keep track of numerous complex passwords without creating other security flaws.
</description>
		<content:encoded><![CDATA[<p>If you use 1Password on a Mac it keeps track of all your passwords for you and can generate extremely strong passwords for every site and then access them via a master password on your computer.  It also has an iPhone version that syncs with the desktop.<br />
I used to use strong passwords, but only kept a handful I could remember.  Now I use different passwords on each site.<br />
Realistically you need something like that if you are going to have sufficient security.  Because frankly no one can keep track of numerous complex passwords without creating other security flaws.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Katkinkate</title>
		<link>http://blogs.discovermagazine.com/gnxp/2010/01/123456-most-common-password/#comment-19398</link>
		<dc:creator>Katkinkate</dc:creator>
		<pubDate>Fri, 22 Jan 2010 04:12:35 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.discovermagazine.com/gnxp/2010/01/21/123456-most-common-password/#comment-19398</guid>
		<description>At my last job, when the number of passwords I had (and were renewed on different schedules) grew to many to be handled by my inadequate rote memory, I figured out about 11 different passwords as a base stock and wrote a list of clues to them, to help me keep track of which one I was using for each application.  I randomly substituted numbers for similar-looking letters to keep it a bit more secure as well (eg. s=5, q=9.  The list of clues lived in my diary with whatever application I was using it for written in pencil beside the relevant clue.   I used things like my mother&#039;s, mother&#039;s maiden name + my niece&#039;s current age.
</description>
		<content:encoded><![CDATA[<p>At my last job, when the number of passwords I had (and were renewed on different schedules) grew to many to be handled by my inadequate rote memory, I figured out about 11 different passwords as a base stock and wrote a list of clues to them, to help me keep track of which one I was using for each application.  I randomly substituted numbers for similar-looking letters to keep it a bit more secure as well (eg. s=5, q=9.  The list of clues lived in my diary with whatever application I was using it for written in pencil beside the relevant clue.   I used things like my mother&#8217;s, mother&#8217;s maiden name + my niece&#8217;s current age.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Vicki</title>
		<link>http://blogs.discovermagazine.com/gnxp/2010/01/123456-most-common-password/#comment-19397</link>
		<dc:creator>Vicki</dc:creator>
		<pubDate>Thu, 21 Jan 2010 22:04:02 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.discovermagazine.com/gnxp/2010/01/21/123456-most-common-password/#comment-19397</guid>
		<description>There&#039;s always a tradeoff between security and inconvenience: it&#039;s easier to walk through an unlocked door, including my own front door while I&#039;m carrying groceries. So it only makes sense to lock a door if you care who comes through it. (You might _close_ a door to keep the wind out, or animals in: the local dog run uses gates that almost any human would find trivial, but the dogs can&#039;t open.) And the more passwords I have, the more I have to either remember or store: and pieces of paper can be lost or stolen.
I leave my work computer logged in to the library&#039;s website, because the worst any of my coworkers could do is cancel my holds on library books; it&#039;s not a real risk. (They could also reserve books I didn&#039;t want, which I wouldn&#039;t have to borrow, or renew the books I have checked out, which is harmless.) That doesn&#039;t mean I&#039;m staying logged in to my personal email, or my pension fund.
Tacroy is absolutely right about hash functions: that was old news in the 1980s. It&#039;s not an absolute guarantee--given a system, a hashed password file, and time, brute-force attacks are useful--but it&#039;s still worth doing.
</description>
		<content:encoded><![CDATA[<p>There&#8217;s always a tradeoff between security and inconvenience: it&#8217;s easier to walk through an unlocked door, including my own front door while I&#8217;m carrying groceries. So it only makes sense to lock a door if you care who comes through it. (You might _close_ a door to keep the wind out, or animals in: the local dog run uses gates that almost any human would find trivial, but the dogs can&#8217;t open.) And the more passwords I have, the more I have to either remember or store: and pieces of paper can be lost or stolen.<br />
I leave my work computer logged in to the library&#8217;s website, because the worst any of my coworkers could do is cancel my holds on library books; it&#8217;s not a real risk. (They could also reserve books I didn&#8217;t want, which I wouldn&#8217;t have to borrow, or renew the books I have checked out, which is harmless.) That doesn&#8217;t mean I&#8217;m staying logged in to my personal email, or my pension fund.<br />
Tacroy is absolutely right about hash functions: that was old news in the 1980s. It&#8217;s not an absolute guarantee&#8211;given a system, a hashed password file, and time, brute-force attacks are useful&#8211;but it&#8217;s still worth doing.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: llewelly</title>
		<link>http://blogs.discovermagazine.com/gnxp/2010/01/123456-most-common-password/#comment-19396</link>
		<dc:creator>llewelly</dc:creator>
		<pubDate>Thu, 21 Jan 2010 21:58:49 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.discovermagazine.com/gnxp/2010/01/21/123456-most-common-password/#comment-19396</guid>
		<description>&lt;blockquote&gt;In the idealized world championed by security specialists, people would have different passwords for every Web site they visit and store them in their head or, &lt;i&gt;if absolutely necessary, on a piece of paper&lt;/i&gt;.&lt;/blockquote&gt;
The italicized words (my italics) are the root of the problem. Memorizing good passwords is hard work, and most people can&#039;t be convinced to do it. As Bruce Schneier pointed out over 10 years ago, writing your passwords down should not be viewed as a last resort. Instead, it should be your first resort. Write all your passwords down on a piece of old-fashioned paper. Make a copy. Store the copy in a safe place, where it is unlikely to be affected by common disasters, such as fires, floods, etc. Keep the other on your person, but treat it like your credit card, or your id card - take every reasonable precaution against losing it.
But most importantly - know how to report identity theft. Write down a list of the steps you will need to go through in the event of your password list being lost, or stolen. Do a few dry runs, so that when you need to use it, it is somewhat familiar to you. Keep that list somewhere else (not with the password list, obviously) on your person.
</description>
		<content:encoded><![CDATA[<blockquote><p>In the idealized world championed by security specialists, people would have different passwords for every Web site they visit and store them in their head or, <i>if absolutely necessary, on a piece of paper</i>.</p></blockquote>
<p>The italicized words (my italics) are the root of the problem. Memorizing good passwords is hard work, and most people can&#8217;t be convinced to do it. As Bruce Schneier pointed out over 10 years ago, writing your passwords down should not be viewed as a last resort. Instead, it should be your first resort. Write all your passwords down on a piece of old-fashioned paper. Make a copy. Store the copy in a safe place, where it is unlikely to be affected by common disasters, such as fires, floods, etc. Keep the other on your person, but treat it like your credit card, or your id card &#8211; take every reasonable precaution against losing it.<br />
But most importantly &#8211; know how to report identity theft. Write down a list of the steps you will need to go through in the event of your password list being lost, or stolen. Do a few dry runs, so that when you need to use it, it is somewhat familiar to you. Keep that list somewhere else (not with the password list, obviously) on your person.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tacroy</title>
		<link>http://blogs.discovermagazine.com/gnxp/2010/01/123456-most-common-password/#comment-19395</link>
		<dc:creator>Tacroy</dc:creator>
		<pubDate>Thu, 21 Jan 2010 20:52:45 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.discovermagazine.com/gnxp/2010/01/21/123456-most-common-password/#comment-19395</guid>
		<description>Meh. If I&#039;d had a rockyou.com account, the password would have probably been something simple like that - after all, it&#039;s &lt;i&gt;RockYou&lt;/i&gt;. I don&#039;t care if anyone steals my account on that website, and I don&#039;t want to use one of my real passwords in case their system architects are morons and something like this happens.
Further, rockyou.com was doing it wrong in the worst way possible. You &lt;b&gt;do not ever&lt;/b&gt; store passwords as plain text. You store the result of a cryptographic hashing function applied to the password + some random but constant salt value. That way, even if someone steals your customer records, they can&#039;t easily get your user&#039;s passwords - which might have been used on a different site.
</description>
		<content:encoded><![CDATA[<p>Meh. If I&#8217;d had a rockyou.com account, the password would have probably been something simple like that &#8211; after all, it&#8217;s <i>RockYou</i>. I don&#8217;t care if anyone steals my account on that website, and I don&#8217;t want to use one of my real passwords in case their system architects are morons and something like this happens.<br />
Further, rockyou.com was doing it wrong in the worst way possible. You <b>do not ever</b> store passwords as plain text. You store the result of a cryptographic hashing function applied to the password + some random but constant salt value. That way, even if someone steals your customer records, they can&#8217;t easily get your user&#8217;s passwords &#8211; which might have been used on a different site.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eric Lund</title>
		<link>http://blogs.discovermagazine.com/gnxp/2010/01/123456-most-common-password/#comment-19394</link>
		<dc:creator>Eric Lund</dc:creator>
		<pubDate>Thu, 21 Jan 2010 15:19:17 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.discovermagazine.com/gnxp/2010/01/21/123456-most-common-password/#comment-19394</guid>
		<description>Frustrating, yes, but nothing new. In &lt;i&gt;&quot;Surely You&#039;re Joking, Mr. Feynman&quot;&lt;/i&gt;, Feynman tells the story of contriving a meeting with the official locksmith at Los Alamos, who had managed to open a special safe that a captain had had delivered to store his sensitive documents (the captain was unavailable at the time but the documents were urgently needed). It turned out the locksmith was eager to meet Feynman, who had cultivated a reputation for being a safecracker. The locksmith&#039;s secret: those safes came from the factory with one of two default settings, and the second one opened the safe. Feynman subsequently found that about one out of every five combination locks that he tried opened with one of the two default combinations. So the weak password problem has been around for at least 65 years.
</description>
		<content:encoded><![CDATA[<p>Frustrating, yes, but nothing new. In <i>&#8220;Surely You&#8217;re Joking, Mr. Feynman&#8221;</i>, Feynman tells the story of contriving a meeting with the official locksmith at Los Alamos, who had managed to open a special safe that a captain had had delivered to store his sensitive documents (the captain was unavailable at the time but the documents were urgently needed). It turned out the locksmith was eager to meet Feynman, who had cultivated a reputation for being a safecracker. The locksmith&#8217;s secret: those safes came from the factory with one of two default settings, and the second one opened the safe. Feynman subsequently found that about one out of every five combination locks that he tried opened with one of the two default combinations. So the weak password problem has been around for at least 65 years.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ambitwistor</title>
		<link>http://blogs.discovermagazine.com/gnxp/2010/01/123456-most-common-password/#comment-19393</link>
		<dc:creator>Ambitwistor</dc:creator>
		<pubDate>Thu, 21 Jan 2010 15:04:36 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.discovermagazine.com/gnxp/2010/01/21/123456-most-common-password/#comment-19393</guid>
		<description>That&#039;s amazing!  I&#039;ve got the same combination on my luggage!
</description>
		<content:encoded><![CDATA[<p>That&#8217;s amazing!  I&#8217;ve got the same combination on my luggage!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rob W</title>
		<link>http://blogs.discovermagazine.com/gnxp/2010/01/123456-most-common-password/#comment-19392</link>
		<dc:creator>Rob W</dc:creator>
		<pubDate>Thu, 21 Jan 2010 13:26:04 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.discovermagazine.com/gnxp/2010/01/21/123456-most-common-password/#comment-19392</guid>
		<description>Hmm.. PEBKAC.
If you&#039;re coding a web application, it&#039;s wise to reject these passwords outright.  I also like the weak-&gt;strong meters shown next to password fields.
Offering advice on how to choose a good password is also helpful.  Best advice I know: memorize a passPHRASE as part of your password.  E.g., &quot;That&#039;s what your MOM said last night&quot; as a passphrase becomes &quot;TwyMsln&quot; in your password (or go with the 3rd letter of each word to get &quot;aauMisg&quot;) and then throw a number and special character in there that you can remember (5^, for example).
5^aauMisg is a pretty good password, and not that much harder to remember than 123456.
Keyboard patterns like qwerty are possible if you are smart about them; i.e., use the shift key, jump around, and make it long.  &quot;2w)OdfJHerIU&quot; is a keyboard pattern password that&#039;s pretty solid.
</description>
		<content:encoded><![CDATA[<p>Hmm.. PEBKAC.<br />
If you&#8217;re coding a web application, it&#8217;s wise to reject these passwords outright.  I also like the weak-&gt;strong meters shown next to password fields.<br />
Offering advice on how to choose a good password is also helpful.  Best advice I know: memorize a passPHRASE as part of your password.  E.g., &#8220;That&#8217;s what your MOM said last night&#8221; as a passphrase becomes &#8220;TwyMsln&#8221; in your password (or go with the 3rd letter of each word to get &#8220;aauMisg&#8221;) and then throw a number and special character in there that you can remember (5^, for example).<br />
5^aauMisg is a pretty good password, and not that much harder to remember than 123456.<br />
Keyboard patterns like qwerty are possible if you are smart about them; i.e., use the shift key, jump around, and make it long.  &#8220;2w)OdfJHerIU&#8221; is a keyboard pattern password that&#8217;s pretty solid.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: 01jack</title>
		<link>http://blogs.discovermagazine.com/gnxp/2010/01/123456-most-common-password/#comment-19391</link>
		<dc:creator>01jack</dc:creator>
		<pubDate>Thu, 21 Jan 2010 13:12:34 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.discovermagazine.com/gnxp/2010/01/21/123456-most-common-password/#comment-19391</guid>
		<description>&quot;Princess&quot;?
</description>
		<content:encoded><![CDATA[<p>&#8220;Princess&#8221;?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
