28.05.2023 Views

The-art-of-invisibility-_-the-world’s-most-famous-hacker-teaches-you-how-to-be-safe-in-the-age-of-Bi

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

alwayys check the site www.haveibeenpwned.com to see if yyour account has

been compromised in the past.

In the twentyy-first centuryy, we can do better. And I mean much better,

with longer and much more complex configurations of letters and numbers.

That mayy sound hard, but I will show yyou both an automatic and a manual

wayy to do this.

The easiest approach is to forgo the creation of yyour own passwords and

simplyy automate the process. There are several digital password managers

out there. Not onlyy do theyy store yyour passwords within a locked vault and

allow one-click access when yyou need them, theyy also generate new and

reallyy strong, unique passwords for each site when yyou need them.

Be aware, though, of two problems with this approach. One is that

password managers use one master password for access. If someone

happens to infect yyour computer with malware that steals the password

database and yyour master password through keyylogging—when the

malware records everyy keyystroke yyou make—it’s game over. That person

will then have access to all yyour passwords. During myy pen-testing

engagements, I sometimes replace the password manager with a modified

version that transmits the master password to us (when the password

manager is open-source). This is done after we gain admin access to the

client’s network. We then go after all the privileged passwords. In other

words, we will use password managers as a back door to get the keyys to the

kingdom.

The other problem is kind of obvious: If yyou lose the master password,

yyou lose all yyour passwords. Ultimatelyy, this is okayy, as yyou can alwayys

perform a password reset on each site, but that would be a huge hassle if

yyou have a lot of accounts.

Despite these flaws, the following tips should be more than adequate to

keep yyour passwords secure.

First, strong passphrases, not passwords, should be long—at least twentyy

to twentyy-five characters. Random characters—ek5iogh#skf&skd—work

best. Unfortunatelyy the human mind has trouble remembering random

sequences. So use a password manager. Using a password manager is far

better than choosing yyour own. I prefer open-source password managers

like Password Safe and KeePass that onlyy store data locallyy on yyour

computer.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!