Browse by Tags

Pafwert: Now Open Source
Wed, Apr 17 2013 23:04
More than 15 years ago I started working on a unique password generator that eventually evolved into a small program I now call Pafwert. Pafwert is an unique tool to help you to select strong passwords that are easy to remember. Using strong entropy,... Read More...
Email: The Security Industry’s Single Biggest Failure
Thu, Nov 29 2012 15:07
I still remember so clearly the frustration I felt back in the 90′s when starting in the security industry and trying to sell my services. It was so difficult trying to emphasize just how much at risk potential clients were and then get them to... Read More...
Now eBay Wants in on Password Patents
Tue, Nov 13 2012 11:16
I wrote a couple months ago about the many attempts to patent various methods of checking passwords. Now eBay wants in on the game with United States Patent Application 20120284783. Here’s their summary: A proposed password is decomposed into basic... Read More...
6 New Password Rules
Wed, Sep 5 2012 17:12
Considering the increasing attention passwords have been getting lately, I thought it was about time we sit down and establish some new rules to define exactly what is a password. After all, so much of our personal lives, finances, and identities rely... Read More...
Despite the Hyperbole, Flame is Kind of Lame
Fri, Jun 8 2012 16:40
We have all been hearing quite a bit of hyperbole concerning the sophistication of the Flame malware. It’s hard to find any headline about the malware that doesn’t involve the adjectives massive, sophisticated, elaborate, impressive, or scarey... Read More...
93% of the Top 10,000 in the LinkedIn List
Thu, Jun 7 2012 18:27
I would like to welcome LinkedIn to the not-so-exclusive club of major web sites that have experienced major password leaks. Like any other major leak it is hard to visit any forum or tech blog without seeing some mention of it. And like any other leak... Read More...
Yes, Use Bcrypt. And Scrypt.
Mon, Mar 19 2012 13:06
I often come across articles that argue the strengths or weaknesses of one crypto algorithm or another. As these articles point out, cryptography is complicated and there are many factors that can affect any particular algorithm. The greatest threat for... Read More...
More Top Worst Passwords
Mon, Jun 20 2011 21:33
Back when I wrote Perfect Passwords, I generated a list of the top 500 worst (aka most common) passwords which seems to have propagated quite a bit across the internet, including being mentioned on Gizomodo, Boing Boing, Symantec, Laughing Squid and many... Read More...