<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Holy Shmoly! &#187; password</title>
	<atom:link href="http://ocaoimh.ie/tag/password/feed/" rel="self" type="application/rss+xml" />
	<link>http://ocaoimh.ie</link>
	<description>Look what I found today!</description>
	<lastBuildDate>Fri, 25 May 2012 17:12:43 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Speedy password cracking</title>
		<link>http://ocaoimh.ie/2012/04/06/speedy-password-cracking/</link>
		<comments>http://ocaoimh.ie/2012/04/06/speedy-password-cracking/#comments</comments>
		<pubDate>Fri, 06 Apr 2012 13:13:24 +0000</pubDate>
		<dc:creator>Donncha O Caoimh</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[irishblogs]]></category>
		<category><![CDATA[pass phrase generator]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[xkcd]]></category>

		<guid isPermaLink="false">http://ocaoimh.ie/?p=89497317</guid>
		<description><![CDATA[Earlier today Jeff Atwood tweeted: you should *really* be scared if your passwords are all lowercase. 12 chars in 75 days on my box.. He was referring to his post on speed hashing where a video card GPU is used to calculate the hash of any given text. Compared to a computer CPU it does [...]]]></description>
			<content:encoded><![CDATA[<p>Earlier today Jeff Atwood <a href="https://twitter.com/#!/codinghorror/statuses/188217028786667521">tweeted</a>:</p>
<blockquote><p>you should *really* be scared if your passwords are all lowercase. 12 chars in 75 days on my box..</p></blockquote>
<p>He was referring to his post on <a href="http://www.codinghorror.com/blog/2012/04/speed-hashing.html">speed hashing</a> where a video card GPU is used to calculate the hash of any given text. Compared to a computer CPU it does it <em>much</em> faster. </p>
<blockquote><p>all 6 character password MD5s	47 seconds<br />
all 7 character password MD5s	1 hour, 14 minutes<br />
all 8 character password MD5s	~465 days<br />
all 9 character password MD5s	fuggedaboudit</p></blockquote>
<p>It&#8217;s honestly scary and really time for everyone to use <a href="http://xkcd.com/936/">pass phrases</a>. They&#8217;re not perfect either but they&#8217;re better because they&#8217;re longer and easier to remember. Some of my passwords are not phrases yet, this <a href="http://www.fourmilab.ch/javascrypt/pass_phrase.html">pass phrase generator</a> (or <a href="http://passphra.se/">this one</a>) should help make it easier to change those. </p>
<p><a href="http://ocaoimh.ie/ocaoimh/2012/04/password_strength.png"><img src="http://ocaoimh.ie/ocaoimh/2012/04/password_strength-300x243.png" alt="" title="password strength" width="300" height="243" class="aligncenter size-medium wp-image-89497320" /></a><br />
* obligatory xkcd cartoon.</p>
 <img src="http://ocaoimh.ie/wp-content/plugins/wordpress-feed-statistics/feed-statistics.php?view=1&post_id=89497317" width="1" height="1" style="display: none;" />
<p><strong>Related Posts</strong><ul><li> <a href="http://ocaoimh.ie/2004/06/28/excel-password-remover/" rel="bookmark" title="Permanent Link: Excel password remover">Excel password remover</a></li><li> <a href="http://ocaoimh.ie/2012/01/27/cant-login-to-games-for-windows-live/" rel="bookmark" title="Permanent Link: Can&#8217;t login to Games for Windows Live?">Can&#8217;t login to Games for Windows Live?</a></li><li> <a href="http://ocaoimh.ie/2011/05/18/wow-more-playstation-problems-the-password-reset-form/" rel="bookmark" title="Permanent Link: Wow more Playstation problems The password reset form&#8230;">Wow more Playstation problems The password reset form&#8230;</a></li></ul></p>]]></content:encoded>
			<wfw:commentRss>http://ocaoimh.ie/2012/04/06/speedy-password-cracking/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>20f1aeb7819d7858684c898d1e98c1bb</title>
		<link>http://ocaoimh.ie/2007/12/19/20f1aeb7819d7858684c898d1e98c1bb/</link>
		<comments>http://ocaoimh.ie/2007/12/19/20f1aeb7819d7858684c898d1e98c1bb/#comments</comments>
		<pubDate>Wed, 19 Dec 2007 13:59:32 +0000</pubDate>
		<dc:creator>Donncha O Caoimh</dc:creator>
				<category><![CDATA[WordPress]]></category>
		<category><![CDATA[12345]]></category>
		<category><![CDATA[Anthony]]></category>
		<category><![CDATA[irishblogs]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[qwerty]]></category>
		<category><![CDATA[wordpress-mu]]></category>

		<guid isPermaLink="false">http://ocaoimh.ie/2007/12/19/20f1aeb7819d7858684c898d1e98c1bb/</guid>
		<description><![CDATA[What is the significance of &#8220;20f1aeb7819d7858684c898d1e98c1bb&#8221;? It&#8217;s the MD5 hash of the name &#8220;Anthony&#8221; and was the password used by someone who broke into lightbluetouchpaper.org. Searching for the md5 hash was clever, but it won&#8217;t work for long because Ryan is working on securing the WordPress cookies and passwords. In case you&#8217;re wondering, the hacker [...]]]></description>
			<content:encoded><![CDATA[<p>What is the significance of &#8220;20f1aeb7819d7858684c898d1e98c1bb&#8221;? It&#8217;s the MD5 hash of the name &#8220;Anthony&#8221; and was the password used by someone <a href="http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/">who broke into</a> lightbluetouchpaper.org. Searching for the md5 hash was clever, but it won&#8217;t work for long because <a href="http://boren.nu/archives/2007/12/17/secure-cookies-and-passwords/">Ryan is working</a> on securing the WordPress cookies and passwords.<br />
In case you&#8217;re wondering, the hacker <a href="http://www.lightbluetouchpaper.org/2007/10/27/upgrade-and-new-theme/">got in</a> because the blog was running an outdated version of WordPress.</p>
<p>Tips to help keep your blog safe:
<ul>
<li> Keep all your software updated, not just WordPress. Make sure your plugins are updated.</li>
<li> Use a strong password. Don&#8217;t use words or sequences of characters like &#8220;12345&#8243; as your password. Make it a mix of characters and numbers.</li>
<li> Don&#8217;t <em>ever</em> store your database dump online in a place Google will index it. It is very easy to use a Google search to find it.</li>
<li> If you use public WiFi or a net cafe regularly, use SSL to secure the communication with your blog. Use the <a href="http://wordpress.org/extend/plugins/secure-admin/">secure admin</a> plugin for just this purpose.</li>
<li> If you use Firefox, install <a href="https://addons.mozilla.org/en-US/firefox/addon/1033">PwdHash</a>. It&#8217;s simple to use and works really well.</li>
</ul>
<p>WordPress MU admins &#8211; Fire up phpmyadmin and look at wp_users. Try these sql queries to find weak passwords in your database:</p>
<blockquote><p>SELECT count(*) FROM `wp_users` WHERE user_pass = md5(&#8216;wordpress&#8217;);<br />
SELECT count(*) FROM `wp_users` WHERE user_pass = md5(&#8217;12345&#8242;);<br />
SELECT count(*) FROM `wp_users` WHERE user_pass = md5(&#8216;qwerty&#8217;);<br />
SELECT count(*) FROM `wp_users` WHERE user_pass = md5(&#8216;anthony&#8217;);<br />
SELECT count(*) FROM `wp_users` WHERE user_pass = md5(&#8216;Anthony&#8217;);<br />
and because of the season:<br />
SELECT count(*) FROM `wp_users` WHERE user_pass = md5(&#8216;christmas&#8217;);</p></blockquote>
<p>Scary isn&#8217;t it how many people still use simple passwords? I must release that &#8220;Strong password&#8221; plugin we use on WordPress.com soon. That will certainly help avoid account hijacking.</p>
 <img src="http://ocaoimh.ie/wp-content/plugins/wordpress-feed-statistics/feed-statistics.php?view=1&post_id=89493428" width="1" height="1" style="display: none;" />
<p><strong>Related Posts</strong><ul><li> No related posts</li></ul></p>]]></content:encoded>
			<wfw:commentRss>http://ocaoimh.ie/2007/12/19/20f1aeb7819d7858684c898d1e98c1bb/feed/</wfw:commentRss>
		<slash:comments>29</slash:comments>
		</item>
		<item>
		<title>Excel password remover</title>
		<link>http://ocaoimh.ie/2004/06/28/excel-password-remover/</link>
		<comments>http://ocaoimh.ie/2004/06/28/excel-password-remover/#comments</comments>
		<pubDate>Mon, 28 Jun 2004 15:04:28 +0000</pubDate>
		<dc:creator>Donncha O Caoimh</dc:creator>
				<category><![CDATA[Desktop apps]]></category>
		<category><![CDATA[Excel]]></category>
		<category><![CDATA[irishblogs]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[xls]]></category>

		<guid isPermaLink="false">//?p=</guid>
		<description><![CDATA[If, as sometimes happens, you&#8217;re working at something and are called away from your desk, it&#8217;s nice to know you can lock Excel and stop others fiddling with it. Unfortunately it&#8217;s also possible that you might forget your password. *ahem* If so, go download the Free Excel password remover and watch it work wonders and [...]]]></description>
			<content:encoded><![CDATA[<p>If, as sometimes happens, you&#8217;re working at something and are called away from your desk, it&#8217;s nice to know you can lock Excel and stop others fiddling with it. Unfortunately it&#8217;s also possible that you might forget your password. *ahem*<br />
If so, go download the Free <a href="http://www.straxx.com/excel/password.html">Excel password remover</a> and watch it work wonders and crack that password and get you back into work mode faster than you can read a long winded run-on sentence that&#8217;s meandering nowhere, fast.</p>
 <img src="http://ocaoimh.ie/wp-content/plugins/wordpress-feed-statistics/feed-statistics.php?view=1&post_id=89491132" width="1" height="1" style="display: none;" />
<p><strong>Related Posts</strong><ul><li> <a href="http://ocaoimh.ie/2007/02/21/how-to-edit-a-cell-in-excel-or-openoffice/" rel="bookmark" title="Permanent Link: How to edit a cell in Excel or Openoffice">How to edit a cell in Excel or Openoffice</a></li><li> <a href="http://ocaoimh.ie/2012/01/27/cant-login-to-games-for-windows-live/" rel="bookmark" title="Permanent Link: Can&#8217;t login to Games for Windows Live?">Can&#8217;t login to Games for Windows Live?</a></li><li> <a href="http://ocaoimh.ie/2011/05/18/wow-more-playstation-problems-the-password-reset-form/" rel="bookmark" title="Permanent Link: Wow more Playstation problems The password reset form&#8230;">Wow more Playstation problems The password reset form&#8230;</a></li></ul></p>]]></content:encoded>
			<wfw:commentRss>http://ocaoimh.ie/2004/06/28/excel-password-remover/feed/</wfw:commentRss>
		<slash:comments>79</slash:comments>
		</item>
	</channel>
</rss>

