<?xml version="1.0" encoding="utf-8" ?>

<rss version="2.0" 
   xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
   xmlns:admin="http://webns.net/mvcb/"
   xmlns:dc="http://purl.org/dc/elements/1.1/"
   xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
   xmlns:wfw="http://wellformedweb.org/CommentAPI/"
   xmlns:content="http://purl.org/rss/1.0/modules/content/"
   >
<channel>
    <title>Village Elder - Comments</title>
    <link>http://www.village-elder.com/blog/</link>
    <description>Village Elder - Why do you seek the Village Elder?</description>
    <dc:language>en</dc:language>
    <generator>Serendipity 1.1 - http://www.s9y.org/</generator>
    <managingEditor>blog@village-elder.com</managingEditor>
<webMaster>blog@village-elder.com</webMaster>
<pubDate>Fri, 05 Sep 2008 19:57:51 GMT</pubDate>

    <image>
        <url>http://www.village-elder.com/john.village-elder.jpg</url>
        <title>RSS: Village Elder - Comments - Village Elder - Why do you seek the Village Elder?</title>
        <link>http://www.village-elder.com/blog/</link>
        <width>100</width>
        <height>109</height>
    </image>

<item>
    <title>John Curry: Great comments from Computer Defence</title>
    <link>http://www.village-elder.com/blog/archives/9-Great-comments-from-Computer-Defence.html#c10</link>
            <category></category>
    
    <comments>http://www.village-elder.com/blog/archives/9-Great-comments-from-Computer-Defence.html#comments</comments>
    <wfw:comment>http://www.village-elder.com/blog/wfwcomment.php?cid=9</wfw:comment>

    

    <author>john@village-elder.com (John Curry)</author>
    <content:encoded>
    Great Stats Igor!  Thanks for sharing!  
    </content:encoded>

    <pubDate>Tue, 13 Mar 2007 08:50:34 -0500</pubDate>
    <guid isPermaLink="false">http://www.village-elder.com/blog/archives/9-guid.html#c10</guid>
    
</item>
<item>
    <title>Igor Drokov: Great comments from Computer Defence</title>
    <link>http://www.village-elder.com/blog/archives/9-Great-comments-from-Computer-Defence.html#c9</link>
            <category></category>
    
    <comments>http://www.village-elder.com/blog/archives/9-Great-comments-from-Computer-Defence.html#comments</comments>
    <wfw:comment>http://www.village-elder.com/blog/wfwcomment.php?cid=9</wfw:comment>

    

    <author>john@village-elder.com (Igor Drokov)</author>
    <content:encoded>
    Talking about passprase-based passwords, there is a report published in 2000 on &quot;The memorability and security of&lt;br /&gt;
passwords  some empirical results&quot; based on the study of 400 first-year students at the University of Cambridge. The report provides some interesting data, e.g.:&lt;br /&gt;
&lt;br /&gt;
&quot;The summary of the number of cracked passwords is as follows (with brute-force attacks treated separately):&lt;br /&gt;
&lt;br /&gt;
- Control group 30 (32%) +3 brute force&lt;br /&gt;
- Random password group 8 (8%) +3 brute force&lt;br /&gt;
- Passphrase group 6 (6%) +3 brute force&lt;br /&gt;
- Comparison sample 33 (33%) +2 brute force&quot;&lt;br /&gt;
&lt;br /&gt;
Full report: http://www.cl.cam.ac.uk/techreports/UCAM-CL-TR-500.pdf  
    </content:encoded>

    <pubDate>Tue, 13 Mar 2007 08:37:28 -0500</pubDate>
    <guid isPermaLink="false">http://www.village-elder.com/blog/archives/9-guid.html#c9</guid>
    
</item>
<item>
    <title>John Curry - on behalf of Jordan: A realistic approach to creating very strong passwords</title>
    <link>http://www.village-elder.com/blog/archives/7-A-realistic-approach-to-creating-very-strong-passwords.html#c8</link>
            <category></category>
    
    <comments>http://www.village-elder.com/blog/archives/7-A-realistic-approach-to-creating-very-strong-passwords.html#comments</comments>
    <wfw:comment>http://www.village-elder.com/blog/wfwcomment.php?cid=7</wfw:comment>

    

    <author>john@village-elder.com (John Curry - on behalf of Jordan)</author>
    <content:encoded>
    The comment below was valiantly attempted to be posted here only to fail because I haven&#039;t worked out all my blogging mojo yet.  Jordan sent this in with another great link on password policy.  Thanks Jordan, I think I have this sorted now &lt;img src=&quot;http://www.village-elder.com/blog/templates/default/img/emoticons/smile.png&quot; alt=&quot;:-)&quot; style=&quot;display: inline; vertical-align: bottom;&quot; class=&quot;emoticon&quot; /&gt; -john&lt;br /&gt;
---&lt;br /&gt;
That&#039;s a great writeup.  We recommend something similar, though without &lt;br /&gt;
quite as much detail on our password page at the University of Florida:&lt;br /&gt;
&lt;br /&gt;
http://infosec.ufl.edu/athome/passwords.shtml&lt;br /&gt;
&lt;br /&gt;
Thanks for the explanation.  
    </content:encoded>

    <pubDate>Thu, 01 Mar 2007 17:50:18 -0600</pubDate>
    <guid isPermaLink="false">http://www.village-elder.com/blog/archives/7-guid.html#c8</guid>
    
</item>
<item>
    <title>Keri: To sudo or not to sudo</title>
    <link>http://www.village-elder.com/blog/archives/8-To-sudo-or-not-to-sudo.html#c7</link>
            <category></category>
    
    <comments>http://www.village-elder.com/blog/archives/8-To-sudo-or-not-to-sudo.html#comments</comments>
    <wfw:comment>http://www.village-elder.com/blog/wfwcomment.php?cid=8</wfw:comment>

    

    <author>john@village-elder.com (Keri)</author>
    <content:encoded>
    You know your sudo command always worked on me =) Miss you tons!  &lt;strong&gt;hugs&lt;/strong&gt;  
    </content:encoded>

    <pubDate>Thu, 01 Mar 2007 07:28:23 -0600</pubDate>
    <guid isPermaLink="false">http://www.village-elder.com/blog/archives/8-guid.html#c7</guid>
    
</item>
<item>
    <title>Ricky: To sudo or not to sudo</title>
    <link>http://www.village-elder.com/blog/archives/8-To-sudo-or-not-to-sudo.html#c6</link>
            <category></category>
    
    <comments>http://www.village-elder.com/blog/archives/8-To-sudo-or-not-to-sudo.html#comments</comments>
    <wfw:comment>http://www.village-elder.com/blog/wfwcomment.php?cid=8</wfw:comment>

    

    <author>john@village-elder.com (Ricky)</author>
    <content:encoded>
    I think, when properly applied, the sudo command can have a dramatic effect on lunch.  
    </content:encoded>

    <pubDate>Wed, 28 Feb 2007 10:19:07 -0600</pubDate>
    <guid isPermaLink="false">http://www.village-elder.com/blog/archives/8-guid.html#c6</guid>
    
</item>
<item>
    <title>John Curry: A realistic approach to creating very strong passwords</title>
    <link>http://www.village-elder.com/blog/archives/7-A-realistic-approach-to-creating-very-strong-passwords.html#c5</link>
            <category></category>
    
    <comments>http://www.village-elder.com/blog/archives/7-A-realistic-approach-to-creating-very-strong-passwords.html#comments</comments>
    <wfw:comment>http://www.village-elder.com/blog/wfwcomment.php?cid=7</wfw:comment>

    

    <author>john@village-elder.com (John Curry)</author>
    <content:encoded>
    Thats a good point Wilbur!  Perhaps it&#039;s too much to say this method will create &#039;very strong&#039; passwords.  I know that I have seen some pretty ugly passwords in the field.  Often terrible things like:&lt;br /&gt;
&lt;br /&gt;
baseb@ll&lt;br /&gt;
r1234&lt;br /&gt;
mypass&lt;br /&gt;
&lt;br /&gt;
Eeeks, keeps me up at night! I think compared to passwords of that level the technique I propose would fair pretty well.&lt;br /&gt;
&lt;br /&gt;
I certainly wouldn&#039;t suggest any of the standard 3l173or &#039;elite&#039; character replacements, they are just to common now, and I always feel dirty when I think about using them.&lt;br /&gt;
&lt;br /&gt;
If anyone can use this technique to beef up their passwords a few notches in the right direction, then I think my work is done.&lt;br /&gt;
&lt;br /&gt;
Perhaps I&#039;ll do a follow up post on how to create 64 character passwords for the non mensa member &lt;img src=&quot;http://www.village-elder.com/blog/templates/default/img/emoticons/smile.png&quot; alt=&quot;:-)&quot; style=&quot;display: inline; vertical-align: bottom;&quot; class=&quot;emoticon&quot; /&gt;&lt;br /&gt;
&lt;br /&gt;
That gives me another idea.  password olympics!  I think I&#039;ll see about setting up some cracking tools to test who&#039;s 8 character password hold out the longest.   hrm.. let me look into that!  
    </content:encoded>

    <pubDate>Wed, 28 Feb 2007 08:45:33 -0600</pubDate>
    <guid isPermaLink="false">http://www.village-elder.com/blog/archives/7-guid.html#c5</guid>
    
</item>
<item>
    <title>Wilbur: A realistic approach to creating very strong passwords</title>
    <link>http://www.village-elder.com/blog/archives/7-A-realistic-approach-to-creating-very-strong-passwords.html#c4</link>
            <category></category>
    
    <comments>http://www.village-elder.com/blog/archives/7-A-realistic-approach-to-creating-very-strong-passwords.html#comments</comments>
    <wfw:comment>http://www.village-elder.com/blog/wfwcomment.php?cid=7</wfw:comment>

    

    <author>john@village-elder.com (Wilbur)</author>
    <content:encoded>
    Have you performed any analysis of the passwords, perhaps with common phrases?   It&#039;s easy to suggest that they are strong but I think that there are a lot of letters that are not as commonly the first letter of a word in a phrase.  Some simple analysis could show the distribution.&lt;br /&gt;
&lt;br /&gt;
There are already password attackers that factor all the &quot;elite&quot; speak letters and numbers in,  they don&#039;t increase the distribution nearly as much as you might think.  
    </content:encoded>

    <pubDate>Wed, 28 Feb 2007 07:22:50 -0600</pubDate>
    <guid isPermaLink="false">http://www.village-elder.com/blog/archives/7-guid.html#c4</guid>
    
</item>
<item>
    <title>Brian: A realistic approach to creating very strong passwords</title>
    <link>http://www.village-elder.com/blog/archives/7-A-realistic-approach-to-creating-very-strong-passwords.html#c1</link>
            <category></category>
    
    <comments>http://www.village-elder.com/blog/archives/7-A-realistic-approach-to-creating-very-strong-passwords.html#comments</comments>
    <wfw:comment>http://www.village-elder.com/blog/wfwcomment.php?cid=7</wfw:comment>

    

    <author>john@village-elder.com (Brian)</author>
    <content:encoded>
    Check out &quot;rainbow table attacks&quot;, which have effectively made your 8-character password obsolete (save for in systems that salt their hashes, such as Unixes). Now I take the type of passwords you talk about, and string two together separated with punctuation.  Thus, I would use&lt;br /&gt;
What the f is your problem&lt;br /&gt;
(W7f1urPr0b)&lt;br /&gt;
with&lt;br /&gt;
This ain&#039;t my momma&#039;s cookin&#039;&lt;br /&gt;
(T8ntMm&#039;scKn)&lt;br /&gt;
and turn it into&lt;br /&gt;
W7f1urPr0b#T8ntMm&#039;scKn&lt;br /&gt;
&lt;br /&gt;
(hypothetically...)  
    </content:encoded>

    <pubDate>Wed, 21 Feb 2007 09:16:14 -0600</pubDate>
    <guid isPermaLink="false">http://www.village-elder.com/blog/archives/7-guid.html#c1</guid>
    
</item>

</channel>
</rss>