Automated hacking tools swarm Web site login pages - CSO Online - Security and Risk
Posted by UncommonSense 11 years, 5 months ago to Technology
This is one of my favorite sites for professional Situational Awareness on the IT Security front. Take heed of the information and if anyone has a dictionary word + any numbers as a password, you'd better step up and change it to something harder. FYI.
http://arstechnica.com/security/2013/05/...
One of these password cracking machine is built from four Gameboy boxes. (Bless those graphics processors!)
Basically, no two-factor authentication - username and password - is secure. To be reasonable (only that much) you need a password and also biometrics.
Try these links
http://arstechnica.com/search/?query=pas...
You have absolutely no idea...
http://en.wikipedia.org/wiki/Rainbow_tab...
Instead, use the NSA guidelines: (yes, I know they aren't exactly popular right now, just keep calm! :) ) Minimum of 2 upper case, 2 lower case, 2 numbers and 2 special characters with a 10 character minimum length overall ~ that means you'll use more than 2 of one of letters/numbers/special characters. Change out every 45 days (if you're really concerned) and you'll be good to go.
Oh, don't think you're so slick if you substitute one of the letters or numbers in the middle of the word and believe you'll fool a password cracking program: for example...P@ssw0rd....that is very weak and it would be brute forced in no time. Use pass phrases instead.
Of course, if crackers are running loose in your program space, you're hosed anyway.
Others, may employ tools such as cloud-cracking sites such as cloudcracker.com. FYI.