PaddleWise by thread

From: Kirk Olsen <kork4_at_cluemail.com>
subject: [Paddlewise] Unsolicited email.
Date: Tue, 21 Sep 2010 08:04:59 -0400
There's been a fair bit of spam lately.

I'm seeing 2 sources.

Source 1 is someone is sending to addresses used on paddlewise.  I've
contacted the senders ISP, with any luck that address will be monitored
and the company will be nuked.  This is strictly not allowed by the
terms of subscribing to paddlewise, if I can figure out the underlying
subscription I'll terminate that subscriber.  I've already added their
firm to the list of banned paddlewise content.

Source 2 is from cracked hotmail/aol/yahoo accounts.  If you have a
simple password please turn it into a real password

Syracuse university looks to have decent directions on how to make an
easy to remember hard to crack password
http://its.syr.edu/accounts/psswdsug.cfm  

My preference is for using the first letter of each word from a
phrase/song/poem - with some numbers to replace letters or words.

Kirk
-- 
  Kirk Olsen
***************************************************************************
PaddleWise Paddling Mailing List - Any opinions or suggestions expressed
here are solely those of the writer(s). You must assume the entire
responsibility for reliance upon them. All postings copyright the author.
Submissions:     PaddleWise_at_PaddleWise.net
Subscriptions:   PaddleWise-request_at_PaddleWise.net
Website:         http://www.paddlewise.net/
***************************************************************************
From: Craig Jungers <crjungers_at_gmail.com>
subject: Re: [Paddlewise] Unsolicited email.
Date: Tue, 21 Sep 2010 07:40:18 -0700
On Tue, Sep 21, 2010 at 5:04 AM, Kirk Olsen <kork4_at_cluemail.com> wrote:

>
> My preference is for using the first letter of each word from a
> phrase/song/poem - with some numbers to replace letters or words.
>
> A method I learned when working for an unmentionable government agency is
to pick two consonants that do not normally appear in (most) western
vocabularies, add four or five letters of a word that means something to
you, and then a number (like current year or your birth year).

For instance:  BDsword10 or ZCjulia76

The advantage to this method is that it's only necessary to remember the two
consonants... the rest you probably already know. It also generally defeats
dictionary cracks. Unless it gets really popular; in which case someone can
design a crack that takes this method into account. I usually pick the
consonants by looking around the area and choosing two at random.

Additional protection can be had by adding some punctuation (like a comma
before the numbers).

One problem with complicated passwords is that they are so difficult to
remember that users are forced to write them down somewhere. I've seen them
taped to the monitor, written on a scrap of paper that is taped to the
inside of a desk drawer (just open it to see the password). Dictionary
cracks are remarkably effective against the passwords so many people choose.
Usually they are the names of pets, kids, spouses, parents, etc. Using my
method you can still use those names... you just have to disguise them in a
packet.

Craig Jungers
Moses Lake, WA
www.nwkayaking.net
***************************************************************************
PaddleWise Paddling Mailing List - Any opinions or suggestions expressed
here are solely those of the writer(s). You must assume the entire
responsibility for reliance upon them. All postings copyright the author.
Submissions:     PaddleWise_at_PaddleWise.net
Subscriptions:   PaddleWise-request_at_PaddleWise.net
Website:         http://www.paddlewise.net/
***************************************************************************
From: Nick Schade <nick_at_guillemot-kayaks.com>
subject: Re: [Paddlewise] Unsolicited email.
Date: Tue, 21 Sep 2010 12:47:39 -0400
An alternative look at the password issue: http://www.nytimes.com/2010/09/05/business/05digi.html

This not to say that you should keep your password as "password", but making your password "Xp2K&qM" is probably not needed "NDKexplorer" would probably be fine.

On Sep 21, 2010, at 8:04 AM, Kirk Olsen wrote:

> Source 2 is from cracked hotmail/aol/yahoo accounts.  If you have a
> simple password please turn it into a real password
> 

Nick Schade

Guillemot Kayaks
54 South Rd
Groton, CT 06340
USA
Ph/Fx: (860) 659-8847
http://www.guillemot-kayaks.com/
***************************************************************************
PaddleWise Paddling Mailing List - Any opinions or suggestions expressed
here are solely those of the writer(s). You must assume the entire
responsibility for reliance upon them. All postings copyright the author.
Submissions:     PaddleWise_at_PaddleWise.net
Subscriptions:   PaddleWise-request_at_PaddleWise.net
Website:         http://www.paddlewise.net/
***************************************************************************

This archive was generated by hypermail 2.4.0 : Thu Aug 21 2025 - 16:33:54 PDT