D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] An observation on wordpress and scripted attacks

 

On Thu, 7 Feb 2013, Simon Waters wrote:

Almost nobody will use a password like that
As I said - use a password manager.  Sure it introduces new issues but I 
have a lot of random passwords 20+ characters in length. It also warns 
if password forms are insecure (although not consistently enough for my 
liking! ).
Password length restrictions may be less prevalent, but I hit them 
pretty much daily. Credit card companies seem the worst - sigh.
Not just that, but there are companies who won't let you copy & paste a 
password into a web page - e.g. O2. They won't let you copy & paste an 
email address either - they must think that they're so smart asking people 
to type their email address twice, and refuse to allow copy & paste. Oh 
well, glad I'm not a customer of theirs anymore.
Another solution is something like Yubikey, but that requires the host 
you're logging into to have an active internet connection (probably not an 
issue if you're logging in via the Internet though!)
Then there's: http://xkcd.com/936/

Designing a yubikey like device is a great hackspace project.

Gordon

--
The Mailing List for the Devon & Cornwall LUG
http://mailman.dclug.org.uk/listinfo/list
FAQ: http://www.dcglug.org.uk/listfaq