LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - General
User Name
Password
Linux - General This Linux forum is for general Linux questions and discussion.
If it is Linux Related and doesn't seem to fit in any other forum then this is the place.

Notices


Reply
  Search this Thread
Old 03-09-2011, 02:38 PM   #1
Cultist
Member
 
Registered: Feb 2010
Location: Georgia
Distribution: Slackware64 14.2
Posts: 779

Rep: Reputation: 107Reputation: 107
secure password?


Cryptography isn't a strong point of mine, so thought I'd get an opinion here. For an AES truecrypt volume, would this be considered a secure password?
Code:
januarY--99***
(note that this is not the actual password to be used, but rather an equivelant pw that has the same structure and use of special chars, etc)

Basically, would this be enough to foil any dedicated cracking efforts? I don't mean like if the NSA decided they wanted to break my password, but if some script kiddie with a powerful computer and lots of time tried, would it be secure?
 
Old 03-09-2011, 02:43 PM   #2
SL00b
Member
 
Registered: Feb 2011
Location: LA, US
Distribution: SLES
Posts: 375

Rep: Reputation: 112Reputation: 112
It has mixed-case alphabetic, numeric, and special characters. Yep. That's very secure.
 
Old 03-09-2011, 02:58 PM   #3
szboardstretcher
Senior Member
 
Registered: Aug 2006
Location: Detroit, MI
Distribution: GNU/Linux systemd
Posts: 4,278

Rep: Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694
I wouldn't use anything resembling a word.
 
Old 03-09-2011, 05:12 PM   #4
anomie
Senior Member
 
Registered: Nov 2004
Location: Texas
Distribution: RHEL, Scientific Linux, Debian, Fedora
Posts: 3,935
Blog Entries: 5

Rep: Reputation: Disabled
This one's debatable. Try tinkering with John sometime to see how he cracks passwords. It's very enlightening. My thoughts on januarY--99***:
  • A substantial part of it is a common dictionary word.
  • The case change for 'january' is not as clever as it seems. (I believe there are several default John rules that tweak case in exactly that way.)
  • The special characters and digits are all repeating.

It's not a bad password, IMO. Technically you are observing good practices by choosing from different character classes. I would still be more inclined to use (the similarly memorable): jan*99-RAPIDO-

----

P.S. If anyone reading this thread decides to actually use any of these passwords, please have your noggin examined. (Password dictionaries.)

Last edited by anomie; 03-09-2011 at 05:13 PM.
 
Old 03-09-2011, 05:24 PM   #5
anomie
Senior Member
 
Registered: Nov 2004
Location: Texas
Distribution: RHEL, Scientific Linux, Debian, Fedora
Posts: 3,935
Blog Entries: 5

Rep: Reputation: Disabled
Quote:
Originally Posted by Cultist
Basically, would this be enough to foil any dedicated cracking efforts? I don't mean like if the NSA decided they wanted to break my password, but if some script kiddie with a powerful computer and lots of time tried, would it be secure?
Again, that part is debatable. I'd argue that your key selection is woefully inadequate if you need to be able to defend against a dedicated offline attack.

Look into something like pwgen(1), and shoot for something with good character class diversity and 20+ bytes in length. That should create enough difficulty that they'll just smack you with a rubber-hose cryptanalysis instead.
 
Old 03-10-2011, 08:29 AM   #6
H_TeXMeX_H
LQ Guru
 
Registered: Oct 2005
Location: $RANDOM
Distribution: slackware64
Posts: 12,928
Blog Entries: 2

Rep: Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301
See:
http://www.passwordmeter.com/
or search google.

Personally, for really secure passwords I use hashes, although I'm sure there are even better ways to generate good passwords.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
secure login password shaveta Linux - Security 1 01-20-2011 12:25 AM
[SOLVED] how to secure folders and files with password senthil1186 Red Hat 2 10-01-2010 07:51 AM
Firefox master password: how secure is it ? PlatinumX Linux - Security 3 08-27-2009 06:29 AM
Secure Password Management win32sux General 0 04-30-2005 08:11 AM
Secure Password Authenication danielrcummins Linux - Software 2 03-26-2003 09:05 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - General

All times are GMT -5. The time now is 04:53 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration