Re: OT:Password strength

2014-12-04 Thread Craig Skinner
On 2014-12-03 Wed 15:04 PM |, Ted Unangst wrote: If you want strong, short passwords that look ridiculous: dd if=/dev/random bs=1 count=9 | b64encode password $ pkg_info apg Information for inst:apg-2.2.3p0 Comment: automated password generator Description: APG (Automated Password

Re: OT:Password strength

2014-12-03 Thread Tor Houghton
On Sun, Nov 30, 2014 at 04:21:50PM -0500, Ted Unangst wrote: On Sun, Nov 30, 2014 at 15:37, thornton.rich...@gmail.com wrote: Where do you store these passwords? On a napkin? Wherever you like. A shorter password with all the o's turned into 0's is hardly more secure. I'd say on a napkin

Re: OT:Password strength

2014-12-03 Thread Brad Smith
On 11/30/14 15:20, Ted Unangst wrote: Examples: treetykaveprethicooputhedu soonataviceenoopatecoge gootrozapiceelytrithunula preezypeendothanundipeesooka That defeats the purpose of the second example in the OPs question. -- This message has been scanned for viruses and dangerous content by

Re: OT:Password strength

2014-12-03 Thread Ted Unangst
On Wed, Dec 03, 2014 at 08:27, Brad Smith wrote: On 11/30/14 15:20, Ted Unangst wrote: Examples: treetykaveprethicooputhedu soonataviceenoopatecoge gootrozapiceelytrithunula preezypeendothanundipeesooka That defeats the purpose of the second example in the OPs question. If you want

Re: OT:Password strength

2014-12-03 Thread Jason Adams
On 12/03/2014 12:04 PM, Ted Unangst wrote: On Wed, Dec 03, 2014 at 08:27, Brad Smith wrote: On 11/30/14 15:20, Ted Unangst wrote: Examples: treetykaveprethicooputhedu soonataviceenoopatecoge gootrozapiceelytrithunula preezypeendothanundipeesooka That defeats the purpose of the second

Re: OT:Password strength

2014-12-03 Thread Alexander Hall
On December 3, 2014 9:10:42 PM CET, Jason Adams adams...@gmail.com wrote: On 12/03/2014 12:04 PM, Ted Unangst wrote: On Wed, Dec 03, 2014 at 08:27, Brad Smith wrote: On 11/30/14 15:20, Ted Unangst wrote: Examples: treetykaveprethicooputhedu soonataviceenoopatecoge gootrozapiceelytrithunula

Re: [Bulk] Re: OT:Password strength

2014-12-03 Thread Kevin Chadwick
On Wed, 03 Dec 2014 22:53:22 +0100 Alexander Hall wrote: If you want strong, short passwords that look ridiculous: dd if=/dev/random bs=1 count=9 | b64encode password And then try to remember that mess, or type it, especially into a smartphone. Gaak! 8-O base64 ain't that bad,

Re: OT:Password strength

2014-12-03 Thread Brad Smith
On 12/03/14 15:04, Ted Unangst wrote: On Wed, Dec 03, 2014 at 08:27, Brad Smith wrote: On 11/30/14 15:20, Ted Unangst wrote: Examples: treetykaveprethicooputhedu soonataviceenoopatecoge gootrozapiceelytrithunula preezypeendothanundipeesooka That defeats the purpose of the second example in

Re: OT:Password strength

2014-12-03 Thread Eric Furman
On Wed, Dec 3, 2014, at 08:27 AM, Brad Smith wrote: On 11/30/14 15:20, Ted Unangst wrote: Examples: treetykaveprethicooputhedu soonataviceenoopatecoge gootrozapiceelytrithunula preezypeendothanundipeesooka That defeats the purpose of the second example in the OPs question. I think

Re: OT:Password strength

2014-12-03 Thread Theo de Raadt
: 1.0 Content-Transfer-Encoding: 8bit Content-Type: text/plain X-Mailer: MessagingEngine.com Webmail Interface - html Subject: Re: OT:Password strength Date: Wed, 03 Dec 2014 22:36:17 -0500 In-Reply-To: 547f0fb8.6070...@comstyle.com References: 1417316824.2046833.196840165.39fa2

Re: OT:Password strength

2014-11-30 Thread Ted Unangst
On Sat, Nov 29, 2014 at 22:07, Eric Furman wrote: OFF TOPIC. This has nothing to do with OpenBSD, but a lot of guys here know about this stuff. I've done some reading, but still not sure. OK, at the risk of looking stupid,which of these passwords is better; kMH65?3 or

Re: OT:Password strength

2014-11-30 Thread Miod Vallat
Examples: treetykaveprethicooputhedu soonataviceenoopatecoge gootrozapiceelytrithunula preezypeendothanundipeesooka These stand no chance against a finnish attacker! Miod

Re: OT:Password strength

2014-11-30 Thread thornton . richard
Where do you store these passwords? On a napkin?   Original Message   From: Ted Unangst Sent: Sunday, November 30, 2014 3:21 PM To: Eric Furman Cc: OpenBSD Misc Subject: Re: OT:Password strength On Sat, Nov 29, 2014 at 22:07, Eric Furman wrote: OFF TOPIC. This has nothing to do with OpenBSD

Re: OT:Password strength

2014-11-30 Thread Ted Unangst
On Sun, Nov 30, 2014 at 15:37, thornton.rich...@gmail.com wrote: Where do you store these passwords? On a napkin? Wherever you like. A shorter password with all the o's turned into 0's is hardly more secure.

Re: OT:Password strength

2014-11-30 Thread thornton . richard
way to create a password which is ok, and easy to remember.   Original Message   From: Ted Unangst Sent: Sunday, November 30, 2014 4:21 PM To: thornton.rich...@gmail.com Cc: Eric Furman; OpenBSD Misc Subject: Re: OT:Password strength On Sun, Nov 30, 2014 at 15:37, thornton.rich...@gmail.com

Re: OT:Password strength

2014-11-30 Thread Eric Furman
On Sun, Nov 30, 2014, at 05:02 PM, thornton.rich...@gmail.com wrote: I get why network admins and CIO types live and breath security and hardened passwords, but the average user has gone mad. I like leading alpha characters in combination with an old phone number, with a few non-alpha‎

Re: OT:Password strength

2014-11-30 Thread Eric Furman
On Sun, Nov 30, 2014, at 03:20 PM, Ted Unangst wrote: On Sat, Nov 29, 2014 at 22:07, Eric Furman wrote: OFF TOPIC. This has nothing to do with OpenBSD, but a lot of guys here know about this stuff. I've done some reading, but still not sure. OK, at the risk of looking stupid,which of

Re: OT:Password strength

2014-11-30 Thread Eric Furman
On Sun, Nov 30, 2014, at 12:48 AM, Nick Holland wrote: On 11/29/14 22:06, Eric Furman wrote: OFF TOPIC. This has nothing to do with OpenBSD, but a lot of guys here know about this stuff. I've done some reading, but still not sure. OK, at the risk of looking stupid,which of these passwords

Re: OT:Password strength

2014-11-30 Thread davidson
On Sun, November 30, 2014 8:09 pm, Eric Furman wrote: On Sun, Nov 30, 2014, at 12:48 AM, Nick Holland wrote: lots snipped Then there is the system where it is stored. If you are working on a stock Solaris 9 or AIX system with the default settings, only the first eight chars are used, so the

Re: OT:Password strength

2014-11-30 Thread Dennis Davis
On Sun, 30 Nov 2014, Miod Vallat wrote: From: Miod Vallat m...@online.fr To: Ted Unangst t...@tedunangst.com Cc: Eric Furman ericfur...@fastmail.net, OpenBSD Misc misc@openbsd.org Date: Sun, 30 Nov 2014 20:34:01 Subject: Re: OT:Password strength Examples: treetykaveprethicooputhedu

Re: OT:Password strength

2014-11-30 Thread Darren Spruell
On Sun, Nov 30, 2014 at 7:00 PM, david...@ling.ohio-state.edu wrote: On Sun, November 30, 2014 8:09 pm, Eric Furman wrote: On Sun, Nov 30, 2014, at 12:48 AM, Nick Holland wrote: lots snipped Then there is the system where it is stored. If you are working on a stock Solaris 9 or AIX

OT:Password strength

2014-11-29 Thread Eric Furman
OFF TOPIC. This has nothing to do with OpenBSD, but a lot of guys here know about this stuff. I've done some reading, but still not sure. OK, at the risk of looking stupid,which of these passwords is better; kMH65?3 or mylittlelambjumpedovertenredbarns

Re: OT:Password strength

2014-11-29 Thread Brian Empson
The latter, I would bet. On 11/29/2014 10:07 PM, Eric Furman wrote: OFF TOPIC. This has nothing to do with OpenBSD, but a lot of guys here know about this stuff. I've done some reading, but still not sure. OK, at the risk of looking stupid,which of these passwords is better; kMH65?3 or

Re: OT:Password strength

2014-11-29 Thread bodie
On 30.11.2014 04:07, Eric Furman wrote: OFF TOPIC. This has nothing to do with OpenBSD, but a lot of guys here know about this stuff. I've done some reading, but still not sure. OK, at the risk of looking stupid,which of these passwords is better; kMH65?3 or mylittlelambjumpedovertenredbarns

Re: OT:Password strength

2014-11-29 Thread Nick Holland
On 11/29/14 22:06, Eric Furman wrote: OFF TOPIC. This has nothing to do with OpenBSD, but a lot of guys here know about this stuff. I've done some reading, but still not sure. OK, at the risk of looking stupid,which of these passwords is better; kMH65?3 or mylittlelambjumpedovertenredbarns

Re: OT:Password strength

2014-11-29 Thread bodie
On 30.11.2014 06:48, Nick Holland wrote: On 11/29/14 22:06, Eric Furman wrote: OFF TOPIC. This has nothing to do with OpenBSD, but a lot of guys here know about this stuff. I've done some reading, but still not sure. OK, at the risk of looking stupid,which of these passwords is better;