Install the app
How to install the app on iOS

Follow along with the video below to see how to install our site as a web app on your home screen.

Note: This feature may not be available in some browsers.

Think Your Password Is Secure from the NSA? Try This

Katzenfreund

The Oracle
V I P
Joined
Jun 1, 2013
Messages
2,456
Reaction score
394
Points
113
Loc
Europe
Password Security

A comment from a typical user: “What I thought was my most secure password that would take months to crack... Seven minutes!

That’s how long it would take to crack one of the passwords I had been using for more than ten years, according to the crypto experts at Silent Circle. ”

Let’s be honest. A lot of people use the same password over and over again across multiple websites, like email, bank accounts, and social media.

Sometimes these passwords can be a bit elementary. The dog’s name. Daughter’s birthday. A favorite chocolate syrup. These types of passwords won’t typically thwart government agencies that are keen to spy on their citizens. They can easily be cracked in a matter of minutes.

You may be using eight or ten different passwords for several years, always thinking they were secure– letters and numbers.

Well, you may be surprised! It may well turn out that the passwords aren’t so secure after all. You can try it for yourself here:

(You don’t have to sign up; you can just type in a password and see for yourself…)
Code:
https://accounts.silentcircle.com/join/

Modern Password Cracking Algorithms

Most password cracking algorithms have adapted, particularly as a lot of people use ‘dictionary’ words in their passwords.

For example, instead of “sunshine”, one may use “5unshinE!”, substituting a 5 for the s, capitalizing the E, and adding an exclamation mark.

The first password, “sunshine”, is considered to be highly vulnerable based on industry convention, but “5unshinE!” is considered to be much more secure.

It turns out that both passwords can be cracked by modern algorithms almost instantly. Neither is secure.

Since cracking algorithms succeed by picking up patterns in human behavior, the key to a secure password is randomness and disorder. In the security business, this is known as entropy.

It’s difficult for a human being to fake randomness and disorder. So one easy way to achieve this is to use a password generator tool that incorporates entropy.

Try, for example, going to
Code:
https://entima.net/random/

On this website, you move your mouse around randomly, and the website’s software incorporates these random mouse movements into its password generation code.

The passwords that it generates are far more secure, taking centuries to crack instead of mere seconds.

It may be a good idea to take a few minutes out of your life to check your own password vulnerability, and come up with an alternative that’s far more secure.
 
:hmmm: :D Nice...mine take an average of 11 minutes :( even if they aren't related to me or my personal life
 
Time to crack: centuries

I always use very complicated passwords and different ones at different places.
 
This is an example of the kind of passwords I use - a different one on every site. I keep a list next to my keyboard (no one else ever uses my computer).

Example password: AS12$%;lk<?87Tbx
Time to crack: centuries
 
Wow my password took 14 minutes.
The Mrs's took 4 hours.

I'll have to look into changing that sort of behaviour.
 
Mine took 33 minutes - but I am not worried a bit. While it is true that software exists that can "crack" a password, its done by trying every combination of letters and numbers, which I believe is called a Brute Force attack. - now how many banking sites or even forums would allow a hacker to do that? answer: none of them. They all have a set limit on the number of "tries" a person gets.

But to be on the safe side, I use a long letter-number combination for any "important" password - my main email address, ebay, any forum I have mod privileges on, amazon - but for my banking website i use a totally separate password. but banking is pretty safe I think, if you try and log onto my bank from a PC it don't recognize, u gotta answer 2 security questions.
 
they'd be busy for atleast 8 months with one of mine :p
 
A password I was using till a couple of years ago would be cracked instantly. So it's a good job I changed it, because the new one will take a whole minute! :P
 
I use Mask Me to disguise passwords and create strong passwords.
Nothing came up at all but that doesn't mean that it cannot be cracked.
And by the way..NSA would be able to crack even the hardest of passwords Brute Force is childs play.

According to Edward Snowden the informant (whistleblower) on the run from the CIA/NSA and apparently stuck in a Russian airport,
if the National Security Agency at Fort Meade in Maryland 'Crypto City' uses it technology then you can guarantee that a password would be simple to crack.
'Project Prism' is the codename...it collects data from Google, Microsoft, Apple and quite a few other software manufacturers to spy on the contents of your hard drive.


Crypto city employs at least 30, 000 agents operating at a worldwide level that appears to be above the law of most countries, it has been claimed that it is currently the most powerful organisation in the world.
James Clapper is more powerful than President Obama and since 2010 he has managed 16 US Intelligence Agencies and their 850,000 employees and was the mastermind behind the take down of Osama Bin Laden.
 
Using a sample password phrase: To be or not to be, that is the question = 2b0ntb,titq = centuries (without the comma it is 3 years).
 
I dont think these test are really true,
any way here its mine.

8vq6x4.png
 
US and UK spy agencies defeat internet privacy and security

• A 10-year NSA program against encryption technologies made a breakthrough in 2010 which made "vast amounts" of data collected through internet cable taps newly "exploitable".
• NSA and GCHQ unlock encryption used to protect emails, banking and medical records

But they don’t stop at just cracking passwords…
• $250m-a-year US program works covertly with tech companies to insert weaknesses into products

Code:
http://www.theguardian.com/world/2013/sep/05/nsa-gchq-encryption-codes-security

8DZhZB9.jpg
 
...unless, of course, that website was set up by the nsa to capture passwords and now they just added your passwords to their list. :D
 
Katzenfreund said:
US and UK spy agencies defeat internet privacy and security

• A 10-year NSA program against encryption technologies made a breakthrough in 2010 which made "vast amounts" of data collected through internet cable taps newly "exploitable".
• NSA and GCHQ unlock encryption used to protect emails, banking and medical records

But they don’t stop at just cracking passwords…
• $250m-a-year US program works covertly with tech companies to insert weaknesses into products

Code:
http://www.theguardian.com/world/2013/sep/05/nsa-gchq-encryption-codes-security

8DZhZB9.jpg


As I posted a page back Katz:

'Project Prism' is the codename...it collects data from Google, Microsoft, Apple and quite a few other software manufacturers to spy on the contents of your hard drive.

Code:
http://www.theguardian.com/world/2013/jun/06/us-tech-giants-nsa-data
 
Back
Top