Guild Wars Forums - GW Guru
 
 

Go Back   Guild Wars Forums - GW Guru > Forest of True Sight > Technician's Corner

Notices

Reply
 
Thread Tools Display Modes
Old Nov 05, 2009, 03:48 PM // 15:48   #1
Site Contributor
 
Join Date: Dec 2004
Advertisement

Disable Ads
Default Realistic Password Advice Please

All the talk on password security. I know the advice, unique, complicated passwords with numbers and letters. I'm posing a REALISTIC and serious question here. How can this possibly be maintained? I've listed below the stuff I logged into yesterday through my history (yes literally). It topped out at 30. I mean honestly, it's just not possible to come up with and use a unique password every single time to be as secure as everyone says.

I can see combining things such as all email with a single password. All forums??? Maybe, maybe not. (Admin's on Guru force a new password every 90 days so that's not a concern). I mean every game you play with a unique password? C'mon. Bank/financial stuff you don't mess around with so that's all seperate and completley unique including email associated with it. Then there's some work stuff that I don't have a choice but is assigned a password that you also have to keep track of.

You can't save your passwords in file, that's too easy to grab by someone. I know there is software out there to help keep track of all your passwords but I hesitate considering earlier this year I fried a hard drive that all data was unrecoverable. So what is there? Sheet of paper, yeah right. What's the best method? Now people are one upping that with a unique email address you should ALSO have with certain accounts. It's a bit ridiculous.

Looking for realistic answer's here.

twitter
fb
gw1g
gw2g
gmail
gmail
yahoo email
yahoo email
ncsoft
bank
bank
utility
forum
forum
forum
forum
forum
forum
forum
forum admin
forum admin
site admin
site admin
site admin
IRC
IM
game
game
game
blog
Inde is offline   Reply With Quote
Old Nov 05, 2009, 04:00 PM // 16:00   #2
Hell's Protector
 
Quaker's Avatar
 
Join Date: Aug 2005
Location: Canada
Guild: Brothers Disgruntled
Default

Personally, I do use a couple of main passwords for unimportant stuff, and unique passwords for important things (like banking).
Since no one, outside of my own family, has access to my computer (or home), I write down the unique passwords in a small notebook. (Which I could lock in a drawer, but don't.)
I use Windows and/or Firefox's ability to "remember" passwords to simplify the process - some important unique passwords are not "remembered" though.

Just keep in mind to try to keep passwords either very unique, like "aSpo67&LLm" or else, make sure they are something that you would know, but casual acquaintances wouldn't guess. For example, your mother's maiden name plus her birthday date.

And, of course, keep your virus/spyware checkers active to catch keyloggers.

Last edited by Quaker; Nov 05, 2009 at 04:10 PM // 16:10..
Quaker is offline   Reply With Quote
Old Nov 05, 2009, 04:01 PM // 16:01   #3
The Fallen One
 
Lord Sojar's Avatar
 
Join Date: Dec 2005
Location: Oblivion
Guild: Irrelevant
Profession: Mo/Me
Default

Personally, I use a sheet of paper. I update my main passwords every 10 days, and change the main piece of paper every 10 days as well.

As for other non important passwords, I usually make one solid password and stick with that. I keep those on a permanent paper for reference.

I store unimportant passwords using Firefox's password manager as well.

It is a lot of work, but honestly, to be safe these days, you have to put some effort in. Too many people forget that, and just don't do what they need to do to be safe online.

If you make a habit, and keep telling yourself a mantra (like, "I need to do this to be safe") you might find after a short while of doing it every however many days, that it isn't a chore, and just a motion you start going through.
__________________
Lord Sojar is offline   Reply With Quote
Old Nov 05, 2009, 04:02 PM // 16:02   #4
Site Contributor
 
Join Date: Dec 2004
Default

I guess one of my points is, I don't think anyone is ever rock solid truly secure. Or they only go to a few internet sites a day I guess.

I'm at the point where things are getting more complicated and am really looking for a way to manage all the different passwords that are needed. So maybe I just need to see what some of you all are doing to maintain your security.
Inde is offline   Reply With Quote
Old Nov 05, 2009, 05:59 PM // 17:59   #5
Academy Page
 
nagisaki's Avatar
 
Join Date: Nov 2006
Location: The Interblag
Guild: Game Time [GT]
Profession: N/Me
Default

For my super complicated passwords I can't remember that well, I have a little text file hidden and encrypted on a flash drive I only plug in when needed. Sure, not the best solution, but if there's a keylogger or clipboard monitoring malware on the machine no matter what option you use is going to fail if you don't detect it soon enough.
nagisaki is offline   Reply With Quote
Old Nov 05, 2009, 06:56 PM // 18:56   #6
Lion's Arch Merchant
 
sosycpsycho's Avatar
 
Join Date: May 2008
Location: Atlanta
Guild: Krazy Guild With Krazy People[KrZy]
Default Got any needles?

Quote:
Originally Posted by nagisaki View Post
For my super complicated passwords I can't remember that well, I have a little text file hidden and encrypted on a flash drive .
Right next to the Sword of a Thousand Truths. His super complicated passwords
also cause 120 DPS with instant mana burn and give an enchant of +80 stamina.

I find the answer to protecting my Passwords is Haitian Voodoo.

I agree with the idea of having 3 different passwords and using them on different things, a short one for non crucial stuff, one that's like your b-day or something for personal but non vital stuff, then make one super long letters and numbers one for things like guild wars or secure logins.

Last edited by sosycpsycho; Nov 05, 2009 at 07:01 PM // 19:01..
sosycpsycho is offline   Reply With Quote
Old Nov 05, 2009, 08:54 PM // 20:54   #7
Ascalonian Squire
 
Sagra's Avatar
 
Join Date: Jun 2009
Location: SC
Guild: Passionate Kiss of the Dragons [KISS]
Profession: N/
Default

Haitian voodoo, as if there's any other kind? :P

I use a system where random things that get said that day or days ago get mashed into phrases only I can know. And keeping track in a secure spot on paper is the best solution. Partner that with frequent virus scans of your system and do all your Windows updates, you should be pretty safe.

Updating frequently is a major thing to do, and if you rely on Firefox to auto-fill, you might get lax and not do it as often as you should. Plus, if you lose your HD, you're boned.

I think most of the cracking that happens is because of 2 things: people using stupid-easy passwords (like: password) or giving their information to someone else for whatever reason. Somehow I think that the people who can invade your privacy would be after the big fish, and not necessarily concerned with us little guys.
Sagra is offline   Reply With Quote
Old Nov 05, 2009, 09:24 PM // 21:24   #8
Lion's Arch Merchant
 
Join Date: Dec 2007
Profession: P/Me
Default

i have a sheet of notebook paper next to my computer with info and stuff, not like people can see that over your computer
Evil Eye is offline   Reply With Quote
Old Nov 05, 2009, 09:26 PM // 21:26   #9
Desert Nomad
 
own age myname's Avatar
 
Join Date: Sep 2007
Location: Minnesota
Guild: [TAS]
Profession: R/
Default

I have a laminated sheet under my keyboard with a bunch of my passwords. I don't have very important stuff (as of yet, only game and email. I'm a minor, so no bank account yet). I also have a notepad with basic codes like my internet connection password.
own age myname is offline   Reply With Quote
Old Nov 05, 2009, 10:01 PM // 22:01   #10
Academy Page
 
Join Date: Jun 2005
Default

in many computer science departments, we allow students to log on for that quarter. we choose their username, but they choose their password. which creates huge security problems. as such, the recommendation is choosing the first letter in a phrase that makes sense to you. our examples are:

sewage workers: do not chew your fingernails!
password: sw:dncyf!

ex-girlfriends - one less bitch to slap
password: xgf-1lb2s

so my username of 'squirrel' could have a catchphrase '1 more tree to climb' and my password would be '1mt2c'. for your games, at least, base it on your character:
username: i pwn
passphrase: time to kick ass and chew bubble gum, i'm out of bubblegum
password: t2kaacbg,ioob
squiros is offline   Reply With Quote
Old Nov 05, 2009, 10:55 PM // 22:55   #11
Pre-Searing Cadet
 
Join Date: Feb 2007
Location: North Dakota
Guild: Unaffiliated
Profession: R/
Default

Use a password manager. That way you only have to remember one. I use keepass. It has a password generator so you can easily make a random password as well as store them.
Askani is offline   Reply With Quote
Old Nov 05, 2009, 10:59 PM // 22:59   #12
Age
Hall Hero
 
Age's Avatar
 
Join Date: Jul 2005
Location: California Canada/BC
Guild: STG Administrator
Profession: Mo/
Default

I just use a couple of simple ones for forums and stuff like that.I clear out my browser everytime I exit it and when I do my banking I clear out my cache.I don't have them written down anywhere.This is why I need ot use the pw recovery in NCSoft site for my master account.I don't use that much so I forget it.
Age is offline   Reply With Quote
Old Nov 05, 2009, 11:05 PM // 23:05   #13
Dre
Krytan Explorer
 
Join Date: Nov 2007
Location: Belgium
Guild: Dutch Doom Brigade
Profession: W/
Default

To create an easy and secure password, just take a random word and apply leetspeek to it
i.e. guildwars ==> gui1dw4r5 or gu11dw4r5 if you want to change both 'i' and 'l' to numbers
Just look up a random word in a dictionary (try to take a word of moderate length)
Dre is offline   Reply With Quote
Old Nov 05, 2009, 11:33 PM // 23:33   #14
Academy Page
 
Join Date: Mar 2009
Guild: Dominion Of The Shattered Sun [Sun]
Profession: Rt/
Default

Quote:
Originally Posted by squiros View Post
in many computer science departments, we allow students to log on for that quarter. we choose their username, but they choose their password. which creates huge security problems. as such, the recommendation is choosing the first letter in a phrase that makes sense to you. our examples are:

sewage workers: do not chew your fingernails!
password: sw:dncyf!

ex-girlfriends - one less bitch to slap
password: xgf-1lb2s

so my username of 'squirrel' could have a catchphrase '1 more tree to climb' and my password would be '1mt2c'. for your games, at least, base it on your character:
username: i pwn
passphrase: time to kick ass and chew bubble gum, i'm out of bubblegum
password: t2kaacbg,ioob


I kind of like that one.

Also,

http://googleblog.blogspot.com/2009/...g-list-of.html

Last edited by Kitor; Nov 05, 2009 at 11:35 PM // 23:35..
Kitor is offline   Reply With Quote
Old Nov 06, 2009, 12:49 AM // 00:49   #15
Frost Gate Guardian
 
Join Date: Jan 2007
Default

I categorize accounts by importance, and choose a password and e-mail based on that. Then I use modular passwords. For example:

Pick a few things: 1abc234 (license plate), eggrolls (word), 56789-0123 (zip code), etc.
Decorate them, e.g. EGGro11s
Make combinations, e.g. 1abc234EGGro11s
Decorate the combination: 1abc234O_OEGGro11s

Then I just use variations on the theme as my passwords. It's easy enough for me to remember, since only important accounts have unique passwords. Even then, there are some exceptions. Sometimes I use the same password, but instead use different account names.
eggrolls is offline   Reply With Quote
Old Nov 06, 2009, 10:40 AM // 10:40   #16
Desert Nomad
 
Join Date: Apr 2007
Default

Quote:
Originally Posted by Dre View Post
To create an easy and secure password, just take a random word and apply leetspeek to it
i.e. guildwars ==> gui1dw4r5 or gu11dw4r5 if you want to change both 'i' and 'l' to numbers
Just look up a random word in a dictionary (try to take a word of moderate length)
This is worthless. Anyone trying to guess your password will also use these common substitutions. And using words that appear in any dictionary - even klingon - makes automated brute force attacks much easier.

Quote:
Originally Posted by squiros View Post
in many computer science departments, we allow students to log on for that quarter. we choose their username, but they choose their password. which creates huge security problems. as such, the recommendation is choosing the first letter in a phrase that makes sense to you. our examples are:

sewage workers: do not chew your fingernails!
password: sw:dncyf!

ex-girlfriends - one less bitch to slap
password: xgf-1lb2s

so my username of 'squirrel' could have a catchphrase '1 more tree to climb' and my password would be '1mt2c'. for your games, at least, base it on your character:
username: i pwn
passphrase: time to kick ass and chew bubble gum, i'm out of bubblegum
password: t2kaacbg,ioob
I use a passphrase approach similar to squiros, but I use at least two phrases or obscure song lyrics that are completely unrelated, and join them together. I also use symbols and weird substitutions of my own (not stuff like i = 1). This produces password strings that look random, but are easy for me to remember.

Quote:
Originally Posted by Inde View Post
considering earlier this year I fried a hard drive that all data was unrecoverable.
All computers die, and all your data dies with it. It's only a question of how long before it happens. If you have anything on your computer, that you value, can't replace, can't afford to lose... you MUST make backups. With a little planning, this doesn't have to be a difficult or onerous task.

If you really have so many passwords that they are becoming unmanageable, perhaps you could put them in all in a file/spreadsheet... and then put that file in a strongly encrypted container (eg. Truecrypt). Make a single "master" password for that container, that is fully monstrous, and burn it into your memory such that you will remember it for all time.

Last edited by Riot Narita; Nov 06, 2009 at 10:59 AM // 10:59..
Riot Narita is offline   Reply With Quote
Old Nov 06, 2009, 12:07 PM // 12:07   #17
Banned
 
Join Date: Apr 2009
Default

Sheet of paper in your wallet.

p.s. hi it's captain arne
M1EK is offline   Reply With Quote
Old Nov 06, 2009, 12:19 PM // 12:19   #18
Forge Runner
 
Aera's Avatar
 
Join Date: Dec 2005
Guild: Galactic President Superstar Mc [awsm]
Profession: E/
Default

Just take your favourite song and replace it with some leetspeak like Dre said. The brain works by associations when it comes to remembering, so if you associate a song with a website it's not hard to remember. All you have to do is replace some letters with numbers.

For exaple, GWGuru reminds me of Trancequility ( some 1.5h mix by some DJ ) which then becomes Tr4ncequ1l!ty

Not hard to remember, but very very hard to guess.
Aera is offline   Reply With Quote
Old Dec 02, 2009, 01:14 PM // 13:14   #19
Site Contributor
 
bsoltan's Avatar
 
Join Date: Dec 2005
Location: UK
Guild: [SoF]
Default

First of all my apologies for posting in a 1 month old thread.

Quote:
Originally Posted by Askani View Post
Use a password manager. That way you only have to remember one. I use keepass. It has a password generator so you can easily make a random password as well as store them.
I would like to recommend KeePass as well.

http://keepass.info/

A few years ago I realised that I would be more secure if I used different passwords for everything, this wasn't due to any sort of breach of security or anything. I just realised that using two different passwords for everything wasn't very secure.

I think it was actually someone from GW, possibly Dralspire who I first saw recommending this particular software.

Since I started using it I have generated unique passwords for everything I use and not only does it make it easy for that respect, and it's ability to store the passwords and encrypt it's database but you can copy and paste out of the software to prevent being vunerable to keyloggers when typing passwords.

I also use the PortableApps (http://portableapps.com/) on my USB Flash Drive, and my copy of KeePass is the portable version to run from USB. This way I can take it anywhere and use it on any machine that has USB ports.

I would recommend it to anyone, I haven't had any problems since I started using it and don't forsee any problems in the future. There are also a lot of functions in there that I don't use but for keeping, generating and using passwords it works really well.

Hope it helps.
bsoltan is offline   Reply With Quote
Old Dec 02, 2009, 03:58 PM // 15:58   #20
Furnace Stoker
 
Elder III's Avatar
 
Join Date: Jan 2007
Location: Ohio
Guild: I Will Never Join Your Guild (NTY)
Profession: R/
Default

If an elite team of hackers wants to take the time to break your password etc... it's just about 100% for sure that it will happen - it's just a matter of how much time do they want to spend on it, and for almost everyone on these forums, it's not worth it. I know for sure that there's nothing on any of my computers that would be tempting to anyone, and I suspect most of you are the same.

Common sense when on the intrawebz will protect you more than 30 different passwords. Obviously it's important to have good passwords, but I don't believe it's at all necessary to have a different one for everything you ever need to loggin for. I use several different ones and it's not at all hard to remember that many. Keep them in your head and you know they're safe.
Elder III is offline   Reply With Quote
Reply

Share This Forum!  
 
 
           

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 04:53 AM // 04:53.


Powered by: vBulletin
Copyright ©2000 - 2016, Jelsoft Enterprises Ltd.
jQuery(document).ready(checkAds()); function checkAds(){if (document.getElementById('adsense')!=undefined){document.write("_gaq.push(['_trackEvent', 'Adblock', 'Unblocked', 'false',,true]);");}else{document.write("