# Need a Strong Password?

**URL:** <https://forums.speedlife.net/t/need-a-strong-password/216058>\
**Category:** NYSpeed Off Topic\
**Created:** [August 31, 2011, 9:21am UTC](https://forums.speedlife.net/t/need-a-strong-password/216058 "2011-08-31T09:21:02Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![ProgRocker](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/progrocker/32/5434_2.png) [@ProgRocker](https://forums.speedlife.net/u/ProgRocker)\
**Post date:** [August 31, 2011, 9:21am UTC](https://forums.speedlife.net/t/need-a-strong-password/216058/1 "2011-08-31T09:21:02Z")

</div>

- Go Here: [http://www.wolframalpha.com/](http://www.wolframalpha.com/)
- In the search and type **Password X Characters** (Substitute X with however many characters you want your password to be)
- You can use the “specific password rules” to change how the password is formatted (if it has special characters, upper case, lower case, etc.)

---

<div class="post-metadata">

**Author:** ![boardjnky4](https://avatars.discourse-cdn.com/v4/letter/b/96bed5/32.png) [@boardjnky4](https://forums.speedlife.net/u/boardjnky4)\
**Post date:** [August 31, 2011, 9:23am UTC](https://forums.speedlife.net/t/need-a-strong-password/216058/2 "2011-08-31T09:23:50Z")

</div>

using a 3rd party to generate your passwords for you?

LOL

---

<div class="post-metadata">

**Author:** ![tpgsr](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/tpgsr/32/7374_2.png) [@tpgsr](https://forums.speedlife.net/u/tpgsr)\
**Post date:** [August 31, 2011, 9:24am UTC](https://forums.speedlife.net/t/need-a-strong-password/216058/3 "2011-08-31T09:24:32Z")

</div>

SHIT that thing guessed my password. Crazy. It is/soon to not be \*\*\*\*\*\*\*\*\*

Edit: wow, if you type your password the forum automatically replaces it with asterisks. Cool.

---

<div class="post-metadata">

**Author:** ![ProgRocker](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/progrocker/32/5434_2.png) [@ProgRocker](https://forums.speedlife.net/u/ProgRocker)\
**Post date:** [August 31, 2011, 9:25am UTC](https://forums.speedlife.net/t/need-a-strong-password/216058/4 "2011-08-31T09:25:35Z")

</div>

> [@boardjnky4](#):
>
> using a 3rd party to generate your passwords for you?
> 
> LOL

I knew that was coming…I’ll take the third party over watching someone type in 1234

---

<div class="post-metadata">

**Author:** ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)\
**Post date:** [August 31, 2011, 9:29am UTC](https://forums.speedlife.net/t/need-a-strong-password/216058/5 "2011-08-31T09:29:22Z")

</div>

Yea generate some 16 character long random password you can’t remember.

However make sure you leave the sticky note under your keyboard

---

<div class="post-metadata">

**Author:** ![ProgRocker](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/progrocker/32/5434_2.png) [@ProgRocker](https://forums.speedlife.net/u/ProgRocker)\
**Post date:** [August 31, 2011, 9:32am UTC](https://forums.speedlife.net/t/need-a-strong-password/216058/6 "2011-08-31T09:32:22Z")

</div>

> [@LZ](#):
>
> Yea generate some 16 character long random password you can’t remember.
> 
> However make sure you leave the sticky note under your keyboard

I forget about those, I tape it to my monitor. I can memorize pretty well, so a 15 character password wouldn’t be too hard. I have VLKs memorized for various products.

It knew my password too it was @71is@69w/2f1ng3rSupTH3@$$

---

<div class="post-metadata">

**Author:** ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)\
**Post date:** [August 31, 2011, 9:37am UTC](https://forums.speedlife.net/t/need-a-strong-password/216058/7 "2011-08-31T09:37:54Z")

</div>

With centralized logins like AD/Radius/TACACS having to remember one password isn’t that bad…

However with single login I really like using two factor auth.

---

<div class="post-metadata">

**Author:** ![ProgRocker](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/progrocker/32/5434_2.png) [@ProgRocker](https://forums.speedlife.net/u/ProgRocker)\
**Post date:** [August 31, 2011, 9:42am UTC](https://forums.speedlife.net/t/need-a-strong-password/216058/8 "2011-08-31T09:42:00Z")

</div>

> [@LZ](#):
>
> With centralized logins like AD/Radius/TACACS having to remember one password isn’t that bad…
> 
> However with single login I really like using two factor auth.

We really only have 2 factor for our encrypted machines.

---

<div class="post-metadata">

**Author:** ![boardjnky4](https://avatars.discourse-cdn.com/v4/letter/b/96bed5/32.png) [@boardjnky4](https://forums.speedlife.net/u/boardjnky4)\
**Post date:** [August 31, 2011, 9:43am UTC](https://forums.speedlife.net/t/need-a-strong-password/216058/9 "2011-08-31T09:43:34Z")

</div>

Using a multiple word phrase with mixed cases, a special character, and a number are pretty fucking secure.

I’ve done the whole randomly generated password thing before, it fucking blew.

---

<div class="post-metadata">

**Author:** ![walter](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/walter/32/7202_2.png) [@walter](https://forums.speedlife.net/u/walter)\
**Post date:** [August 31, 2011, 9:48am UTC](https://forums.speedlife.net/t/need-a-strong-password/216058/10 "2011-08-31T09:48:25Z")

</div>

Protip: None of you have anything important enough to hide behind a 16 character super password.

---

<div class="post-metadata">

**Author:** ![boardjnky4](https://avatars.discourse-cdn.com/v4/letter/b/96bed5/32.png) [@boardjnky4](https://forums.speedlife.net/u/boardjnky4)\
**Post date:** [August 31, 2011, 9:52am UTC](https://forums.speedlife.net/t/need-a-strong-password/216058/11 "2011-08-31T09:52:36Z")

</div>

> [@walter](#):
>
> Protip: None of you have anything important enough to hide behind a 16 character super password.

oh yeah, you’re right. I work at a top-10 in the national hospital with access to PHI of every patient. That’s not important to protect.

---

<div class="post-metadata">

**Author:** ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)\
**Post date:** [August 31, 2011, 9:54am UTC](https://forums.speedlife.net/t/need-a-strong-password/216058/12 "2011-08-31T09:54:29Z")

</div>

My thought process was this a lot of companies tie their AD to everything radius/tacacs/databases/everything

If some how user gets hacked and logs into webmail remotely with a keylogger on their machine you’re pretty much fucked :lol:

---

<div class="post-metadata">

**Author:** ![JayS](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/jays/32/15375_2.png) [@JayS](https://forums.speedlife.net/u/JayS)\
**Post date:** [August 31, 2011, 9:54am UTC](https://forums.speedlife.net/t/need-a-strong-password/216058/13 "2011-08-31T09:54:49Z")

</div>

> [@walter](#):
>
> Protip: None of you have anything important enough to hide behind a 16 character super password.

lol… I write the software that does secure uploads of about 500 credit union’s data. Name, address, SSN, account numbers… nah, I’ll stick with simple passwords.

---

<div class="post-metadata">

**Author:** ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)\
**Post date:** [August 31, 2011, 9:55am UTC](https://forums.speedlife.net/t/need-a-strong-password/216058/14 "2011-08-31T09:55:28Z")

</div>

> [@walter](#):
>
> Protip: None of you have anything important enough to hide behind a 16 character super password.

DoD says differently?

---

<div class="post-metadata">

**Author:** ![JayS](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/jays/32/15375_2.png) [@JayS](https://forums.speedlife.net/u/JayS)\
**Post date:** [August 31, 2011, 9:55am UTC](https://forums.speedlife.net/t/need-a-strong-password/216058/15 "2011-08-31T09:55:48Z")

</div>

> [@tpgsr](#):
>
> SHIT that thing guessed my password. Crazy. It is/soon to not be \*\*\*\*\*\*\*\*\*  
> Edit: wow, if you type your password the forum automatically replaces it with asterisks. Cool.

Hahaha… nice try btw.

---

<div class="post-metadata">

**Author:** ![08GT500](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/08gt500/32/5417_2.png) [@08GT500](https://forums.speedlife.net/u/08GT500)\
**Post date:** [August 31, 2011, 10:05am UTC](https://forums.speedlife.net/t/need-a-strong-password/216058/16 "2011-08-31T10:05:22Z")

</div>

> [@walter](#):
>
> Protip: None of you have anything important enough to hide behind a 16 character super password.

Protip: You’re a noob.

---

<div class="post-metadata">

**Author:** ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)\
**Post date:** [August 31, 2011, 10:16am UTC](https://forums.speedlife.net/t/need-a-strong-password/216058/17 "2011-08-31T10:16:02Z")

</div>

Speaking of things that are leet long passwords

and hacking companies that can issue certs for domains

[https://www.infosecisland.com/blogview/16188-Potentially-Hundreds-of-Bogus-Digital-Certificates-Issued.html](https://www.infosecisland.com/blogview/16188-Potentially-Hundreds-of-Bogus-Digital-Certificates-Issued.html)

---

<div class="post-metadata">

**Author:** ![ProgRocker](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/progrocker/32/5434_2.png) [@ProgRocker](https://forums.speedlife.net/u/ProgRocker)\
**Post date:** [August 31, 2011, 10:23am UTC](https://forums.speedlife.net/t/need-a-strong-password/216058/18 "2011-08-31T10:23:00Z")

</div>

Yeah, M$ JUST got around to patching the Zune not too long ago to cover those bogus certs that got released not too long ago.

Our laptops are encrypted and use 2 factor authentication to protect student data. If it gets compromised we have to pay for credit monitoring for (2 years I think) for any students who might have been on the laptop. As a domain admin I like to keep my passwords lengthy.

Almost anything can be compromised, and I’m sure Network Security professionals could point out flaws in any one of our businesses.

---

<div class="post-metadata">

**Author:** ![boxxa](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/boxxa/32/5045_2.png) [@boxxa](https://forums.speedlife.net/u/boxxa)\
**Post date:** [August 31, 2011, 11:01am UTC](https://forums.speedlife.net/t/need-a-strong-password/216058/19 "2011-08-31T11:01:41Z")

</div>

dasd$3rfd@ is not a secure password.  
R3@llyC00l is not a secure password.

redhorsepilotcanyon is more secure mathematically. also, based on general public, companies that require 8-10 letter “complex” passwords leave their users to write them down on a pad of paper next to their desk. companies that do not allow long passwords are less secure than the admin making password rules like the following list I have seen:

no repeating letters  
must contain letter, number, and symbol  
must not be one used the last 10 times  
must start with a capital letter (this itself makes the first character only 26 guesses)

Also, certs are only as trust worthy as the providers of them. The best security that is used at high level banks is client certs that are all based on machines and issued on an internal CA. Hell, the Iranian government was issued certificates to man in the middle all the Google sites recently.

 ![http://imgs.xkcd.com/comics/password_strength.png](http://imgs.xkcd.com/comics/password_strength.png)

Also, if you have no account locking on failed login attempts, you deserve to be hacked.

---

<div class="post-metadata">

**Author:** ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)\
**Post date:** [August 31, 2011, 11:06am UTC](https://forums.speedlife.net/t/need-a-strong-password/216058/20 "2011-08-31T11:06:55Z")

</div>

Part of the reason random characters are used is when cracking hashs with rainbow tables those add a lot to the size of the table.

[Next page](https://forums.speedlife.net/t/need-a-strong-password/216058.md?page=2)
