D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] An observation on wordpress and scripted attacks

 

On Thu, 7 Feb 2013, Simon Waters wrote:

Almost nobody will use a password like that

As I said - use a password manager. Sure it introduces new issues but I have a lot of random passwords 20+ characters in length. It also warns if password forms are insecure (although not consistently enough for my liking! ).

Password length restrictions may be less prevalent, but I hit them pretty much daily. Credit card companies seem the worst - sigh.

Not just that, but there are companies who won't let you copy & paste a password into a web page - e.g. O2. They won't let you copy & paste an email address either - they must think that they're so smart asking people to type their email address twice, and refuse to allow copy & paste. Oh well, glad I'm not a customer of theirs anymore.

Another solution is something like Yubikey, but that requires the host you're logging into to have an active internet connection (probably not an issue if you're logging in via the Internet though!)

Then there's: http://xkcd.com/936/

Designing a yubikey like device is a great hackspace project.

Gordon

--
The Mailing List for the Devon & Cornwall LUG
http://mailman.dclug.org.uk/listinfo/list
FAQ: http://www.dcglug.org.uk/listfaq