Home > Security Tips > > Creating secure passwords you don't have to remember
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 


Creating secure passwords you don't have to remember


Serdar Yegulalp, Contributor
03.22.2006
Rating: -3.00- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Are passwords doomed? The unanimous lament among security experts is how most people don't use strong passwords. They either use personally identifiable information or else horribly weak passwords that won't survive a dictionary attack. Furthermore, Microsoft is talking about allowing people to almost entirely do away with passwords in Internet Explorer 7.

It's a Catch-22 situation: People rarely use strong passwords because they are impossible to remember, and yet they've been told time and again never to write them down, which only makes them harder to memorize.

There's got to be a better way, you say. Well, to a degree, there already is. Programmer Chris Zarate has created an online password generator application that functions in a way I've never seen before. It actually works with a user's bad memory rather than against it.

The premise is simple. You supply a single master password -- it doesn't matter what it is, and it doesn't have to be secure -- and the application generates a bookmarklet that takes the domain name of the site you're visiting and creates a password to use in that domain by hashing it against your master password. The bookmarklet is not a program; it's simply a bookmark that, when selected, pops up a text window (via JavaScript) that contains the password to use for that domain.

Bookmarklets can be generated for Firefox and IE and are created via the secure MD5 algorithm, which makes them impossible to reverse-engineer. No information of any kind is transmitted to an outside server to create the bookmarklet or generate the password. You can also create a bookmarklet with the master password hard-coded into it (if you're reasonably certain you'll be the only one accessing the computer) or one that prompts you for the master password each time. The script can even automatically populate password fields in the current page as needed.

This is a creative and powerful solution to a problem that isn't going to go away soon.

Serdar Yegulalp is editor of the Windows Power Users Newsletter. Check it out for the latest advice and musings on the world of Windows network administrators -- and please share your thoughts as well!

This tip originally appeared on SearchWinSystems.com.

Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Enterprise User Provisioning Tools,   Enterprise Identity and Access Management,   Identity Management Technology and Strategy,   Password Management and Policy,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Enterprise User Provisioning Tools
Quiz: Compliance-driven role management
Identity lifecycle management for security and compliance
Content-aware IAM: Uniting user access and data rights
Is Identity Management as a Service (IDaaS) a good idea?
Top tactics for endpoint security
How to edit group policy objects to give a user local admin rights
Privileged account management critical to data security
Making the case for enterprise IAM centralized access control
Lesson 3: How to implement secure access
Best practices for a privileged access policy to secure user accounts

Password Management and Policy
Two-factor authentication, vigilance foil password theft
Group to shed light on secure identity management threats
Brute force attacks target Yahoo email accounts
Best Identity and Access Management Products
Privileged account management critical to data security
Making the case for enterprise IAM centralized access control
How to prevent brute force webmail attacks
Best practices for a privileged access policy to secure user accounts
Mature SIMs do more than log aggregation and correlation
PCI compliance requirement 2: Defaults

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
AAA server  (SearchSecurity.com)
authentication, authorization, and accounting  (SearchSecurity.com)
federated identity management  (SearchSecurity.com)
logon  (SearchSecurity.com)
onboarding and offboarding  (SearchSecurity.com)
password synchronization  (SearchSecurity.com)
RADIUS  (SearchSecurity.com)
role mining  (SearchSecurity.com)
role-based access control (RBAC)  (SearchSecurity.com)
user profile  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts