Dictionary attacks and brute force: Clever password protection

By Sebastian Knoppik
19:56, November 9th 2008
41 votes
Vote this story

Darmstadt - Hackers are always refining their methods of sniffing out other people's passwords. That's why experts advise that you always select tough-to-crack passwords. That means using different passwords for different web sites. Luckily, special programs are available to help you remember them all.

"There are two prime ways to steal users' passwords," explains Ruben Wolf from the Fraunhofer Institute for Secure Information Technology (SIT) in Darmstadt, Germany.

"Either the hacker tricks the user into revealing the password or the hackers test out various possibilities until they stumble upon the right one," says Daniel Bachfeld of the Hanover-based c't magazine. The first option is the current favourite among cyber criminals, he said.

Tricking the user into revealing the password is known as phishing. Phishers typically use forged e-mail messages to create the impression that the recipient is receiving correspondence from a trusted source - such as the user's bank. Clicking on a link embedded in the message leads to a counterfeit web site, at which point the user is then asked to enter personal data.

One glance at the browser's address bar is often enough to show when a site is bogus. Most sites that require the input of sensitive data also are usually SSL encrypted. Such secure sites are denoted with a lock symbol in the browser's status bar.

"Banks will never request personal data via e-mail," Bachfeld says.

Another increasingly popular attack method is trojans, says Guenther Ennen from the German Federal Agency for Security in Information Technology (BSI) in Bonn. Trojans are malicious programs that hide themselves on your PC, record your passwords, and then send them to the hacker.

"A trojan can get planted on your computer if you click on an e- mail attachment. It's also possible for trojans to infiltrate your machine by simply visiting certain web sites," he says.

"You can prevent trojans by installing a virus scanner and always keeping the rest of your software updated," Bachfeld says. That applies not just to internet browsers, but also to other programs like Flash players.

Hackers also use software to test potential passwords until they hit upon the right one. The best way to beat the brute force method, as it is known, is to select complicated passwords, Wolf says.

"Your wife's birthday, the name of your dog, or even your own phone number won't cut it," says Wolf.

Instead Wolf suggests a combination of capital and small letters, numbers, and special characters as passwords. Yet not all special characters are allowed in passwords, Ennen notes. "Nor should passwords include umlauts or other diacriticals, since you can't enter them in easily on foreign keyboards if you're on vacation," he adds.

A moderately secure password has at least eight characters, says Wolf. High security passwords have no fewer than 12. Under no circumstances should identical passwords be used for multiple sites.

Users who heed these warnings end up with a thick catalogue of passwords, making it hard to keep track of them all. There are both hardware and software solutions to help administer passwords, however, including the award winning RoboForm (http://www.roboform.com), available over the internet.



© 2007 - 2009 - DPA/eFluxMedia
dotclear

Other News in

Ballmer’s Rather Convincing Attempt to Convince Us That Windows Is Always the Best Choice

Ballmer’s Rather Convincing Attempt to Convince Us That Windows Is Always the Best Choice

The 2009 International Consumer Electronics Show debuted Wednesday with Microsoft CEO Steve Ballmer’s endorsement of PCs and a sneak preview of the company's future Windows 7 operating...

AMD Launches Phenom II X4 Processor

AMD Launches Phenom II X4 Processor

Advanced Micro Devices (AMD) has officially unveiled on Thursday its highly-anticipated AMD Phenom II central processing unit (CPU) along with the code-named Dragon platform for gamers. The company...

TomTom Launches TomTom GO 740 Live

TomTom Launches TomTom GO 740 Live

In the first day of CES 2009, TomTom, the GPS manufacturer, has introduced its newest portable navigation device, the TomTom GO 740 Live. This is a connected GPS that uses a built-in SIM card and a...

Sony Also Unveils The New Vaio P Series

Sony Also Unveils The New Vaio P Series

Sony has also unveiled at CES what it claims to be the world's lightest netbook, weighing only 638g. The new Vaio P Series measures 120mm x 245mm x 19.8mm, just like a business envelope and roughly...

Sony Announces Wi-Fi camera

Sony Announces Wi-Fi camera

Sony has recently unveiled its first ever Wi-Fi camera, the Cyber-shot $499 DSC-G3, at the Consumer Electronics Show (CES). However, this is not the first Wi-Fi equipped camera, but it will be the...

dotclear
Latest videos in Technology
Apple's new tune
Gadget Show Goes on Despite...
Apple Announces ITunes Price...
Macworld Goes on Without...
Apple CEO says healthy to lead

dotclear
Technology You are here: Technology
» Technology   » Gadgets   » Video Games   
E-mail To A Friend Print RSS Text size: Decrease font size Increase font size
dotclear
dotclear
dotclear
Most Popular in Technology
LG to Launch Netflix-Capable TVsLG to Launch Netflix-Capable TVs

» read full story
dotclear

Interested In This Topic?

News Alert will keep you informed. Find out more.
dotclear
Photos Gallery
dotclear
Today's Latest News
Obama’s Health Care System Reform Plans Draw Mixed ReactionObama’s Health Care System Reform Plans Draw Mixed Reaction

» read full story
dotclear