Skip to main content

Creating an invincible password

You think you have a clever password, eh? Well, sorry, guest123 just ain't gonna cut it anymore. Hackers* can crack your English-word-plus-number based password in a matter of hours. With much of our lives moving online, through email, Facebook, online photo albums, banking, etc, Farhad Manjoo's tips on creating invincible passwords is well worth reading. His tips basically boil down to to following two steps:

Start with an original but memorable phrase. For this exercise, let's use these two sentences: I like to eat bagels at the airport and My first Cadillac was a real lemon so I bought a Toyota. The phrase can have something to do with your life or it can be a random collection of words—just make sure it's something you can remember. That's the key: Because a mnemonic is easy to remember, you don't have to write it down anywhere. (If you can't remember it without writing it down, it's not a good mnemonic.) This reduces the chance that someone will guess it if he gets into your computer or your e-mail. What's more, a relatively simple mnemonic can be turned into a fanatically difficult password.

Which brings us to Step 2: Turn your phrase into an acronym. Be sure to use some numbers and symbols and capital letters, too. I like to eat bagels at the airport becomes Ilteb@ta, and My first Cadillac was a real lemon so I bought a Toyota is M1stCwarlsIbaT.

I used to use a single password for everything, from banking to my Unix account at work. It's a miracle I never had a break-in. I now use several passwords, all completely scrambled based on the formula above. Now you, like me, have no excuse not to keep your online life securely locked up!

*Yes, I know that a cracker .NE. haX0r, but most people think "cracker" means something else, entirely.


blissful_e said…
I use LastPass. That way, I only have to remember one password (and I use the type you describe) but LastPass generates gobbledegook passwords for all my other accounts (email, bank, forums, etc). I don't think LastPass would work for a UNIX account, but I highly recommend it for everything else.
Marshall said…
I've recently jumped on the 1Password bandwagon, and so far I really like it. It integrates very nicely into Safari, so you just have to remember your one master password and it autofills any web page with the appropriate password for that site. And it does let you store arbitrary secure information of any sort, not just web page passwords, so it's good for encrypting unix account login info or medical record numbers or insurance information, etc.

The best part is that it works perfectly with Dropbox for synchronization between machines. Any accounts logged into on my laptop propagate the login info securely to my desktop, and vice versa.

Popular posts from this blog

On the Height of J.J. Barea

Dallas Mavericks point guard J.J. Barea standing between two very tall people (from: Picassa user photoasisphoto).

Congrats to the Dallas Mavericks, who beat the Miami Heat tonight in game six to win the NBA championship.

Okay, with that out of the way, just how tall is the busy-footed Maverick point guard J.J. Barea? He's listed as 6-foot on, but no one, not even the sports casters, believes that he can possibly be that tall. He looks like a super-fast Hobbit out there. But could that just be relative scaling, with him standing next to a bunch of extremely tall people? People on Yahoo! Answers think so---I know because I've been Google searching "J.J. Barea Height" for the past 15 minutes.

So I decided to find a photo and settle the issue once and for all.

I started by downloading a stock photo of J.J. from, which I then loaded into OpenOffice Draw:

I then used the basketball as my metric. Wikipedia states that an NBA basketball is 29.5 inches in circumfe…

The Long Con

Hiding in Plain Sight

ESPN has a series of sports documentaries called 30 For 30. One of my favorites is called Broke which is about how professional athletes often make tens of millions of dollars in their careers yet retire with nothing. One of the major "leaks" turns out to be con artists, who lure athletes into elaborate real estate schemes or business ventures. This naturally raises the question: In a tightly-knit social structure that is a sports team, how can con artists operate so effectively and extensively? The answer is quite simple: very few people taken in by con artists ever tell anyone what happened. Thus, con artists can operate out in the open with little fear of consequences because they are shielded by the collective silence of their victims.
I can empathize with this. I've lost money in two different con schemes. One was when I was in college, and I received a phone call that I had won an all-expenses-paid trip to the Bahamas. All I needed to do was p…

The GRE: A test that fails

Every Fall seniors in the US take the Graduate Records Examination (GRE), and their scores are submitted along with their applications to grad school. Many professors, particularly those in physics departments, believe that the GRE is an important predictor of future success in grad school, and as a result many admissions committees employ score cutoffs in the early stages of their selection process. However, past and recent studies have shown that there is little correlation between GRE scores and future graduate school success.
The most recent study of this type was recently published in Nature Jobs. The authors, Casey Miller and Keivan Stassun show there are strong correlations between GRE scores and race/gender, with minorities and (US) white women scoring lower than their white male (US) counterparts. They conclude, "In simple terms, the GRE is a better indicator of sex and skin colour than of ability and ultimate success."
Here's the key figure from their article: