Friday, March 7, 2008

"My hands are small...."

When I was in college, my best friend and I decided it would be useful to share our computer and email passwords with each other. It came in handy whenever I needed him to check my email and check my grades online. Little did I know that the password I thought was so clever, “blink182,” was (and still is) one of the most frequently used passwords. Since many computer systems require at least eight characters and a combination of letters and numbers, I thought it was a perfect password. After all, it was 1998, Dammit was one of the hottest songs out, and “hands” doesn’t have any numbers in it. Yeah, I was a big Jewel fan, too.

Note to self to make myself feel better…Blink 182 got even better after Travis Barker joined them.



What’s funny is that whenever I’m working on a client’s computer and I get prompted for a password, there’s about a 25% chance I can guess what it is within five tries. I never thought to try my own, though. Fortunately, I had that password nearly ten years ago and identity theft, malicious hacks, and intrusive attacks were not nearly as rampant as they are today.

In fact, a group of researchers from Princeton recently published a paper showing how a computer could be hacked with just a spray duster and a screwdriver. Why does this sound so familiar? Oh yeah.



While Princeton’s method requires shutting down the computer and physically removing the memory, a New Zealand security consultant recently discovered a way to unlock Windows and OS X passwords using a Linux machine connected via Firewire.

Note that both of these methods require physical access to the PC, which is not the most common forms of attacks. Most attacks occur through the network where they can go undetected. Therefore, in addition to physically protecting your computer, there are steps everyone should take to protect themselves from network attacks. Obviously, purchasing a firewall is a huge plus but the easiest and most effective thing you can do to protect yourself is by protecting your computers and accounts with strong passwords. Here’s a helpful Microsoft article on creating strong passwords so you can minimize your chances of getting hacked.

And if you’re worried about forgetting your complex password or you’re stuck on using band names from the 90’s, you’re better off leaving your password blank. Windows computers require a password to be accessed remotely, thus making blank password a better solution than simple passwords.

No comments: