E-CommerceALERT.com is part of the Bennett Gold LLP web site network.
LINK TO: Bennett Gold LLP, Chartered Professional Accountants, home page.
LINK TO: E-CommerceALERT.com Home Page.
CLICK to GO BACK to Main Page.

Research and retrieval of news articles by:
Bennett Gold LLP, Chartered Professional Accountants


SPECIAL NOTE TO ALL VISITORS:
Effective December 31 2012, articles are no longer being updated on this web site.
The site is now maintained as an historical archive, covering notable e-commerce news articles from the period 1999 to 2012.


CREATING SECURE PASSWORDS YOU DON'T HAVE TO REMEMBER

Source: SearchSecurity.com

Posted on March 23, 2006

      Are passwords doomed? The unanimous lament among security experts is how most people don't use strong passwords. They either use personally identifiable information or else horribly weak passwords that won't survive a dictionary attack. Furthermore, Microsoft is talking about allowing people to almost entirely do away with passwords in Internet Explorer 7.

      It's a Catch-22 situation: People rarely use strong passwords because they are impossible to remember, and yet they've been told time and again never to write them down, which only makes them harder to memorize.

      There's got to be a better way, you say. Well, to a degree, there already is. Programmer Chris Zarate has created an online password generator application that functions in a way I've never seen before. It actually works with a user's bad memory rather than against it.

      The premise is simple. You supply a single master password -- it doesn't matter what it is, and it doesn't have to be secure -- and the application generates a bookmarklet that takes the domain name of the site you're visiting and creates a password to use in that domain by hashing it against your master password.

      The bookmarklet is not a program; it's simply a bookmark that, when selected, pops up a text window (via JavaScript) that contains the password to use for that domain.

      Bookmarklets can be generated for Firefox and IE and are created via the secure MD5 algorithm, which makes them impossible to reverse-engineer. No information of any kind is transmitted to an outside server to create the bookmarklet or generate the password. You can also create a bookmarklet with the master password hard-coded into it (if you're reasonably certain you'll be the only one accessing the computer) or one that prompts you for the master password each time. The script can even automatically populate password fields in the current page as needed.

      This is a creative and powerful solution to a problem that isn't going to go away soon.




CLICK to GO BACK to Main Page.

E-Commerce Alerts are issued by Bennett Gold LLP, Chartered Professional Accountants as situations develop. Bookmark this site and check back often. Our e-mail address is: info@BennettGold.ca

In accordance with United States Code, Title 17, Section 107 and Article 10 of The Berne Convention on Literary and Artistic Works, the news clippings on this web site are made available without profit for research and educational purposes.


ALERT
ARCHIVES
Final Entries
2012
2011
2010
2009
2008
2007
2006
2005
2004
2003
2002
2001
2000
1999


LINK TO: Bennett Gold, Chartered Professional Accountants: A Licensed Provider of WebTrust Services.

WebTrust Is Your
Best Defense
Against
Privacy Breaches.

Get WebTrust
Working For
Your Site.