Tuesday 5 January 2016

Beating the scammers

I have just watched a recorded program about beating the scammers, and it showed about 4 methods by which people have been scammed. It was a good program, sponsored by NatWest Bank.

The last part of it had our presenter meeting a security expert who tested various passwords, that were hash-encrypted to see how easy that were to unencrypt. And it seemed very easy.

After the program I got on the computer and downloaded one of these programs to test out some of my passwords, but then realised that I would need a program to hash encrypt my plaintext password.

A bit of a think and I went looking for a password strength tester and found http://www.passwordmeter.com/ and  tested a number of my passwords on it. They all fell short.   As a matter of fact the only password/phrase that gave 100% strength  was "Then out spake brave Horatio"  and that is without numerals or symbols (aside from spaces).

The question is how good are these password checkers that compare your password against defined parameters in comparison with hash crackers?   They both rate poorly easy words and simple words with substitutions and rate highly difficult phrases such as words of a  song or poem, but does the comparison hold?

More thought required, so I'll come back to this later.