SlideShare une entreprise Scribd logo
1  sur  20
Why Your Password Sucks And how to fix it.
Rank These Passwords by “secureness” Missouri Fr33 b33r F(3)*4%1q1Ff! hotwings are awesome
Ranked by security…  hotwings are awesome F(3)*4%1q1Ff! Fr33 b33r Missouri
We told you a great password is.. 8 Characters Long. Has a few symbols. Has uppercase letters. Has lowercase letters. Has a number in it.
We told you a great password isn't… A word in the dictionary. Your dogs name. Your kids names. Your favorite sports team.  Anything easy to remember
   We told you these rocked… 2K1ds@hm <3Truman
We were wrong!!!!(Seriously)
The truth is they suck… 2K1ds@hm Can be cracked in 1.12 Minutes <3Truman Can be cracked in 1.22 Minutes All times taken from https://www.grc.com/haystack
 Why did we lie to you? 5 years ago brute forcing passwords was nearly impossible. If your password wasn’t in the dictionary you were pretty safe.
 Then along came Amazon $1.60 an hour I can have the power of8 3.0 GHZ server at my disposal.  Can processes a billion passwords attempts second.
   At that speed… A 8 character password can be brute forced in under 90 seconds.
 How do we fix it?  BY NEVER USING THE WORD “PASSWORD” AGAIN.
 How do we fix it? INSTEAD THE NEW WORD IS:PASSPHRASE
   Rules for a good passphrase At least 15 characters long. The longer the better. “That’s what she said?” Use whatever words you want. Make it easy to remember.
 My last passphrase was… Landon loves to swing
That passphrase is… 21 characters long It would take 1.06 hundred thousand trillion centuries to brute force using an Amazon cluster.
 In five years…  Computers will be faster and passphrases will be as crappy as passwords. Sorry
  2FA is next!  Two Factor Authenticationis something you know, and something you have.
   Free 2FA Facebook  Google Most Banks
  Thank you for your time… Go change your passphrases!

Contenu connexe

En vedette

Chapter4.6
Chapter4.6Chapter4.6
Chapter4.6
nglaze10
 
Chapter2.6
Chapter2.6Chapter2.6
Chapter2.6
nglaze10
 
Striking the Right Balance: Free vs. Fee Account Strategies (Recorded Webinar...
Striking the Right Balance: Free vs. Fee Account Strategies (Recorded Webinar...Striking the Right Balance: Free vs. Fee Account Strategies (Recorded Webinar...
Striking the Right Balance: Free vs. Fee Account Strategies (Recorded Webinar...
NAFCU Services Corporation
 
Notes 2.6 2013
Notes 2.6 2013Notes 2.6 2013
Notes 2.6 2013
nglaze10
 
Parts of body
Parts of bodyParts of body
Parts of body
dianallan
 
цахим 2в
цахим 2вцахим 2в
цахим 2в
Zaya80
 
Metlifewebsitepresentation
MetlifewebsitepresentationMetlifewebsitepresentation
Metlifewebsitepresentation
ashleymannes
 
New week 4
New week 4New week 4
New week 4
nglaze10
 

En vedette (16)

Chapter4.6
Chapter4.6Chapter4.6
Chapter4.6
 
Youtubeři v Čechách
Youtubeři v ČecháchYoutubeři v Čechách
Youtubeři v Čechách
 
Em Dash Usage
Em Dash UsageEm Dash Usage
Em Dash Usage
 
Chapter2.6
Chapter2.6Chapter2.6
Chapter2.6
 
Striking the Right Balance: Free vs. Fee Account Strategies (Recorded Webinar...
Striking the Right Balance: Free vs. Fee Account Strategies (Recorded Webinar...Striking the Right Balance: Free vs. Fee Account Strategies (Recorded Webinar...
Striking the Right Balance: Free vs. Fee Account Strategies (Recorded Webinar...
 
The Consumer Marketplace in an Ageing Society
The Consumer Marketplace in an Ageing SocietyThe Consumer Marketplace in an Ageing Society
The Consumer Marketplace in an Ageing Society
 
Notes 2.6 2013
Notes 2.6 2013Notes 2.6 2013
Notes 2.6 2013
 
2012 Ford Mustang For Sale NE | Ford Dealer Nebraska
2012 Ford Mustang For Sale NE | Ford Dealer Nebraska2012 Ford Mustang For Sale NE | Ford Dealer Nebraska
2012 Ford Mustang For Sale NE | Ford Dealer Nebraska
 
Parts of body
Parts of bodyParts of body
Parts of body
 
цахим 2в
цахим 2вцахим 2в
цахим 2в
 
Walla faces dinner
Walla faces dinnerWalla faces dinner
Walla faces dinner
 
Licence to Play interactive E-brochure
Licence to Play interactive E-brochureLicence to Play interactive E-brochure
Licence to Play interactive E-brochure
 
Metlifewebsitepresentation
MetlifewebsitepresentationMetlifewebsitepresentation
Metlifewebsitepresentation
 
Intro to Pattern Lab
Intro to Pattern LabIntro to Pattern Lab
Intro to Pattern Lab
 
Email Split Testing is Essential for Profitability
Email Split Testing is Essential for ProfitabilityEmail Split Testing is Essential for Profitability
Email Split Testing is Essential for Profitability
 
New week 4
New week 4New week 4
New week 4
 

Similaire à Why your password sucks (6)

Computer Privacy:Passwords-Mike B.
Computer Privacy:Passwords-Mike B.Computer Privacy:Passwords-Mike B.
Computer Privacy:Passwords-Mike B.
 
Passphrases presentation rev1
Passphrases presentation rev1Passphrases presentation rev1
Passphrases presentation rev1
 
Password Policies
Password PoliciesPassword Policies
Password Policies
 
How to Create a Quality Password
How to Create a Quality PasswordHow to Create a Quality Password
How to Create a Quality Password
 
Passwords, Passwords and more Passwords
Passwords, Passwords and more PasswordsPasswords, Passwords and more Passwords
Passwords, Passwords and more Passwords
 
UX of Passwords | Refresh Seattle | Claire Carlson
UX of Passwords  |  Refresh Seattle  |  Claire CarlsonUX of Passwords  |  Refresh Seattle  |  Claire Carlson
UX of Passwords | Refresh Seattle | Claire Carlson
 

Dernier

Dernier (20)

Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?
 
HTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation StrategiesHTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation Strategies
 
Advantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your BusinessAdvantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your Business
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf
 

Why your password sucks

  • 1. Why Your Password Sucks And how to fix it.
  • 2. Rank These Passwords by “secureness” Missouri Fr33 b33r F(3)*4%1q1Ff! hotwings are awesome
  • 3. Ranked by security… hotwings are awesome F(3)*4%1q1Ff! Fr33 b33r Missouri
  • 4. We told you a great password is.. 8 Characters Long. Has a few symbols. Has uppercase letters. Has lowercase letters. Has a number in it.
  • 5. We told you a great password isn't… A word in the dictionary. Your dogs name. Your kids names. Your favorite sports team. Anything easy to remember
  • 6. We told you these rocked… 2K1ds@hm <3Truman
  • 8. The truth is they suck… 2K1ds@hm Can be cracked in 1.12 Minutes <3Truman Can be cracked in 1.22 Minutes All times taken from https://www.grc.com/haystack
  • 9. Why did we lie to you? 5 years ago brute forcing passwords was nearly impossible. If your password wasn’t in the dictionary you were pretty safe.
  • 10. Then along came Amazon $1.60 an hour I can have the power of8 3.0 GHZ server at my disposal. Can processes a billion passwords attempts second.
  • 11. At that speed… A 8 character password can be brute forced in under 90 seconds.
  • 12. How do we fix it? BY NEVER USING THE WORD “PASSWORD” AGAIN.
  • 13. How do we fix it? INSTEAD THE NEW WORD IS:PASSPHRASE
  • 14. Rules for a good passphrase At least 15 characters long. The longer the better. “That’s what she said?” Use whatever words you want. Make it easy to remember.
  • 15. My last passphrase was… Landon loves to swing
  • 16. That passphrase is… 21 characters long It would take 1.06 hundred thousand trillion centuries to brute force using an Amazon cluster.
  • 17. In five years… Computers will be faster and passphrases will be as crappy as passwords. Sorry
  • 18. 2FA is next! Two Factor Authenticationis something you know, and something you have.
  • 19. Free 2FA Facebook Google Most Banks
  • 20. Thank you for your time… Go change your passphrases!