原文地址:https://profiles.google.com/changsimeng/posts/JZxgmsB9A3M#changsimeng/posts/JZxgmsB9A3M
一个好的密码策略是,选一个你容易记住的长 句子,比如诗句,选每个字拼音首字母,作为 密码。
你很容易记而别人很难猜到。
用这个长密码作为主密码前缀。
对每个不同帐号,再选一个短而容易记的,和 网站相关的密码后缀。
每个帐号的密码由同样的主密码前缀和不同的 短密码后缀构成[1]。
这样,即便一个帐号的密码失窃[4],窃贼 也无法容易地知道你其他帐号的密码。
而你却很容易记住每个帐号的密码。
比如,
选一个长密码前缀:天然一个仙人洞无限风光 在险峰 trygxrdwxfgzxf
这串字符看起来无意义,但对你有意义。;)
然后,选择
gmail 帐号密码后缀为 gm01
hotmail 帐号密码后缀为 h0m
这样,
gmail 密码为 trygxrdwxfgzxfgm01
hotmail 密码为 trygxrdwxfgzxfh0m
这样如果窃取了一个密码,是很难分清哪一部 分是前缀,哪一部分是后缀的,也就很难猜测 其他帐号密码。
即便窃取了两个帐号的密码,知道了共同的前 缀,要猜测第三个帐号的后缀,毕竟还是需要 一点时间的。
这样的密码强度[2]很高,但记忆负担却并 不很大。
为了防止遗忘密码,学会用 keepass [7]保存网络密码,这样不会因为记不住而 都用同样密码而带来密码失窃导致全部帐号被 窃取的危险。
特别注意,不要为了偷懒而在办公,网吧,旅 店等公用计算机上保存帐号密码。在私人电脑 上保存密码,也必须选择支持主密码加密的软 件[3],最好不要保存帐 号密码。因为保存的密码不一定加密保存,很 容易用软件工具[5][6]破解获取。
参考:
[1] Security Simplified: The Base+Suffix Method for Memorable Strong Passwords; Thursday, February 19th, 2009; http://luxsci.com/bl og/security-simplifi ed-the-basesuffix-me thod-for-memorable-s trong-passwords.html
[2] Cracking Passwords in the Cloud: Insights on Password Policies; THURSDAY, OCTOBER 29, 2009; http://news.electric alchemy.net/2009/10/ password-cracking-in -cloud-part-5.html
[3] Master Password Encryption in FireFox and Thunderbird; Friday, February 27th, 2009; http://luxsci.com/bl og/master-password-e ncryption-in-firefox -and-thunderbird.htm l
[4] SniffPass v1.12 - Password Monitoring Software; http://www.nirsoft.n et/utils/password_sn iffer.html
[5] Mail PassView - Recover POP3/IMAP/SMTP email passwords; http://www.nirsoft.n et/utils/password_sn iffer.html
[6] Dialupass - Recover VPN/RAS/Dialup passwords; http://www.nirsoft.n et/utils/dialupass2. html
[7] Five Best Password Managers; http://lifehacker.co m/5042616/five-best- password-managers
[15] 编程随想:如何防止黑客入侵
https://www.google.c om/buzz/changsimeng/ Wk4kHpyx6Yz/
http://blog.csdn.net /program_think/archi ve/2010/06/09/565726 2.aspx
https://www.google.c om/buzz/changsimeng/ HsT1eTZ7iyg/
http://program-think .blogspot.com/2010/0 6/howto-prevent-hack er-attack-1.html
http://blog.csdn.net /program_think/archi ve/2010/06/09/565726 9.aspx
http://program-think .blogspot.com/2010/0 6/howto-prevent-hack er-attack-2.html
http://blog.csdn.net /program_think/archi ve/2010/06/15/567303 3.aspx
http://program-think .blogspot.com/2010/0 6/howto-prevent-hack er-attack-3.html
http://blog.csdn.net /program_think/archi ve/2010/06/20/568209 4.aspx
https://www.google.c om/buzz/program.thin k/KP2FrN4c4RH/
https://www.google.c om/buzz/program.thin k/66R8cijnwGM/
http://program-think .blogspot.com/2010/0 8/howto-prevent-hack er-attack-4.html
http://blog.csdn.net /program_think/archi ve/2010/08/02/578394 7.aspx [16] 编程随想:CNNIC证书的危害及各种清除 方法
https://www.google.c om/buzz/changsimeng/ b5dVmPZSe6p/
http://program-think .blogspot.com/2010/0 2/remove-cnnic-cert. html
http://blog.csdn.net /program_think/archi ve/2010/02/16/530969 9.aspx
http://program-think .blogspot.com/2010/0 2/about-cnnic.html
http://program-think .spaces.live.com/blo g/cns!F5B0090663FEEA DA!623.entry
http://program-think .blogspot.com/2010/0 2/introduce-digital- certificate-and-ca.h tml
http://blog.csdn.net /program_think/archi ve/2010/02/08/530018 4.aspx
[17] 编程随想:如何隐藏你的踪迹,避免跨省追捕
https://www.google.c om/buzz/changsimeng/ Az9MioJQvsQ/
http://program-think .blogspot.com/2010/0 4/howto-cover-your-t racks-0.html
http://program-think .spaces.live.com/blo g/cns!F5B0090663FEEA DA!674.entry
http://program-think .blogspot.com/2010/0 4/howto-cover-your-t racks-1.html
http://program-think .spaces.live.com/blo g/cns!F5B0090663FEEA DA!675.entry
http://program-think .blogspot.com/2010/0 4/howto-cover-your-t racks-2.html
http://program-think .spaces.live.com/blo g/cns!F5B0090663FEEA DA!678.entry
http://program-think .blogspot.com/2010/0 5/howto-cover-your-t racks-3.html
http://program-think .spaces.live.com/blo g/cns!F5B0090663FEEA DA!689.entry
[18] 编程随想:信息安全之社会工程学; https://www.google.c om/buzz/104802289453 542970648/N88CucN5Ys T/
http://program-think .blogspot.com/2009/0 5/social-engineering -0-overview.html
http://blog.csdn.net /program_think/archi ve/2009/05/05/415292 2.aspx
http://program-think .blogspot.com/2009/0 5/social-engineering -1-gather-informatio n.html
http://blog.csdn.net /program_think/archi ve/2009/05/06/415618 7.aspx
http://program-think .blogspot.com/2009/0 5/social-engineering -2-pretend.html
http://blog.csdn.net /program_think/archi ve/2009/05/09/416424 2.aspx
http://program-think .blogspot.com/2009/0 5/social-engineering -3-influence.html
http://blog.csdn.net /program_think/archi ve/2009/05/19/420254 5.aspx
http://program-think .blogspot.com/2009/0 6/social-engineering -4-example.html
http://blog.csdn.net /program_think/archi ve/2009/06/07/425026 6.aspx
http://program-think .blogspot.com/2009/0 7/social-engineering -5-defend.html
http://blog.csdn.net /program_think/archi ve/2009/07/08/432973 1.aspx
Permalink | Leave a comment »
你很容易记而别人很难猜到。
用这个长密码作为主密码前缀。
对每个不同帐号,再选一个短而容易记的,和
每个帐号的密码由同样的主密码前缀和不同的
这样,即便一个帐号的密码失窃[4],窃贼
而你却很容易记住每个帐号的密码。
比如,
选一个长密码前缀:天然一个仙人洞无限风光
这串字符看起来无意义,但对你有意义。;)
然后,选择
gmail 帐号密码后缀为 gm01
hotmail 帐号密码后缀为 h0m
这样,
gmail 密码为 trygxrdwxfgzxfgm01
hotmail 密码为 trygxrdwxfgzxfh0m
这样如果窃取了一个密码,是很难分清哪一部
即便窃取了两个帐号的密码,知道了共同的前
这样的密码强度[2]很高,但记忆负担却并
为了防止遗忘密码,学会用 keepass [7]保存网络密码,这样不会因为记不住而
特别注意,不要为了偷懒而在办公,网吧,旅
参考:
[1] Security Simplified: The Base+Suffix Method for Memorable Strong Passwords; Thursday, February 19th, 2009; http://luxsci.com/bl
[2] Cracking Passwords in the Cloud: Insights on Password Policies; THURSDAY, OCTOBER 29, 2009; http://news.electric
[3] Master Password Encryption in FireFox and Thunderbird; Friday, February 27th, 2009; http://luxsci.com/bl
[4] SniffPass v1.12 - Password Monitoring Software; http://www.nirsoft.n
[5] Mail PassView - Recover POP3/IMAP/SMTP email passwords; http://www.nirsoft.n
[6] Dialupass - Recover VPN/RAS/Dialup passwords; http://www.nirsoft.n
[7] Five Best Password Managers; http://lifehacker.co
[8] gmail 安全检查步骤
http://3.ly/fTFs = https://docs.google. com/View?id=d9bwjsf_ 14fb6wj6hb
http://3.ly/FQFR = https://www.google.c om/buzz/104802289453 542970648/FV7eH2WUfw X/
http://is.gd/bYh7q = https://www.google.c om/buzz/104802289453 542970648/FV7eH2WUfw X/ [9] 邮件安全提示 http://3.ly/rM9S = https://www.google.c om/buzz/104802289453 542970648/3p9eht8utU B/
[10] virushuo: 匿名网民的安全指南 https://www.google.c om/buzz/changsimeng/ YCJVddVvqK2/
匿名网民的安全指南(1) https://www.google.c om/buzz/100347718699 709543053/hu1cGmnAnG x/
匿名网民的安全指南(2) https://www.google.c om/buzz/100347718699 709543053/1kGBjJ1Jw5 c/
[11] wxzbb: 平民技术,检查你的Google账户安全! https://www.google.c om/buzz/104802289453 542970648/fkFF6amKXD k/
[12] 你以为电信,联通他们就不偷你的密码么? https://www.google.c om/buzz/changsimeng/ 4NG96qtRbH5/
[13] 防范 邮件钓鱼欺诈窃取密码 https://www.google.c om/buzz/changsimeng/ 8V51WoevTpo/
[14] Internet 安全建议 https://www.google.c om/buzz/104802289453 542970648/Fk7AsXcV2J i/
http://3.ly/fTFs = https://docs.google.
http://3.ly/FQFR = https://www.google.c
http://is.gd/bYh7q = https://www.google.c
[10] virushuo: 匿名网民的安全指南 https://www.google.c
匿名网民的安全指南(1) https://www.google.c
匿名网民的安全指南(2) https://www.google.c
[11] wxzbb: 平民技术,检查你的Google账户安全! https://www.google.c
[12] 你以为电信,联通他们就不偷你的密码么? https://www.google.c
[13] 防范 邮件钓鱼欺诈窃取密码 https://www.google.c
[14] Internet 安全建议 https://www.google.c
[15] 编程随想:如何防止黑客入侵
https://www.google.c
http://blog.csdn.net
https://www.google.c
http://program-think
http://blog.csdn.net
http://program-think
http://blog.csdn.net
http://program-think
http://blog.csdn.net
https://www.google.c
https://www.google.c
http://program-think
http://blog.csdn.net
https://www.google.c
http://program-think
http://blog.csdn.net
http://program-think
http://program-think
http://program-think
http://blog.csdn.net
[17] 编程随想:如何隐藏你的踪迹,避免跨省追捕
https://www.google.c
http://program-think
http://program-think
http://program-think
http://program-think
http://program-think
http://program-think
http://program-think
http://program-think
[18] 编程随想:信息安全之社会工程学; https://www.google.c
http://program-think
http://blog.csdn.net
http://program-think
http://blog.csdn.net
http://program-think
http://blog.csdn.net
http://program-think
http://blog.csdn.net
http://program-think
http://blog.csdn.net
http://program-think
http://blog.csdn.net
Permalink | Leave a comment »
有 1 个人转发了此项 - Orange He
有 36 个人顶了此项 - Akon Wang, Alan Zhang, Atqiorlin CH, Birdy Pandy和D Donnern和还有 31 人
Simeng Chang - 网络安全指南 一个好的密码策略 http://goo.gl/78YL4
确 定 Gmail 是否安全的方法 http://goo.gl/Pet2E http://goo.gl/8Vdxl
gmail 安全检查步骤 http://3.ly/fTFs http://goo.gl/6kn15
邮 件安全提示 http://3.ly/rM9S = https://profiles.goo gle.com/104802289453 542970648/posts/3p9e ht8utUB
附件内文件名伪装欺诈 http://goo.gl/YEYqB
网 络安全指南 如何检查自己帐号的异常登录 防范网狗破解 gmail 帐号 https://profiles.goo gle.com/111763901051 622023220/posts/PzVe fcyuRFt
网络通信安全指南 http://goo.gl/onbkL
协 作编写几个网络安全指南小册子 http://goo.gl/UDWea
网 狗无处不在 skype 聊天安全指南 https://profiles.goo gle.com/111763901051 622023220/posts/1Qpb kvsPkwX
确
gmail 安全检查步骤 http://3.ly/fTFs http://goo.gl/6kn15
邮
附件内文件名伪装欺诈 http://goo.gl/YEYqB
网
网络通信安全指南 http://goo.gl/onbkL
协
网
没有评论:
发表评论