{"id":525,"date":"2013-04-03T00:54:39","date_gmt":"2013-04-03T08:54:39","guid":{"rendered":"http:\/\/systemsolver.com\/StatlerBlog\/?p=525"},"modified":"2013-04-03T00:54:39","modified_gmt":"2013-04-03T08:54:39","slug":"wireless-and-password-security","status":"publish","type":"post","link":"https:\/\/systemsolver.goodhealthyday.com\/StatlerBlog\/2013\/04\/03\/wireless-and-password-security\/","title":{"rendered":"Wireless and password security"},"content":{"rendered":"<p>Basically, wireless security requires WPA2 encryption (with a complex pass-phrase that is not included in any pass-phrase dictionaries), MAC address filtering, and no remote administration of the router.<\/p>\n<p>Here&#8217;s a great link describing these opportunities:<a href=\"http:\/\/www.labnol.org\/internet\/secure-your-wireless-wifi-network\/10549\/\">http:\/\/www.labnol.org\/internet\/secure-your-wireless-wifi-network\/10549\/<\/a><\/p>\n<p>And here&#8217;s a cartoon about making a safe pass-phrase:<br \/>\n<a href=\"http:\/\/xkcd.com\/936\/\">http:\/\/xkcd.com\/936\/<\/a><br \/>\nhttp:\/\/imgs.xkcd.com\/comics\/password_strength.png<img loading=\"lazy\" decoding=\"async\" class=\"alignnone\" alt=\"\" src=\"http:\/\/imgs.xkcd.com\/comics\/password_strength.png \" width=\"740\" height=\"601\" \/><\/p>\n<p>And finally:<\/p>\n<p style=\"padding-left: 30px;\">The following are from comments on an article at:<br \/>\n<a href=\"http:\/\/arstechnica.com\/security\/2013\/03\/how-i-became-a-password-cracker\/1\/\">http:\/\/arstechnica.com\/security\/2013\/03\/how-i-became-a-password-cracker\/1\/<\/a><br \/>\n================\u2026================<br \/>\nalthaz wrote:<br \/>\nThe best passwords are still those posited by XKCD (http:\/\/xkcd.com\/936\/) &#8211; four (two is next to<br \/>\nworthless and three is not that good) random words strung together.<br \/>\nReply:<br \/>\nActually, three or four random words with a numeral or special character inserted between each<br \/>\nword are much better (will defeat -every- lowercase brute force attack). Even just capitalising the<br \/>\nNth letter of each of your words gives a dramatic improvement in security.<br \/>\n&#8220;coRrectbaTteryhoRsestAple&#8221;<br \/>\nLonger is indeed always better, but the following are also good tips:<br \/>\n* numeral or special character inserted somewhere in the middle of the password. (It&#8217;s<br \/>\ncomputationally easy to check prepends and postpends, but still difficult to check every possible<br \/>\nPassword strenth 2 of 3 3\/26\/2013<br \/>\nposition.)<br \/>\n* ditto for capitalisation. The rules out there mean that &#8220;HorseStaple&#8221; is really no more secure<br \/>\nthan &#8220;horsestaple&#8221; (because it&#8217;s the most likely thing someone does to a two-word passphrase, and<br \/>\nthus only double the time to check), but &#8220;hoRsestAple&#8221; adds 5&#215;6+2=33 permutations (if they<br \/>\nhave a rule to look for a single capitalized character in each word), which isn&#8217;t great, but is still<br \/>\nbetter than nothing.<br \/>\n* Even better, replace every Nth character with something completely different. &#8220;h&amp;rses&amp;aple&#8221; \/<br \/>\n&#8220;hQrsesQaple&#8221; \/ &#8220;h5rses5aple&#8221; &#8230; just be careful not to pick a substitution that turns a word into<br \/>\nanother word or accidentally emulates l33tsp34k.<br \/>\nAll that aside, the MOST important thing is, if you reuse passwords, reuse them wisely.<br \/>\n* Use unique passwords, as strong as you can stomach, for -every- account that involves access to<br \/>\nyour actual monetary resources (bank, paypal, amazon, etc)<br \/>\n* Ditto for any email account with password reset access to the above. THIS IS IMPORTANT!<br \/>\n* For sites where your online reputation or business would be harmed by a breakin, or where you<br \/>\nwould be seriously inconvenienced from a loss of access, use a unique password, but you don&#8217;t<br \/>\nneed it to be as strong.<br \/>\n* For generic forums and the like&#8230; try not to reuse if you can, and try to pick &#8220;good&#8221; passwords,<br \/>\nbut if the repercussions are low that it really isn&#8217;t too important. These definitely lend themselves<br \/>\ntowards the &#8220;ease of use&#8221; end of the scale, as there&#8217;s little for you to lose.<br \/>\nLast edited by Yobgod on 25 Mar 2013 02:46<br \/>\n================\u2026================<br \/>\nQuote:<br \/>\nOf course 16+ truly random characters is slightly harder to break, but it&#8217;s also impossible to<br \/>\nremember.<br \/>\nReply:<br \/>\nA 16 character truly random password is not &#8220;slightly harder to break&#8221;; it&#8217;s &#8220;computationally<br \/>\ninfeasible to break, even with massive parallelism, even with a really fast hashing function, for<br \/>\nyears to come&#8221;.<br \/>\nYour GPU may be able to do a billion hashes per second, and you may have a supercomputer<br \/>\nwith a thousand GPUs. Great. A trillion hashes per second. How much does that help you?<br \/>\nNot much.<br \/>\nThere are 95 printable keyboard-friendly ASCII characters. Many systems these days will accept<br \/>\nUTF-8, but we&#8217;ll just stick with ASCII, as it&#8217;s good enough. A 16 character random password<br \/>\ntaken from the 95 printable ASCII characters gives 44,012,666,865,176,569,775,543,212,890,625<br \/>\ncombinations. That&#8217;s 44 million * trillion * trillion. On average you&#8217;ll only need to crack half that<br \/>\nto crack any given password, so call it 22 million * trillion * trillion. At a trillion hashes a second,<br \/>\nthat&#8217;s still going to take, on average, 22 million trillion seconds.<br \/>\nPassword strenth 3 of 3 3\/26\/2013<br \/>\nThat&#8217;s a lot of seconds. It&#8217;s a hair under 700 billion years, or about 50 times the current age of the<br \/>\nuniverse.<br \/>\nYou might complain that the supercomputer is too small. But it doesn&#8217;t really matter. Even with<br \/>\n100,000 GPUs (and that&#8217;s a lot) you&#8217;re looking at 7 billion years. Maybe your GPUs are better,<br \/>\nand can do 4 billion hashes per second. Great; you&#8217;re still looking at more than 1 billion years.<br \/>\nA billion years is a really long time.<br \/>\nNow let&#8217;s look at your XKCD password. The idea here is that they&#8217;re four common words strung<br \/>\ntogether. Typical English speakers have a spoken vocabulary of 10-20,000 words, and a working<br \/>\nknowledge of 35-50,000 words. Four words out of 35,000 gives a total of just<br \/>\n1,500,625,000,000,000,000 passwords. Our trillion hash per second supercomputer can crack that<br \/>\non average in 8.6 days, and can crack it exhaustively in 17 days. Perhaps you&#8217;ll use some really<br \/>\nobscure words (which is rather undermining the point, because you&#8217;re less likely to remember<br \/>\nreally obscure words); four from 100,000 can be cracked exhaustively by our trillion hash<br \/>\nsupercomputer in 3 years. Perhaps you&#8217;ll decide to span most written English, and pick four from<br \/>\na million words. That&#8217;s stepped up the difficulty a lot&#8211;our supercomputer would now take almost<br \/>\n16,000 years, on average.<br \/>\nBut it&#8217;s a blink of an eye compared to the 700 billion years that it&#8217;d take for random selection of<br \/>\n16 ASCII printable characters to be brute forced.<br \/>\n&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-end&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Basically, wireless security requires WPA2 encryption (with a complex pass-phrase that is not included in any pass-phrase dictionaries), MAC address filtering, and no remote administration of the router. Here&#8217;s a great link describing these opportunities:http:\/\/www.labnol.org\/internet\/secure-your-wireless-wifi-network\/10549\/ And here&#8217;s a cartoon about making a safe pass-phrase: http:\/\/xkcd.com\/936\/ http:\/\/imgs.xkcd.com\/comics\/password_strength.png And finally: The following are from comments on an [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[],"class_list":["post-525","post","type-post","status-publish","format-standard","hentry","category-general"],"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/systemsolver.goodhealthyday.com\/StatlerBlog\/wp-json\/wp\/v2\/posts\/525","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/systemsolver.goodhealthyday.com\/StatlerBlog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/systemsolver.goodhealthyday.com\/StatlerBlog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/systemsolver.goodhealthyday.com\/StatlerBlog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/systemsolver.goodhealthyday.com\/StatlerBlog\/wp-json\/wp\/v2\/comments?post=525"}],"version-history":[{"count":0,"href":"https:\/\/systemsolver.goodhealthyday.com\/StatlerBlog\/wp-json\/wp\/v2\/posts\/525\/revisions"}],"wp:attachment":[{"href":"https:\/\/systemsolver.goodhealthyday.com\/StatlerBlog\/wp-json\/wp\/v2\/media?parent=525"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/systemsolver.goodhealthyday.com\/StatlerBlog\/wp-json\/wp\/v2\/categories?post=525"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/systemsolver.goodhealthyday.com\/StatlerBlog\/wp-json\/wp\/v2\/tags?post=525"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}