Seite - 253 - in The Future of Software Quality Assurance
Bild der Seite - 253 -
Text der Seite - 253 -
Security: Itâs Everyoneâs Business! 253
doesnâtneed tobecomplex,only long.ThepassworddhrâQdfe ismuch less secure
thandog . . ., let alonea much longer sausagedog . . .!
6 UsePassphrases Instead ofPasswords
The comedian John Oliver interviewed Edward Snowden8 and the topic of pass-
words came up. We should forget about passwords, and think passphrases. Rules
wecan followare:
1. Still use themixofcharacters (upper/lower/numbers/specialcharacters)
2. Use a combinationofunrelatedwords
3. Use words fromdifferent languagesâamix is best
4. Donot relyon leetspeak/133t5p3@kalone(where lettersare replacedbysimilar
shapednumbers/specialcharacters)
5. Do not relyonone rulealone!
As an example, letâs base a passphrase on that favourite fermented curdâ
cheese. In using a combination of the rules above, my passphrase could be
Ch3ese&Kase&Farmaajo.Afterall,whocouldforgetcheese!At20characters, that
wouldgive thepasswordcrackersa run for theirmoney.
Or, think song lyrics. Something like 4!We!Are!Young!And!Free.9 Even harder
to crack, at 23 characters. Each character exponentially increases the number of
combinations,so longerisbetter.Although,MargretThatcherIs110%Sexystill takes
theprize for sheercreativeness.
What we need is time. If a breech is detected, we need time to ensure word
gets out to those affected by the breech. So timely notification is key from the
organisations who become the victims of attack. The longer the passphrase is, the
longer it takes tocrack.
We could go even further, and use a password manager. These tools will allow
a secure container into which yourcredentialsand passphrasescan be stored.They
are useful, in that they can allow secure passphrases to be auto-generated, stored,
andmost importantlymadeuniqueforeveryseparatesiteorsystemaccessed.Some
alsocomewithwallets to storepayment information,andcanworkboth indesktop
andmobileenvironments.Bothcommercialandopensourcetools areavailable.
Thedownsidesof these toolscanbe:
âą What password/phrase do you have to access this tool? If itâs weak, it would
reduce the usefulnessof the tool.
âą What security is built into this tool itself? Could the encryption it uses be an
older, compromisedversion?
8https://www.youtube.com/watch?v=yzGzB-yYKccâplease watch thisvideoâin 3 min you will
know how simple passphrase security can be.
9The second lineof the Australian national anthem.
zurĂŒck zum
Buch The Future of Software Quality Assurance"
The Future of Software Quality Assurance
- Titel
- The Future of Software Quality Assurance
- Autor
- Stephan Goericke
- Verlag
- Springer Nature Switzerland AG
- Ort
- Cham
- Datum
- 2020
- Sprache
- englisch
- Lizenz
- CC BY 4.0
- ISBN
- 978-3-030-29509-7
- Abmessungen
- 15.5 x 24.1 cm
- Seiten
- 276
- Kategorie
- Informatik