Other Resources My Cup of Joe » If you have a LinkedIn account ... Rss Feed  
Moderators: k9car363, the bear, DerekL, alicefoeller Reply
 
 
of 2
 
 
2012-06-06 8:11 PM

Iron Donkey
38643
50005000500050005000500050002000100050010025
, Wisconsin
Subject: If you have a LinkedIn account ...


2012-06-06 8:30 PM
in reply to: #4248788

User image

Elite
5145
500010025
Cleveland
Subject: RE: If you have a LinkedIn account ...
Thanks for the heads up.
2012-06-07 8:38 AM
in reply to: #4248788

User image

Extreme Veteran
799
500100100252525
Subject: RE: If you have a LinkedIn account ...
If you use that password for anything else, you probably want to change it their as well.  If they can figure out your login to another site by the info in linkedIn, say your e-mail address, then they may likely try to log into that account as well.
2012-06-07 12:17 PM
in reply to: #4249410

User image

Master
2946
200050010010010010025
Centennial, CO
Subject: RE: If you have a LinkedIn account ...

This is where it becomes hard. I have accounts on probably 50 - 60 sites when I really look at things.  This is one of my older accounts and uses an older email username.  But I would be hard pressed to remember all the sites that I may or may not use that email/password combination.  Fortunately it is not the password for the email account itself.

It makes me wonder how to keep track of all the accounts.  Especially in this age of smartphones where everything from google reader to words with friends requires you to sign in.

2012-06-07 12:43 PM
in reply to: #4248788

User image

Extreme Veteran
612
500100
England
Subject: RE: If you have a LinkedIn account ...
They reset my password (and presumably everybody's) this morning. We need to create a new password at next logon.
2012-06-07 1:00 PM
in reply to: #4249995

User image

Veteran
441
10010010010025
Maine
Subject: RE: If you have a LinkedIn account ...
velocomp - 2012-06-07 1:17 PM

This is where it becomes hard. I have accounts on probably 50 - 60 sites when I really look at things.  This is one of my older accounts and uses an older email username.  But I would be hard pressed to remember all the sites that I may or may not use that email/password combination.  Fortunately it is not the password for the email account itself.

It makes me wonder how to keep track of all the accounts.  Especially in this age of smartphones where everything from google reader to words with friends requires you to sign in.

I use http://keepass.info/

Share the database between all my devices & I have it set up to require both a password and encrypted key file to open.



2012-06-07 2:36 PM
in reply to: #4249410

User image

Champion
7347
5000200010010010025
SRQ, FL
Subject: RE: If you have a LinkedIn account ...

jmcconne - 2012-06-07 9:38 AM If you use that password for anything else, you probably want to change it their as well.  If they can figure out your login to another site by the info in linkedIn, say your e-mail address, then they may likely try to log into that account as well.

Relevant: http://xkcd.com/792/

2012-06-07 2:39 PM
in reply to: #4248788

User image

Extreme Veteran
875
500100100100252525
Issaquah
Subject: RE: If you have a LinkedIn account ...

Also a good time to remind everyone not to use passwords that are "easy". From the article looks like they posted only the hashed versions of the password, not the real password. That sucks, but sucks less than if it had been the actual password (which, in a secure system isn't stored anyway). People doing a lookup against simple passwords like 12345 (my luggage) the thieves can use the hash to figure out a simple/common password. (Note this doesn't work with difficult to guess passwords with numbers, symbols, capital letters etc.)

I use LastPass to create and manage passwords for me. Simple, works great at much more secure than an easy to remember, but useless, password.

2012-06-07 4:02 PM
in reply to: #4250376

User image

Champion
7347
5000200010010010025
SRQ, FL
Subject: RE: If you have a LinkedIn account ...
cnsegura - 2012-06-07 3:39 PM

Also a good time to remind everyone not to use passwords that are "easy". From the article looks like they posted only the hashed versions of the password, not the real password. That sucks, but sucks less than if it had been the actual password (which, in a secure system isn't stored anyway). People doing a lookup against simple passwords like 12345 (my luggage) the thieves can use the hash to figure out a simple/common password. (Note this doesn't work with difficult to guess passwords with numbers, symbols, capital letters etc.)

I use LastPass to create and manage passwords for me. Simple, works great at much more secure than an easy to remember, but useless, password.

Also relevant: http://xkcd.com/936/

2012-06-07 4:33 PM
in reply to: #4250567

User image

Extreme Veteran
875
500100100100252525
Issaquah
Subject: RE: If you have a LinkedIn account ...
TriRSquared - 2012-06-07 2:02 PM
cnsegura - 2012-06-07 3:39 PM

Also a good time to remind everyone not to use passwords that are "easy". From the article looks like they posted only the hashed versions of the password, not the real password. That sucks, but sucks less than if it had been the actual password (which, in a secure system isn't stored anyway). People doing a lookup against simple passwords like 12345 (my luggage) the thieves can use the hash to figure out a simple/common password. (Note this doesn't work with difficult to guess passwords with numbers, symbols, capital letters etc.)

I use LastPass to create and manage passwords for me. Simple, works great at much more secure than an easy to remember, but useless, password.

Also relevant: http://xkcd.com/936/

 

But amazingly incorrect. That second password *might* be more secure, but only because it's longer. Computer pwd cracking cares only about how long (really how many combinations) a password has not that it's easy/hard to remember. Make both passwords the same length, but in one only allow real words, and in the second one force the use of caps, numbers, punctuation etc. and the second password strength increases exponentially (because you have more combinations that need to be tried) while the first one remains rather simple to hack because all the computer has to do is try fixed combinations of the 26 character alphabet.

 

 



Edited by cnsegura 2012-06-07 4:35 PM
2012-06-07 5:11 PM
in reply to: #4250647

User image

Pro
6767
500010005001001002525
the Alabama part of Pennsylvania
Subject: RE: If you have a LinkedIn account ...
cnsegura - 2012-06-07 5:33 PM
TriRSquared - 2012-06-07 2:02 PM
cnsegura - 2012-06-07 3:39 PM

Also a good time to remind everyone not to use passwords that are "easy". From the article looks like they posted only the hashed versions of the password, not the real password. That sucks, but sucks less than if it had been the actual password (which, in a secure system isn't stored anyway). People doing a lookup against simple passwords like 12345 (my luggage) the thieves can use the hash to figure out a simple/common password. (Note this doesn't work with difficult to guess passwords with numbers, symbols, capital letters etc.)

I use LastPass to create and manage passwords for me. Simple, works great at much more secure than an easy to remember, but useless, password.

Also relevant: http://xkcd.com/936/

 

But amazingly incorrect. That second password *might* be more secure, but only because it's longer. Computer pwd cracking cares only about how long (really how many combinations) a password has not that it's easy/hard to remember. Make both passwords the same length, but in one only allow real words, and in the second one force the use of caps, numbers, punctuation etc. and the second password strength increases exponentially (because you have more combinations that need to be tried) while the first one remains rather simple to hack because all the computer has to do is try fixed combinations of the 26 character alphabet.

 

OF course being longer it is more secure. That's what it means when it refers to how many bits are in the password. But it is still correct in that a nonsense phrase is going to be easier to remember for a human than the normal "strong" passwords that have to have a mix of capital and lower case letters, numbers, and symbols (except for "@" and "#"), which are the rules for some sites. Being hard to remember is amplified when you have to change passwords every 6 weeks (like my workplace) - which results in people writing down the password on a physical piece of paper and sticking on the computer. Which ends up being the opposite of secure.



2012-06-07 7:34 PM
in reply to: #4250720

User image

Champion
7347
5000200010010010025
SRQ, FL
Subject: RE: If you have a LinkedIn account ...
gearboy - 2012-06-07 6:11 PM
cnsegura - 2012-06-07 5:33 PM
TriRSquared - 2012-06-07 2:02 PM
cnsegura - 2012-06-07 3:39 PM

Also a good time to remind everyone not to use passwords that are "easy". From the article looks like they posted only the hashed versions of the password, not the real password. That sucks, but sucks less than if it had been the actual password (which, in a secure system isn't stored anyway). People doing a lookup against simple passwords like 12345 (my luggage) the thieves can use the hash to figure out a simple/common password. (Note this doesn't work with difficult to guess passwords with numbers, symbols, capital letters etc.)

I use LastPass to create and manage passwords for me. Simple, works great at much more secure than an easy to remember, but useless, password.

Also relevant: http://xkcd.com/936/

 

But amazingly incorrect. That second password *might* be more secure, but only because it's longer. Computer pwd cracking cares only about how long (really how many combinations) a password has not that it's easy/hard to remember. Make both passwords the same length, but in one only allow real words, and in the second one force the use of caps, numbers, punctuation etc. and the second password strength increases exponentially (because you have more combinations that need to be tried) while the first one remains rather simple to hack because all the computer has to do is try fixed combinations of the 26 character alphabet.

 

OF course being longer it is more secure. That's what it means when it refers to how many bits are in the password. But it is still correct in that a nonsense phrase is going to be easier to remember for a human than the normal "strong" passwords that have to have a mix of capital and lower case letters, numbers, and symbols (except for "@" and "#"), which are the rules for some sites. Being hard to remember is amplified when you have to change passwords every 6 weeks (like my workplace) - which results in people writing down the password on a physical piece of paper and sticking on the computer. Which ends up being the opposite of secure.

Exactly... what's easier to remember...

RunBikeSwimBackwards (<- not my password to BT)

or

shyT%$#uy90ccrrt%=!



Edited by TriRSquared 2012-06-07 7:35 PM
2012-06-07 7:48 PM
in reply to: #4248788

User image

Payson, AZ
Subject: RE: If you have a LinkedIn account ...
It takes me over two hours every month to change all my passwords for work.  And the number of them I have keeps growing.  A sticky note is not sufficient for me so I know use an excel spreadsheet.  The rules on the passwords are so messed up I don't even try and remember them.  I randomly type until I find one that it will accept on the most restrictive system and use that.  I get password rage every single month. 
2012-06-07 8:39 PM
in reply to: #4250870

User image

Extreme Veteran
875
500100100100252525
Issaquah
Subject: RE: If you have a LinkedIn account ...
TriRSquared - 2012-06-07 5:34 PM

Exactly... what's easier to remember...

RunBikeSwimBackwards (

or

shyT%$#uy90ccrrt%=!

But for a computer cracking program, the second one is MUCH harder to crack. Sorry, but assuming basic words, particularly words/phrases that can be typed into a typical 8-12 password field is secure just because it's not in "standard" English speaking order is poor security. The computer doesn't care what order the words are typed in. ALL it cares about is how many combinations must be tried before it happens to land on the right order of letters. A password that is easily remembered but easily hacked is useless.

If remembering passwords is really that big a deal, use the services listed here (LastPass etc.) It will generate a strong password, that you don't have to remember at all, it will even fill in your username/pwd for you on a website.

None of this necessarily means that a password has to be hard to use. There are plenty of good ideas being used out there with pattern recognition etc. that do make it secure, and easy to remember However, if typed out words is your option, more variation, not less is better.

2012-06-07 9:16 PM
in reply to: #4248788

Iron Donkey
38643
50005000500050005000500050002000100050010025
, Wisconsin
Subject: RE: If you have a LinkedIn account ...
So, now I know your passwords.
2012-06-08 8:59 AM
in reply to: #4250942

User image

Champion
7347
5000200010010010025
SRQ, FL
Subject: RE: If you have a LinkedIn account ...
cnsegura - 2012-06-07 9:39 PM
TriRSquared - 2012-06-07 5:34 PM

Exactly... what's easier to remember...

RunBikeSwimBackwards (

or

shyT%$#uy90ccrrt%=!

But for a computer cracking program, the second one is MUCH harder to crack. Sorry, but assuming basic words, particularly words/phrases that can be typed into a typical 8-12 password field is secure just because it's not in "standard" English speaking order is poor security. The computer doesn't care what order the words are typed in. ALL it cares about is how many combinations must be tried before it happens to land on the right order of letters. A password that is easily remembered but easily hacked is useless.

If remembering passwords is really that big a deal, use the services listed here (LastPass etc.) It will generate a strong password, that you don't have to remember at all, it will even fill in your username/pwd for you on a website.

None of this necessarily means that a password has to be hard to use. There are plenty of good ideas being used out there with pattern recognition etc. that do make it secure, and easy to remember However, if typed out words is your option, more variation, not less is better.

Now THAT'S bad security.  Having your passwords all in one place and set to autofill on websites  No way.  That's like not even having a password.  All I have to do is nab your laptop and I have access to all of your accounts and the ability to change the passwords.

 



2012-06-08 9:28 AM
in reply to: #4251507

User image

Champion
6503
50001000500
NOVA - Ironic for an Endurance Athlete
Subject: RE: If you have a LinkedIn account ...
TriRSquared - 2012-06-08 8:59 AM
cnsegura - 2012-06-07 9:39 PM
TriRSquared - 2012-06-07 5:34 PM

Exactly... what's easier to remember...

RunBikeSwimBackwards (

or

shyT%$#uy90ccrrt%=!

But for a computer cracking program, the second one is MUCH harder to crack. Sorry, but assuming basic words, particularly words/phrases that can be typed into a typical 8-12 password field is secure just because it's not in "standard" English speaking order is poor security. The computer doesn't care what order the words are typed in. ALL it cares about is how many combinations must be tried before it happens to land on the right order of letters. A password that is easily remembered but easily hacked is useless.

If remembering passwords is really that big a deal, use the services listed here (LastPass etc.) It will generate a strong password, that you don't have to remember at all, it will even fill in your username/pwd for you on a website.

None of this necessarily means that a password has to be hard to use. There are plenty of good ideas being used out there with pattern recognition etc. that do make it secure, and easy to remember However, if typed out words is your option, more variation, not less is better.

Now THAT'S bad security.  Having your passwords all in one place and set to autofill on websites  No way.  That's like not even having a password.  All I have to do is nab your laptop and I have access to all of your accounts and the ability to change the passwords.

 

Great!  Unless lastpass gets hacked.

2012-06-08 9:37 AM
in reply to: #4251507

User image

Payson, AZ
Subject: RE: If you have a LinkedIn account ...
TriRSquared - 2012-06-08 6:59 AM
cnsegura - 2012-06-07 9:39 PM
TriRSquared - 2012-06-07 5:34 PM

Exactly... what's easier to remember...

RunBikeSwimBackwards (

or

shyT%$#uy90ccrrt%=!

But for a computer cracking program, the second one is MUCH harder to crack. Sorry, but assuming basic words, particularly words/phrases that can be typed into a typical 8-12 password field is secure just because it's not in "standard" English speaking order is poor security. The computer doesn't care what order the words are typed in. ALL it cares about is how many combinations must be tried before it happens to land on the right order of letters. A password that is easily remembered but easily hacked is useless.

If remembering passwords is really that big a deal, use the services listed here (LastPass etc.) It will generate a strong password, that you don't have to remember at all, it will even fill in your username/pwd for you on a website.

None of this necessarily means that a password has to be hard to use. There are plenty of good ideas being used out there with pattern recognition etc. that do make it secure, and easy to remember However, if typed out words is your option, more variation, not less is better.

Now THAT'S bad security.  Having your passwords all in one place and set to autofill on websites  No way.  That's like not even having a password.  All I have to do is nab your laptop and I have access to all of your accounts and the ability to change the passwords.

 

Ah, but my laptop is encrypted.  So first you must get through that password.  Course I use an Excel spreadsheet....

2012-06-08 9:43 AM
in reply to: #4250942

User image

Pro
6767
500010005001001002525
the Alabama part of Pennsylvania
Subject: RE: If you have a LinkedIn account ...
cnsegura - 2012-06-07 9:39 PM
TriRSquared - 2012-06-07 5:34 PM

Exactly... what's easier to remember...

RunBikeSwimBackwards (

or

shyT%$#uy90ccrrt%=!

But for a computer cracking program, the second one is MUCH harder to crack. Sorry, but assuming basic words, particularly words/phrases that can be typed into a typical 8-12 password field is secure just because it's not in "standard" English speaking order is poor security. The computer doesn't care what order the words are typed in. ALL it cares about is how many combinations must be tried before it happens to land on the right order of letters. A password that is easily remembered but easily hacked is useless.

If remembering passwords is really that big a deal, use the services listed here (LastPass etc.) It will generate a strong password, that you don't have to remember at all, it will even fill in your username/pwd for you on a website.

None of this necessarily means that a password has to be hard to use. There are plenty of good ideas being used out there with pattern recognition etc. that do make it secure, and easy to remember However, if typed out words is your option, more variation, not less is better.

If both passwords have the same number of characters, then a hacking program will take roughly the same amount of time, since it has no way to know whether or not to exclude numbers and symbols, or to use caps or lower case. But the human who has to remember it will struggle to remember the "odd" one, but easily recall the "easy" one. 

Biomterics are going to be the future, although I always think about things like having my eyeball/iris damaged, or losing my thumb in an accident, or having a stroke and thus changing my typing patterns - all of which would result in being unable to use my secured sites.

2012-06-08 10:44 AM
in reply to: #4251615

User image

Champion
7347
5000200010010010025
SRQ, FL
Subject: RE: If you have a LinkedIn account ...
gearboy - 2012-06-08 10:43 AM

Biomterics are going to be the future, although I always think about things like having my eyeball/iris damaged, or losing my thumb in an accident, or having a stroke and thus changing my typing patterns - all of which would result in being unable to use my secured sites.

Agreed.  I've always said why do we worry about your SS# and bank account #s getting out in the open.  They are going to get out there eventually.  We need a system that allows those #s to be public but useless w/o a unique ID that is PART of you.  Either voice pattern recognition (for phone calls) or biometric scans for in person.

2012-06-08 11:49 AM
in reply to: #4251776

User image

Pro
6767
500010005001001002525
the Alabama part of Pennsylvania
Subject: RE: If you have a LinkedIn account ...
TriRSquared - 2012-06-08 11:44 AM
gearboy - 2012-06-08 10:43 AM

Biomterics are going to be the future, although I always think about things like having my eyeball/iris damaged, or losing my thumb in an accident, or having a stroke and thus changing my typing patterns - all of which would result in being unable to use my secured sites.

Agreed.  I've always said why do we worry about your SS# and bank account #s getting out in the open.  They are going to get out there eventually.  We need a system that allows those #s to be public but useless w/o a unique ID that is PART of you.  Either voice pattern recognition (for phone calls) or biometric scans for in person.

Wait - are you agreeing with my observation that biometrics are coming, or my paranoid ravings about having my eyes fall out, losing my thumbs, and becoming paralyzed?



2012-06-08 12:42 PM
in reply to: #4251936

User image

Champion
7347
5000200010010010025
SRQ, FL
Subject: RE: If you have a LinkedIn account ...
gearboy - 2012-06-08 12:49 PM
TriRSquared - 2012-06-08 11:44 AM
gearboy - 2012-06-08 10:43 AM

Biomterics are going to be the future, although I always think about things like having my eyeball/iris damaged, or losing my thumb in an accident, or having a stroke and thus changing my typing patterns - all of which would result in being unable to use my secured sites.

Agreed.  I've always said why do we worry about your SS# and bank account #s getting out in the open.  They are going to get out there eventually.  We need a system that allows those #s to be public but useless w/o a unique ID that is PART of you.  Either voice pattern recognition (for phone calls) or biometric scans for in person.

Wait - are you agreeing with my observation that biometrics are coming, or my paranoid ravings about having my eyes fall out, losing my thumbs, and becoming paralyzed?

Yes...

2012-06-08 1:51 PM
in reply to: #4248788

User image

Champion
11989
500050001000500100100100100252525
Philly 'burbs
Subject: RE: If you have a LinkedIn account ...
Just logged in to change it and they forced me to anyway.

Edited by mrbbrad 2012-06-08 1:51 PM
2012-06-08 2:29 PM
in reply to: #4250886

User image

Elite
4564
200020005002525
Boise
Subject: RE: If you have a LinkedIn account ...

bzgl40 - 2012-06-07 6:48 PM It takes me over two hours every month to change all my passwords for work.  And the number of them I have keeps growing.  A sticky note is not sufficient for me so I know use an excel spreadsheet.  The rules on the passwords are so messed up I don't even try and remember them.  I randomly type until I find one that it will accept on the most restrictive system and use that.  I get password rage every single month. 

 

That reminds me of this one particular work website we have to login to for HR items. The password requirements are so stringent it took me about 50 tries to get one I could remember and that would work. I believe it was something along the lines of Gotoh3llHRsitePW!1!1(not actually my password but you get the idea).

2012-06-08 3:26 PM
in reply to: #4248788

User image

Regular
180
100252525
Clinton, TN
Subject: RE: If you have a LinkedIn account ...

When I logged into my account, it automatically took me to page to change my password. I am like others who use password for multiple sites. Fortunately not on sites with financial information. But hope I can remember them all after changing!!!
New Thread
Other Resources My Cup of Joe » If you have a LinkedIn account ... Rss Feed  
 
 
of 2