<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Security Fundas</title>
	<atom:link href="http://securityfundas.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://securityfundas.wordpress.com</link>
	<description>Place for small, quick tips and tricks for Information Security</description>
	<lastBuildDate>Thu, 01 Oct 2009 05:26:06 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='securityfundas.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Security Fundas</title>
		<link>http://securityfundas.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://securityfundas.wordpress.com/osd.xml" title="Security Fundas" />
	<atom:link rel='hub' href='http://securityfundas.wordpress.com/?pushpress=hub'/>
		<item>
		<title>How do you choose a good password</title>
		<link>http://securityfundas.wordpress.com/2009/10/01/good-password/</link>
		<comments>http://securityfundas.wordpress.com/2009/10/01/good-password/#comments</comments>
		<pubDate>Thu, 01 Oct 2009 05:26:06 +0000</pubDate>
		<dc:creator>aashishkunte</dc:creator>
				<category><![CDATA[Password Protection]]></category>
		<category><![CDATA[Access Contol]]></category>
		<category><![CDATA[Authentication]]></category>
		<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Good Password]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Password Cracking]]></category>
		<category><![CDATA[password security]]></category>
		<category><![CDATA[Protection]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[User Awareness]]></category>

		<guid isPermaLink="false">http://securityfundas.wordpress.com/?p=4</guid>
		<description><![CDATA[Passwords are the most common means of authentication, but if you don&#8217;t choose good passwords or keep them confidential, they&#8217;re almost as ineffective as not having any password at all. Many systems and services have been successfully broken down due to the use of  small, insecure and inadequate passwords. Some viruses and worms have exploited systems by guessing weak passwords. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=securityfundas.wordpress.com&amp;blog=9683807&amp;post=4&amp;subd=securityfundas&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Passwords are the most common means of authentication, but if you don&#8217;t choose good passwords or keep them confidential, they&#8217;re almost as ineffective as not having any password at all.</p>
<p>Many systems and services have been successfully broken down due to the use of  small, insecure and inadequate passwords. Some viruses and worms have exploited systems by guessing weak passwords. There are various softwares out there to Crack and Guess your password within Fraction of Seconds !!</p>
<p>Here I would like to take you thru some of the tips and tricks to choose a good password and how to protect it !!</p>
<p><strong> </strong></p>
<p><strong>How do you choose a good password?</strong></p>
<p>We choose our passwords as the string of characters based on our personal information and of course that&#8217;s easy to remember.  However, that also makes it easier for an attacker to guess or &#8220;crack&#8221; them. Consider a four-digit PIN number. Do you know how easy it is to generate the combination matrix for a 4 Digit Number ?</p>
<p>Is that number is a sequential combination of the month, day, or year of your birthday?</p>
<p>Or the last four digits of your vehicle registration number?</p>
<p>Or your address … phone number?</p>
<p>Think about how easily it is to find this information out about somebody.</p>
<p>What about the email password&#8230;  is it a word that can be found in the dictionary? If so, it is easy to gain information thru &#8221;dictionary&#8221; attacks, which attempt to guess passwords based on words in the dictionary.<br />
<strong><br />
</strong>Although intentionally misspelling a word (&#8220;daytt&#8221; instead of &#8220;date&#8221;) may hold some protection against dictionary attacks.  Better method is to choose a series of words and use some memory techniques. This will help to remember for decoding it back !  </p>
<p>For example, instead of the password <span style="color:#993300;">&#8220;hoops,&#8221; </span></p>
<p>We can use <span style="color:#993300;">&#8220;IlTpbb&#8221;</span>for &#8220;[I] [l]ike [T]o [p]lay [b]asket[b]all.&#8221;</p>
<p>Using both lowercase and capital letters adds another layer of obscurity.</p>
<p>Your best defense, though, is to use a combination of numbers, special characters, and both lowercase and capital letters.</p>
<p>Change the same example<br />
we used above to &#8220;Il!2pBb.&#8221; and see how much more complicated it has become just by adding numbers and special characters.</p>
<p>Longer passwords are more secure than shorter ones because there are more characters to guess, so consider using passphrases when you can.</p>
<p>For example,</p>
<p> &#8221;This passwd is 4 my email!&#8221; would be a strong password because it has many characters and includes lowercase and capital letters, numbers, and special characters. You may need to try different variations of a passphrase many applications limit the length of passwords, and some do not accept spaces. </p>
<p><span id="lblPasswordEasy2">&#8220;Q3h73QSr&#8221; is strong and easy to remember as [Q]UICK [3] [h]appy [7] [3] [Q]UICK [S]ONY [r]adio !</span></p>
<p>You can use your own way of memory technique in your own language &#8230; &#8220;12#Ks4#f&#8221; is strong and easy to remember in Hindi Language also as [12] Topi[#] [K]e [s]aath [4] Topi[#][f]ree !  </p>
<p>Try to avoid common phrases, famous quotations, and song lyrics. Password crackers have knowledge of various languages as well !</p>
<p>Don&#8217;t assume that now you&#8217;ve developed a strong password you should use it for every system or program you log into. If an attacker does guess it, he would have access to all of your accounts. You should use these techniques to develop unique passwords for each of your accounts. At least keep your Banking/Transaction Passwords separate than your E-Mail, Blogs and Social Networks !</p>
<p><strong>Here is a review of tactics to use when choosing a password:<br />
</strong>* Don&#8217;t use passwords that are based on personal information that can be easily accessed or guessed.<br />
* Don&#8217;t use words that can be found in any dictionary of any language.<br />
* Develop a mnemonic for remembering complex passwords.<br />
* Use both lowercase and capital letters.<br />
* Use a combination of letters, numbers, and special characters.<br />
* Use passphrases when you can.<br />
* Use different set of passwords on different systems.<br />
<strong><br />
How can you protect your password?<br />
</strong><br />
Now that we have chosen a good password that&#8217;s difficult to guess, We need to make sure not to leave it some place for people to find.</p>
<p>Writing it down and leaving it in your desk, next to your computer, tagged to your computer/board side by ! This is just making it easy for someone who has physical access to your workplace. Don&#8217;t tell anyone your passwords, and watch for attackers trying to trick you through phone calls or email messages requesting that you reveal your passwords. Of course, your Banking Accounts and Online Transaction stuff may be of intrest for someone else !  </p>
<p>If your internet service provider (ISP) offers choices of authentication systems, look for ones that use Kerberos, challenge/response type, or public key encryption rather than simple passwords.  Consider challenging service providers that only use passwords to adopt more secure methods. Also you can request the ISP Support person to help you out in changing the configurations as per your comfort level.</p>
<p>Also, many programs offer the option of &#8220;remembering&#8221; your password, but these programs have different ways and methods of security protecting that information. It is not a very good practice to allow those programs to save your password on a Public PC or any other non trusted source of internet!<br />
Some programs, such as email clients, store the information in clear text in a file on your computer. This means that anyone with access to your computer can discover all of your passwords and can gain access to your information.</p>
<p>For this reason, always remember to log out when you are using a public computer (at the library, an internet cafe, or even a shared computer at your office). Other programs, such as Apple&#8217;s Keychain and Palm&#8217;s Secure Desktop, use strong encryption to protect the information. These types of programs may be a good option for managing your passwords if you find you have too many to remember.</p>
<p>There&#8217;s no guarantee that these techniques will prevent an attacker from learning your password, but they will make it more difficult.</p>
<p><strong><span style="color:#800000;">Note:</span> This is an extract from Original Security Tip &#8220;<span style="color:#800000;">Choosing and Protecting Passwords</span>&#8221; Published by US-CERT and the Original post is found at the link below.</strong></p>
<p><strong><a href="http://www.us-cert.gov/cas/tips/ST04-002.html"><span style="color:#800000;">http://www.us-cert.gov/cas/tips/ST04-002.html</span></a><span style="color:#800000;">.</span></strong></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/securityfundas.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/securityfundas.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/securityfundas.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/securityfundas.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/securityfundas.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/securityfundas.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/securityfundas.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/securityfundas.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/securityfundas.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/securityfundas.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/securityfundas.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/securityfundas.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/securityfundas.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/securityfundas.wordpress.com/4/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=securityfundas.wordpress.com&amp;blog=9683807&amp;post=4&amp;subd=securityfundas&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://securityfundas.wordpress.com/2009/10/01/good-password/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3ce333f8d81d4c62dad2761346814722?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">aashishkunte</media:title>
		</media:content>
	</item>
		<item>
		<title>Hello world!</title>
		<link>http://securityfundas.wordpress.com/2009/09/28/hello-world/</link>
		<comments>http://securityfundas.wordpress.com/2009/09/28/hello-world/#comments</comments>
		<pubDate>Mon, 28 Sep 2009 06:32:47 +0000</pubDate>
		<dc:creator>aashishkunte</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Welcome to WordPress.com. This is your first post. Edit or delete it and start blogging!<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=securityfundas.wordpress.com&amp;blog=9683807&amp;post=1&amp;subd=securityfundas&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Welcome to <a href="http://wordpress.com/">WordPress.com</a>. This is your first post. Edit or delete it and start blogging!</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/securityfundas.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/securityfundas.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/securityfundas.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/securityfundas.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/securityfundas.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/securityfundas.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/securityfundas.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/securityfundas.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/securityfundas.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/securityfundas.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/securityfundas.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/securityfundas.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/securityfundas.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/securityfundas.wordpress.com/1/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=securityfundas.wordpress.com&amp;blog=9683807&amp;post=1&amp;subd=securityfundas&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://securityfundas.wordpress.com/2009/09/28/hello-world/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3ce333f8d81d4c62dad2761346814722?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">aashishkunte</media:title>
		</media:content>
	</item>
	</channel>
</rss>
