{"id":76,"date":"2009-07-24T00:00:03","date_gmt":"2009-07-24T07:00:03","guid":{"rendered":"http:\/\/www.zokul.com\/zokulblog\/?p=76"},"modified":"2012-11-11T18:42:59","modified_gmt":"2012-11-12T01:42:59","slug":"whats-in-a-name","status":"publish","type":"post","link":"http:\/\/www.zokul.com\/zokulblog\/?p=76","title":{"rendered":"what&#8217;s in a name?"},"content":{"rendered":"<p>you do this every day many times over: type a username, then a password<\/p>\n<p>but why? it&#8217;s all just letters and numbers, right?<\/p>\n<p>it is known that most smart attacks involve some kind of social engineering e.g. the attacker knows the victims name, and tries a list of well known passwords (like 1234, admin, test etc) from a list &#8211; sometimes a dictionary helps, too, with the most common names, or combinations of username with birthyear etc (like john1975)<br \/>\nand then it&#8217;s up to the password to keep you safe &#8211; so you ought to choose one that&#8217;s long and has special characters in it (like #&lt;*). if that doesn&#8217;t work the attacker digs deeper and calls coworkers, pretending to be a friend, super, lawenforcer or other coworker to obtain more infos.<br \/>\nBUT the name is still fairly simple to guess. so WHY NOT get rid of it?<\/p>\n<p>let&#8217;s say your username has 10 letters, and the password is another 10 &#8211; that&#8217;s 20 letters to type, and in between you gotta use the mouse to move from field to field (or the cursor or tab)<br \/>\nthe first 10 though are almost a waste of time, and the next 10 are supposed to be very difficult to guess (if you can&#8217;t find the post-it-note next to the screen!) &#8211; so sometimes people put a post-it up on their monitor with that info &#8230;<\/p>\n<p>what about if you just enter a (complicated) 15 letter &#8216;access code&#8217; that might have some personal meaning to the user? eg FOOL1975=&gt;JOHN!<\/p>\n<p>hard to guess, in NO dictionary, personalized, shorter than 20, and safer!<\/p>\n<p>almost as safe as certificates &#8211; but who remembers a sha1 hash with 40 characters? besides, the # of wrong logins and attempts per timeunit has to be limited anyways<\/p>\n","protected":false},"excerpt":{"rendered":"<p>you do this every day many times over: type a username, then a password but why? it&#8217;s all just letters and numbers, right? it is known that most smart attacks involve some kind of social engineering e.g. the attacker knows the victims name, and tries a list of well known passwords (like 1234, admin, test [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[],"class_list":["post-76","post","type-post","status-publish","format-standard","hentry","category-software-stuff"],"_links":{"self":[{"href":"http:\/\/www.zokul.com\/zokulblog\/index.php?rest_route=\/wp\/v2\/posts\/76","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.zokul.com\/zokulblog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.zokul.com\/zokulblog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.zokul.com\/zokulblog\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"http:\/\/www.zokul.com\/zokulblog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=76"}],"version-history":[{"count":6,"href":"http:\/\/www.zokul.com\/zokulblog\/index.php?rest_route=\/wp\/v2\/posts\/76\/revisions"}],"predecessor-version":[{"id":153,"href":"http:\/\/www.zokul.com\/zokulblog\/index.php?rest_route=\/wp\/v2\/posts\/76\/revisions\/153"}],"wp:attachment":[{"href":"http:\/\/www.zokul.com\/zokulblog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=76"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.zokul.com\/zokulblog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=76"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.zokul.com\/zokulblog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=76"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}