{"id":631,"date":"2007-08-03T21:41:41","date_gmt":"2007-08-03T20:41:41","guid":{"rendered":"http:\/\/www.craigmurphy.com\/blog\/?p=631"},"modified":"2007-08-03T22:32:53","modified_gmt":"2007-08-03T21:32:53","slug":"password-security-even-big-names-fail","status":"publish","type":"post","link":"http:\/\/www.craigmurphy.com\/blog\/?p=631","title":{"rendered":"Password security &#8211; even big names fail"},"content":{"rendered":"<p>Great mate <a href=\"http:\/\/www.idunno.org\">Barry<\/a> and  I did a podcast yesterday.  In and around the podcast, we chatted about password security, a subject not missed by fellow great mate <a href=\"http:\/\/blackhatspider.wordpress.com\/\">Alan<\/a> &#8211; he&#8217;s a great fan of pass phrases (i.e. a sentence instead of a single word).  So yesterday, whilst in London, Barry picked up an Oyster card application form &#8211; I&#8217;m kind of interested in getting one, if only to maintain the stereotype of a Scotsman (although <a href=\"http:\/\/www.johnsmeaton.com\/\">Mr Smeaton<\/a> has changed that!)  <\/p>\n<p>Imagine my surprise at reading section 3. Password:<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.craigmurphy.com\/blog\/wp-content\/uploads\/2007\/08\/oyster.jpg\" \/><\/p>\n<p>What&#8217;s this all about?  A password is now called an <strong>answer<\/strong>.  The password can&#8217;t be longer than 18 characters and cannot use spaces or punctuation?  Adding a space or two and some punctuation is the first step to making a strong or <strong>secure <\/strong>password.  Limiting it to 18 characters, including numerical values, rules out <strong>pass phrases<\/strong> (which are harder to guess and less prone to dictionary attacks).  But, the other answers on this part of the form, can include spaces.  Your mother&#8217;s maiden name?  Does it have spaces?  <\/p>\n<p>Better wording of this question and more flexibility for the password are required&#8230;surely?<\/p>\n<p>Technorati Tags: <a href=\"http:\/\/technorati.com\/tag\/password\" rel=\"tag\">password<\/a>, <a href=\"http:\/\/technorati.com\/tag\/passwords\" rel=\"tag\">passwords<\/a>, <a href=\"http:\/\/technorati.com\/tag\/password+security\" rel=\"tag\">password security<\/a>, <a href=\"http:\/\/technorati.com\/tag\/password+insecurity\" rel=\"tag\">password insecurity<\/a>, <a href=\"http:\/\/technorati.com\/tag\/passphrase\" rel=\"tag\">passphrase<\/a>, <a href=\"http:\/\/technorati.com\/tag\/pass+phrase\" rel=\"tag\">pass phrase<\/a>, <a href=\"http:\/\/technorati.com\/tag\/passphrases\" rel=\"tag\">passphrases<\/a>, <a href=\"http:\/\/technorati.com\/tag\/pass+phrases\" rel=\"tag\">pass phrases<\/a>, <a href=\"http:\/\/technorati.com\/tag\/oyster\" rel=\"tag\">oyster<\/a>, <a href=\"http:\/\/technorati.com\/tag\/oyster+card\" rel=\"tag\">oyster card<\/a>, <a href=\"http:\/\/technorati.com\/tag\/Barry+Dorrans\" rel=\"tag\">Barry Dorrans<\/a>, <a href=\"http:\/\/technorati.com\/tag\/Alan+Henderson\" rel=\"tag\">Alan Henderson<\/a>, <a href=\"http:\/\/technorati.com\/tag\/blackhatspider\" rel=\"tag\">blackhatspider<\/a>, <a href=\"http:\/\/technorati.com\/tag\/idunno\" rel=\"tag\">idunno<\/a>, <a href=\"http:\/\/technorati.com\/tag\/dictionary+attacks\" rel=\"tag\">dictionary attacks<\/a>, <a href=\"http:\/\/technorati.com\/tag\/johnsmeaton.com\" rel=\"tag\">johnsmeaton.com<\/a>, <a href=\"http:\/\/technorati.com\/tag\/john+smeaton\" rel=\"tag\">john smeaton<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Great mate Barry and I did a podcast yesterday. In and around the podcast, we chatted about password security, a subject not missed by fellow great mate Alan &#8211; he&#8217;s a great fan of pass phrases (i.e. a sentence instead of a single word). So yesterday, whilst in London, Barry picked up an Oyster card &hellip; <a href=\"http:\/\/www.craigmurphy.com\/blog\/?p=631\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Password security &#8211; even big names fail<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[21],"tags":[],"class_list":["post-631","post","type-post","status-publish","format-standard","hentry","category-security"],"_links":{"self":[{"href":"http:\/\/www.craigmurphy.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/631","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.craigmurphy.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.craigmurphy.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.craigmurphy.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.craigmurphy.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=631"}],"version-history":[{"count":0,"href":"http:\/\/www.craigmurphy.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/631\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.craigmurphy.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=631"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.craigmurphy.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=631"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.craigmurphy.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=631"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}