*Mantiki-network™ The real information online to you*Mantiki-network™ The real information online to you*

facebook hack by hacker

Posting By Mantiki-network™ Thursday, September 10, 2009

Last week I talked about how someone hacked into my Facebook account. They did that by guessing my password.

I was weak, and so was the password. I guess I'd not thought my Facebook account worth cracking into. But that was poor thinking. Anything with a password is worth hacking into. Even if it's only to dig around for more things worth hacking into.

Say someone hacks into your email. They'll then get access to all the emails you've saved - which may include bank account numbers, other passwords - all sorts of stuff.

So, rule number one of passwords is: It should always be a good one.

Rule number two: No two passwords should be the same.

This is the bit where you all groan. How can we possibly have different passwords for all the dozens of services we're asked to think up passwords to?

Well, it's not hard. You just need a system. Several systems, actually, but let's keep it simple for now.

Firstly, what makes a good password?

For starters it shouldn't be a word. A word can be guessed. Or attacked - the hacker will first throw a dictionary - actually, just a long list of thousands of words - at your password, and try all those.

So if your password is a word, then it's easy pickings. Probably just a couple of seconds.

So if it's not a word, what can it be?

A phrase is a good one. Boardwalk, for example, is a word. Guessed in a second. Undertheboardwalk is a phrase. A dictionary attack is going to have a bit more trouble with that, because it's three words, and that makes it many times harder.

But still not impossible.

So how about putting some extra characters in there? Say, some underscores: under_the_boardwalk. Not bad. Adding characters that aren't letters is always good. Though still a little predictable.

How about putting something other than underscores? Exclamation marks, say?

All good. Now let's add some numbers.

The usual trick is to replace letters with numbers that look similar: 3 for e, for example. Or 0 for o. Not bad, but still a little predictable. That's when you need to get a little inventive.

One option, for example, might be to replace any letter on the top row of your QWERTY keyboard with the number or symbol above it (or above and to the right, say).

So r, for example, becomes 5. That would make our password und45!6h4!b0a5d3alk.

(Check it out on your keyboard to make sure I've not made any mistakes. And beware of non-standard keyboards - sometimes the layout is not identical, especially if they're non-English.)

But there we have an excellent password. Nineteen characters long - too long, you may find, for some systems, but nothing wrong with going long if you're allowed. The longer the password, the harder it is to hack.

Now I can hear the grumbles. This is way too complicated for me! How am I going to remember all these rules, even if I can remember the original password (or passphrase)?

Good questions. But if you do the same thing for all your passwords - replacing spaces with exclamation marks, lifting the top layer of letters up a row - then you'll find you remember the system for each one, even if you couldn't recite the passphrase off in your head. Once you're at the keyboard, you'll be able to navigate your way.

Now, of course, this is just one passphrase. You'll have to come up with a dozen or so more. Which is where your memories come in. Things you can remember easily, but a bad guy has no way of finding out.

Your kids' names are not good. Neither, surprisingly, is your birthday.

But the first song you kissed someone to? Or your top 10 favorite movies? A poem you were forced to learn at school to remember the Latin prepositions? A silly jingle for acne cream that hasn't been broadcast in 20 years but still rolls around your head?

These are all good sources of passwords.

The longer the better. If they're more than eight words, just use the first letter of each and you've got an eight letter password that won't make sense to anyone but yourself. Try to get four. When you've gathered, say, four of these, jumbled them up with some rules you've designed as above, then you're ready to deploy.

The next tricky bit is remembering which password you used with what website or service.

Here's a suggestion how. Time again to dig into your past. If say, one of your passwords is based on the song you were listening to when you first kissed, chances are you'll remember how old you were. So plot that age on a timeline of your life from birth to now - was it a third of the way through, or half way through? A quarter?

Now look at the website address or service you need to come up with a passphrase for.

Let's say it's Facebook. The first letter, f, is quite near the front of the alphabet, so let's try to find one of the passwords we've got which we can easily connect it to. In the case above, I'd connect it to the first quarter of my life until now (because f is so close to the beginning) so I'd choose my Latin rhyme, as I was about 10 when I learned it.

Whatever system you use for this, it needs to be a logical system - one that doesn't take much brain wracking to recall.

There's one more step. You've only got four passwords, and you've got more than four passwords you need. So you need to add some extra sauce.

In this case, from the service itself.

So, say it's Facebook. You could add some letters from the Facebook name to your password. Once again, it doesn't matter, what, so long as you do the same each time. You could preface your password with F, and suffix it with K.

Or that might be too obvious for you. How about the third and the fifth letters? Doesn't matter, so long as you do the same for each password you conjure up for each service.

You're nearly done.

I can still hear you grumbling. This is too hard! How am I going to remember this? Well, that's the good thing about these passwords. You don't need to; you can write them down.

Well, not the exact password, of course. But something that would trigger it.

For the Facebook password, if you had chosen the song you first kissed to, prefaced by the first and third letter of the service, you could write down somewhere: 13kiss.

That's not going to mean much to anyone but you.

The important thing is to have a system, and to use it for all passwords. Then all you have to do is remember the system, and write down whatever will jog your memory for that specific password. And of course, you can try - indeed, should try - other systems than mine.

And remember: However unimportant you think the data is, it's valuable to someone, so you should invest a bit of time and effort in a password that's worthy of it. Let me know your suggestions for how to further improve on passwords; I'm always up for more ideas.

(c) 2009 Loose Wire Pte Ltd

This story cannot be reproduced without written permission from the writer. Jeremy Wagstaff is a commentator on technology and appears regularly on the BBC World Service. He can be found online at jeremywagstaff.com or via email at jeremy@loose-wire.com

0 komentar

Post a Comment

Live Streaming TV Online from TVONE indonesia
Mantiki-network™