<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Fight Club &#187; Passphrase</title>
	<atom:link href="http://www.securityfightclub.com/tag/passphrase/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.securityfightclub.com</link>
	<description>Brought to you by Awareness Technologies</description>
	<lastBuildDate>Sat, 05 Jun 2010 04:08:44 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Is there a post-it note under your keyboard?</title>
		<link>http://www.securityfightclub.com/is-there-a-post-it-note-under-your-keyboard/</link>
		<comments>http://www.securityfightclub.com/is-there-a-post-it-note-under-your-keyboard/#comments</comments>
		<pubDate>Wed, 15 Jul 2009 23:05:08 +0000</pubDate>
		<dc:creator>mrdenny</dc:creator>
				<category><![CDATA[Passwords]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Passphrase]]></category>

		<guid isPermaLink="false">http://www.securityfightclub.com/?p=11</guid>
		<description><![CDATA[Companies love requiring there employees to have long complex passwords.  Those of us in IT do this to protect the network from users having passwords which are two easy to guess.  The problem with requiring these long passwords, is that they become very hard to remember very quickly.
The most common way for people to remember [...]]]></description>
			<content:encoded><![CDATA[<p>Companies love requiring there employees to have long complex passwords.  Those of us in IT do this to protect the network from users having passwords which are two easy to guess.  The problem with requiring these long passwords, is that they become very hard to remember very quickly.<span id="more-11"></span></p>
<p>The most common way for people to remember there passwords is to write them down.  The most common place to store these passwords that have been written down is under the keyboard.  I&#8217;ll bet if you walked around the company you work for at night (especially in a non-technical part of the company) and start flipping keyboards over you&#8217;ll find a bunch of peoples passwords.</p>
<p>While some of these people may not have access to information which is all that important, I&#8217;ll bet a few people that you&#8217;ll run across have access to some interesting stuff.  (For the love of god don&#8217;t start using there passwords, that&#8217;s just asking to get fired.)</p>
<p>Some middle ground needs to be found between passwords which a 3 year old can guess such as &#8220;password&#8221; and 30 character passwords that have to be reset every day because the person can&#8217;t remember there password.</p>
<p>The easiest way to create a secure, yet easy to remember password is to use a passphrase instead of a password.  There&#8217;s a couple of different ways to do this.</p>
<ol>
<li>Use an entire phrase just without the spaces.  Make sure to use caps where needed, and stick a number or two in there so that it meets the requirements.  This will give you a nice long password that is hopefully easy to remember.  Something like &#8220;ThisIsMyR3allyL0ngPassword-No1CanFigureItOut&#8221; is perfect.  It&#8217;s very long, has numbers, upper and lower case letters, and a symbol.  And when your auditor comes by asking how long your password is, you can tell him 44 characters.</li>
<li>The second technique is to take a song lyric or line from a poem and use the first letter of each word.  Now be sure not to actually say the phrase out loud since it won&#8217;t take long for someone to figure out what you are using for your password.  After you have your phrase stick a couple of numbers in there and make some letters upper and lower case and you are done.  As an example if I were to use the title of this article as a password it could be &#8220;Itap-1nuyk&#8221;.  It&#8217;s still easy for me to remember for no one else will remember it.</li>
</ol>
<p>When using these sorts of long secure passwords you protect not only your company but yourself.  Everything you do at work is traceable by the company, which means that anything that someone else does when logged into the company network as you can be tracked as well.  While this is good, it means that because your username and password were used to access the network it is assumed that everything which was done was done by you, and you&#8217;ll be the one getting in trouble for what ever the other person did.</p>
<p>Protect yourself, protect your company.  Use a long password, but don&#8217;t write it down.</p>
<p>Denny</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securityfightclub.com/is-there-a-post-it-note-under-your-keyboard/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>
