<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Thejesh GN &#187; security</title>
	<atom:link href="http://thejeshgn.com/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://thejeshgn.com</link>
	<description>A Blog, A Website and A container for all my views with excerpts from technology, travel, films, india, photography, kannada, friends and other interests. I am Thejesh GN. Friends call me Thej</description>
	<lastBuildDate>Thu, 09 Sep 2010 21:07:12 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>RTPM &#8211; Real Time Productivity Monitor</title>
		<link>http://thejeshgn.com/2009/01/07/rtpm-real-time-productivity-monitor/</link>
		<comments>http://thejeshgn.com/2009/01/07/rtpm-real-time-productivity-monitor/#comments</comments>
		<pubDate>Wed, 07 Jan 2009 08:34:09 +0000</pubDate>
		<dc:creator>Thejesh GN</dc:creator>
				<category><![CDATA[Life]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Geek-Fun]]></category>
		<category><![CDATA[India]]></category>
		<category><![CDATA[IT-Industry]]></category>
		<category><![CDATA[productivity]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://thejeshgn.com/?p=504</guid>
		<description><![CDATA[RTPMTM &#8211; Real Time Productivity MonitorPP is productivity monitoring tool which runs on your resources computer to monitor the productivity. It helps your resources to see their RTPITM Real Time Productivity IndexPP so that they can increase their productivity index.It keeps track of the productive work and helps you in estimating cost, average RTPI etc. [...]]]></description>
			<content:encoded><![CDATA[<p><img style="float:left;border: solid 10px white" src="http://media.thejeshgn.com/img/blogging/RTPM.gif" alt="" />RTPM<sup>TM</sup> &#8211; Real Time Productivity Monitor<sup>PP</sup> is productivity monitoring tool which runs on your resources computer to monitor the productivity. It helps your resources to see their RTPI<sup>TM</sup> Real Time Productivity Index<sup>PP</sup> so that they can increase their productivity index.It keeps track of the productive work and helps you in estimating cost, average RTPI etc.  Below are some features of the application.<span id="more-504"></span><br />
<strong>Features</strong><br />
1. It runs on all Windows Machines in background.<br />
2. It keeps track of the software used by the resource<br />
3. It categorizes the software used into productive and non productive software. Using this categorization we can calculate the effort.<br />
4. It monitors the keyboard, mouse and hard disk usage while calculating the productive time.<br />
5. It can distributed (auto installed) on your resources computer using any existing methods.<br />
6. There is an option to Quarantine  (<br />
u need admin to unlock) if the RTPI goes below specific level and its real time.<br />
7. It monitors the mails,IM messages, word, excel including your IDE contents. The system includes a centralized server with adequate AI to decide if the message/content is productive/non-productive. Hence the time spent on non productive messages will not be used in RTPI calculation.<br />
8. When monitoring the browsers it can even log up to the level of websites. The centralized server determines if the website productive or non productive.<br />
9. All the monitored data gets uploaded into centralized server for enterprise level calculation.<br />
10. Comes with a powerful reporting engine for any kind of monitoring report you want.<br />
11. It has a centralized server (web service) which has the software category information.</p>
<p><strong>Technical Details:</strong><br />
1. Uses windows API and .Net for client side technologies<br />
2. Uses webservices to communicate with centralized service<br />
3. Server side components are built in Java and Other open source  components. It will bring down the deployment costs.</p>
<p><strong>Business Model:</strong><br />
1. License fee for each of the deployment ( $1 for a machine)<br />
2. Access fee to the centralized sever ( similar to Amazon Web Services) $1/1000req<br />
3. Maintenance and support</p>
<p><strong>Next step:</strong><br />
1. Now start coding&#8230;<br />
2. Find MBA to write business proposal and to find a VC.<br />
3. Find a KPO or IP lawyer for patenting the algo<br />
4. Find a sales guy to market<br />
5. Find a banker to go IPO<br />
6  Make an Exit plan<br />
7. Sell the company</p>
<p>PP: Patent Pending</p>
<p><strong>Trigger :</strong></p>
<p><a href="http://en.wikipedia.org/wiki/Recession">Recession</a>. It looks like every company on earth wants to increase the productivity by hook or crook. If products like <a href="http://en.wikipedia.org/wiki/Websense">this</a> can find a market then why not RTPM?</p>
]]></content:encoded>
			<wfw:commentRss>http://thejeshgn.com/2009/01/07/rtpm-real-time-productivity-monitor/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>oAuth Explained With An Example</title>
		<link>http://thejeshgn.com/2008/07/02/oauth-explained-with-an-example/</link>
		<comments>http://thejeshgn.com/2008/07/02/oauth-explained-with-an-example/#comments</comments>
		<pubDate>Wed, 02 Jul 2008 08:58:48 +0000</pubDate>
		<dc:creator>Thejesh GN</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[OAuth]]></category>
		<category><![CDATA[protocol]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Web]]></category>

		<guid isPermaLink="false">http://thejeshgn.com/?p=411</guid>
		<description><![CDATA[The problem with using more and more social networks is with every social network you join you need to create profile then invite friends. There is no way to carry your data from one network to another network with out a hitch. Few smart people have already started working on this issue of DataPortability in [...]]]></description>
			<content:encoded><![CDATA[<p>The problem with using more and more social networks is with every social network you join you need to create profile then invite friends. There is no way to carry your data from one network to another network with out a hitch. Few smart people have already started working on this issue of <a href="http://dataportability.org">DataPortability</a> in detail. So lets not worry about it.<br />
In the mean time few web apps have given users an opportunity to share the data. Take an example of adding all your Gmail contacts into Orkut. Login to Orkut and then enter your gmail id/password to invite all your contacts. This seems OK since both Gmail and Orkut is owned by the same company. Your id/password *does not* leave Google.<br />
<img src="http://media.thejeshgn.com/img/screenshot/oauth-case-of-linkedin.png" alt="Linked in sharing contacts" /><br />
Where as the same model is used by <a href="http://linkedin.com">LinkedIn</a> to add your professional contacts. You need to give your userid/pw details of gmail/hotmail to add the contacts. This doesn&#8217;t seem OK even with their promise of privacy and purpose.</p>
<p><strong>Now how would you achieve this with out sharing the credentials?</strong><br />
<span id="more-411"></span><br />
<strong><a href="http://oauth.net">oAuth</a></strong><br />
An open protocol to allow secure API authentication in a simple and standard method from desktop and web applications. oAuth is not not a new concept. It is similar to your Google AuthSub, AOL OpenAuth, Yahoo BBAuth, Upcoming API, Flickr API, Amazon Web Services API but more open and not proprietary.</p>
<p><strong>How is it more safe?</strong><br />
Think you are a <a href="http://www.couchsurfing.com/people/thej">couchsurfer</a> and you have a guest at home. You feel good to have a guest at home and you want him to enjoy his stay. Since your and your guests timings are not matching you like to give him key of your home. So he can manage when you are not around.But this key is a special key and not your regular (master key) key. With this key your guest can enter your home and kitchen but not your bedroom. oAuth works on similar principles.</p>
<p><strong>How does oAuth work ?</strong><br />
Lets not get into dry details of protocol. Lets see how the protocol works with an example flow. The case study includes <a href="http://en.wikipedia.org/wiki/Social_bookmarking">social bookmarking</a> sites <a href="http://ma.gnolia.com/">magnolia</a> and <a href="http://del.icio.us">delicious</a>. Their interaction with <a href="http://www.nsyght.com/">Nsyght</a>.</p>
<p>Nsyght pulls your bookmarks from your delicious and magnolia accounts and creates a search engine out of it. To pull the bookmarks on daily basis it needs to log into your magnolia/delicious account. For which you either need to share the credentials or implement oAuth. Lets see how its done.</p>
<p>Delioious doesn&#8217;t implement oAuth hence for Nsyght to pull your bookmarks it needs your userid/pw. Nsyght stores your userid/pw for future use.<br />
<img src="http://media.thejeshgn.com/img/screenshot/oauth-nsyght-delicious.png" border="1" alt="Authorize  delicious" /></p>
<p>Lets see how ma.gnolia does this. Magnolia has oAuth implemented. At Nsyght just click authorize.<br />
<img src="http://media.thejeshgn.com/img/screenshot/oauth-nsyght-magnolia.png" alt="Authorize ma.gnolia" /><br />
Here magnolia is the service provider and Nsyght is the consumer. Nsyght sends a request to magnolia to authorize the request.<br />
<img src="http://media.thejeshgn.com/img/screenshot/oauth-magnolia-login.png" alt="Login to ma.gnolia" /><br />
Magnolia will force you to login. Ma.gnolia uses another standard <a href="http://openid.net">OpenId for login</a> feature. Once you login to magnolia using correct userid/pw then it will take you to authorize page.<br />
<img src="http://media.thejeshgn.com/img/screenshot/oauth-magnolia-oauth-req.png" alt="Authorize at ma.gnolia" /><br />
Where you can authorize Nsyght to access the your magnolia bookmarks. Once done it returns to Nsyght.<br />
Now at Nsyght you can see that your Nysght account as been authorized to access your magnolia bookmarks. And your Nsyght account doesnt need any other details for accessing your magnolia accounts.<br />
<img src="http://media.thejeshgn.com/img/screenshot/oauth-nsyght-magnolia-done.png" alt="Login to ma.gnolia" /></p>
<p>For a developer this is more complex. The oAuth protocol exchanges oAuth keys for authorization between the service provider and consumer. Where consumer can have limited access to the resources using oAuth access keys. If you are a developer you need to read <a href="http://oauth.net/core/1.0/">oAuth Spec</a> to get more details or wait for my next blog post.</p>
]]></content:encoded>
			<wfw:commentRss>http://thejeshgn.com/2008/07/02/oauth-explained-with-an-example/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>What is open id?</title>
		<link>http://thejeshgn.com/2007/06/21/what-is-open-id/</link>
		<comments>http://thejeshgn.com/2007/06/21/what-is-open-id/#comments</comments>
		<pubDate>Thu, 21 Jun 2007 08:08:00 +0000</pubDate>
		<dc:creator>Thejesh GN</dc:creator>
				<category><![CDATA[Life]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[Online]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://thejeshgn.com/2007/06/21/what-is-open-id/</guid>
		<description><![CDATA[Here is very good presentation by Simon about OpenId. It explains everything about OpenId a common user should know. Its big but very simple and direct. This post is from On/Off Tips which is a member blog of TechMag Blog Group. All rights are reserved.]]></description>
			<content:encoded><![CDATA[<p>Here is very good presentation by <a href="http://simonwillison.net/">Simon </a>about OpenId. It explains everything about OpenId a common user should know. Its big but very simple and direct.<br /><object type="application/x-shockwave-flash" data="https://s3.amazonaws.com:443/slideshare/ssplayer.swf?id=51151&#038;doc=the-implications-of-openid-28758" width="425" height="348"><param name="movie" value="https://s3.amazonaws.com:443/slideshare/ssplayer.swf?id=51151&#038;doc=the-implications-of-openid-28758" /></object>
<div class="blogger-post-footer">This post is from <a href="http://www.onofftips.com">On/Off Tips</a> which is a member blog of <a href="http://www.techmag.biz/techmag_blog_group">TechMag Blog Group</a>. All rights are reserved.</div>
]]></content:encoded>
			<wfw:commentRss>http://thejeshgn.com/2007/06/21/what-is-open-id/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>How to erase sensitive files or delete files permanently</title>
		<link>http://thejeshgn.com/2007/06/18/how-to-erase-sensitive-files-or-delete-files-permanently/</link>
		<comments>http://thejeshgn.com/2007/06/18/how-to-erase-sensitive-files-or-delete-files-permanently/#comments</comments>
		<pubDate>Mon, 18 Jun 2007 08:29:00 +0000</pubDate>
		<dc:creator>Thejesh GN</dc:creator>
				<category><![CDATA[Life]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[tools]]></category>
		<category><![CDATA[Video]]></category>

		<guid isPermaLink="false">http://thejeshgn.com/2007/06/18/how-to-erase-sensitive-files-or-delete-files-permanently/</guid>
		<description><![CDATA[If you want to delete files permanently from your computer. What do you do ? Do you use shift + del? Well shift delete does not erase the file from your hard disk. It just removes the file from file table hence your OS can&#8217;t find it. But the data is still there on the [...]]]></description>
			<content:encoded><![CDATA[<p>If you want to delete files permanently from your computer. What do you do ? Do you use shift + del? Well shift delete does not erase the file from your hard disk. It just removes the file from file table hence your OS can&#8217;t find it. But the data is still there on the disk. The best method to remove sensitive data is to erase using <a href="http://www.heidi.ie/eraser/">eraser</a>.</p>
<p><span style="font-weight:bold;">What is eraser?</span><br />Eraser is an advanced security tool (for Windows), which allows you to completely remove sensitive data from your hard drive by overwriting it several times with carefully selected patterns. Works with Windows  95, 98, ME, NT, 2000, XP, Windows 2003 Server and DOS<span style="font-weight:italic;">.Eraser is Free software and its source code is released under GNU General Public License.</span><br />The patterns used for overwriting are based on Peter Gutmann&#8217;s paper &#8220;Secure Deletion of Data from Magnetic and Solid-State Memory&#8221; and they are selected to effectively remove magnetic remnants from the hard drive.<br />Other methods include the one defined in the National Industrial Security Program Operating Manual of the US Department of Defence and overwriting with pseudorandom data. You can also define your own overwriting methods.</p>
<p><a href="http://www.heidi.ie/eraser/">Download Eraser</a> | <a href="http://www.heidi.ie/eraser/faq.php">FAQ on Eraser</p>
<p></a><object width="425" height="350"><param name="movie" value="http://www.youtube.com/v/LE9Ljrp2FN8"></param><param name="wmode" value="transparent"></param><embed src="http://www.youtube.com/v/LE9Ljrp2FN8" type="application/x-shockwave-flash" wmode="transparent" width="425" height="350"></embed></object>
<div class="blogger-post-footer">This post is from <a href="http://www.onofftips.com">On/Off Tips</a> which is a member blog of <a href="http://www.techmag.biz/techmag_blog_group">TechMag Blog Group</a>. All rights are reserved.</div>
]]></content:encoded>
			<wfw:commentRss>http://thejeshgn.com/2007/06/18/how-to-erase-sensitive-files-or-delete-files-permanently/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Openid problem with delegation</title>
		<link>http://thejeshgn.com/2007/06/14/openid-problem-with-delegation/</link>
		<comments>http://thejeshgn.com/2007/06/14/openid-problem-with-delegation/#comments</comments>
		<pubDate>Fri, 15 Jun 2007 04:37:59 +0000</pubDate>
		<dc:creator>Thejesh GN</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[openid]]></category>
		<category><![CDATA[protocol]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.thejeshgn.com/2007/06/14/openid-problem-with-delegation/</guid>
		<description><![CDATA[I have openid from myopenid.com . The open id url is thejeshgn.myopenid.com. I use delegation and use thejeshgn.com as the open id url. But something going wrong today. I am not able to login to few of my regular services like http://www.dopplr.com/openid http://ma.gnolia.com/signin http://jyte.com/auth/login But I am able to login to some other services like [...]]]></description>
			<content:encoded><![CDATA[<p>I have openid from <a href="http://myopenid.com">myopenid.com </a> . The open id url is thejeshgn.myopenid.com. I use delegation and use thejeshgn.com as the open id url.  But something  going wrong today. I am not able to login to few of my regular services like<br />
<a href="http://www.dopplr.com/openid">http://www.dopplr.com/openid</a><br />
<a href="http://ma.gnolia.com/signin">http://ma.gnolia.com/signin</a><br />
<a href="http://jyte.com/auth/login">http://jyte.com/auth/login</a></p>
<p>But I am able to login to some other services like<br />
<a href="http://livejournal.com">livejournal.com</a><br />
productwiki, and few self hosted wordpress blogs.</p>
<p>When I try to login to first set of sites. It does not even take me to myopenid.com login page. The error usually I get is timeout or open idserver does not exist. Which means the consumer is failing to read the delegation info. Is anybody facing the same problem?</p>
<p>Example error from Jyte &#8221; Connection timed out attempting to contact your OpenID server&#8221;<br />
There are more updates below:<br />
<span id="more-56"></span><br />
<strong>Update1: </strong>Since morning it was not working. Strangely it started working now. Any idea?<br />
<strong>Update2: </strong>Logged off and tried to login to Jyte again. Now I am not able to. Its very strange.<br />
<strong>Update3: </strong> I got replies from all (jyte,ma.gnolia,claimid). It was problem with my header setting. One of the setting earlier as said by <a href="https://www.myopenid.com/help#own_domain">myopenid help</a> section was<br />
<code> &lt;meta http-equiv="X-XRDS-Location"<br />
content="http://www.myopenid.com/xrds?username=youraccount.myopenid.com" /&gt;<br />
Changed now to<br />
&lt;meta http-equiv="X-XRDS-Location" content="http://yoururl.myopenid.com/xrds"&gt;</code><br />
Thanks to Brain from Jainrain for this help. Probaly they need to update that help section.<br />
<strong>Update4 [Thursday, June 14, 2007 at 05:42:05 GMT]: </strong>No its something beyond that. As usual the new solution works with live journal and doesnot always work with other sites like Jyte or ma.gnolia.<br />
<strong>Update5:</strong> Sometime in the after noon I was able to login. But now I am not able to. But I am still able to login to livejournal and wikitravel. Is it because they have a different type of implementation?<br />
<strong>Updare6 [Thursday, June 14, 2007 at 10:26:05 GMT]:</strong> Is it the problem with my wordpress implementation? the same meta and link headers I have on <a href="http://www.techmag.biz">techmag.biz</a> ; from there I am able to login in. my wordpress could be the problem?<br />
<strong>Updare8 [Thursday, June 14, 2007 at 11:00:05 GMT]:</strong> A little debugging tells me that its actually problem with the wordpress but the problem with my Theme. When I use the default theme it works well. But when I use SouthRiver theme. It does not work. So I will continue taking that as my starting point.</p>
<p><strong>Updare7[Thursday, June 14, 2007 at 13:00:05 GMT]:</strong>I did some debugging. Now I am almost confirmed that <a href="http://themes.wordpress.net/columns/3-columns/3309/southriver-10/">SouthRiver theme</a> is responsible for it. But I love this theme. I am keeping it. I need to run this theme locally on my laptop to see what exactly is wrong</p>
<p class="techtags"><img id="image108" src="http://www.eventsbangalore.net/wp-content/uploads/2006/06/tn.jpg" alt="tn.jpg" width="20" height="20" /> <a rel="tag" href="http://technorati.com/tag/openid">openid</a> <a rel="tag" href="http://technorati.com/tag/openid+problem">openid problem</a> <a rel="tag" href="http://technorati.com/tag/myopenid">myopenid</a><a rel="tag" href="http://technorati.com/tag/southriver%20">SouthRiver </a><a rel="tag" href="http://technorati.com/tag/wordpress">wordpress</a></p>
]]></content:encoded>
			<wfw:commentRss>http://thejeshgn.com/2007/06/14/openid-problem-with-delegation/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>How to store passwords</title>
		<link>http://thejeshgn.com/2007/06/14/how-to-store-passwords/</link>
		<comments>http://thejeshgn.com/2007/06/14/how-to-store-passwords/#comments</comments>
		<pubDate>Thu, 14 Jun 2007 08:30:00 +0000</pubDate>
		<dc:creator>Thejesh GN</dc:creator>
				<category><![CDATA[Life]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[Online]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[tools]]></category>
		<category><![CDATA[Video]]></category>

		<guid isPermaLink="false">http://thejeshgn.com/2007/06/14/how-to-store-passwords/</guid>
		<description><![CDATA[Chris talks about storing the passwords. He introduces to online password service called passpack. The passpack service is free. It uses AES encryption algorithm to store your passwords on their server.It has many other features like anti phishing etc.If you want to store your passwords online then this could be a good place.Follow their blog [...]]]></description>
			<content:encoded><![CDATA[<p>Chris talks about storing the passwords. He introduces to online password service called <a href="https://www.passpack.com/info/home/">passpack</a>.  The passpack service is free. It uses AES encryption algorithm to store your passwords on their server.It has many other <a href="https://www.passpack.com/info/tour/#faq">features</a> like anti phishing etc.If you want to store your passwords online then this could be a good place.Follow their <a href="http://passpack.wordpress.com/">blog </a>to get more info on passpak and in general secure passwords.<br /><object width="425" height="350"><param name="movie" value="http://www.youtube.com/v/aGNNaViB1LQ"></param><param name="wmode" value="transparent"></param><embed src="http://www.youtube.com/v/aGNNaViB1LQ" type="application/x-shockwave-flash" wmode="transparent" width="425" height="350"></embed></object>
<div class="blogger-post-footer">This post is from <a href="http://www.onofftips.com">On/Off Tips</a> which is a member blog of <a href="http://www.techmag.biz/techmag_blog_group">TechMag Blog Group</a>. All rights are reserved.</div>
]]></content:encoded>
			<wfw:commentRss>http://thejeshgn.com/2007/06/14/how-to-store-passwords/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to choose passwords</title>
		<link>http://thejeshgn.com/2007/04/16/how-to-choose-passwords/</link>
		<comments>http://thejeshgn.com/2007/04/16/how-to-choose-passwords/#comments</comments>
		<pubDate>Mon, 16 Apr 2007 15:52:00 +0000</pubDate>
		<dc:creator>Thejesh GN</dc:creator>
				<category><![CDATA[Life]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://thejeshgn.com/2007/04/16/how-to-choose-passwords/</guid>
		<description><![CDATA[Nowadays people are more online than ever before. Internet is as important as your mobile phone today. We are the &#8220;connected humans&#8221; of the 21st century. One of the basic aspects of being online is the &#8216;username&#8217; &#038; &#8216;password&#8217; funda. This aspect has been around almost as long as computers themselves. So I decided to [...]]]></description>
			<content:encoded><![CDATA[<p>Nowadays people are more online than ever before. Internet is as important as your mobile phone today. We are the &#8220;connected humans&#8221; of the 21st century. One of the basic aspects of being online is the &#8216;username&#8217; &#038; &#8216;password&#8217; funda. This aspect has been around almost as long as computers themselves. So I decided to start my blog by talking about passwords. I&#8217;ll be talk about passwords in general, how to create strong passwords (ones that can&#8217;t be easily cracked), and most important of all, remembering them.</p>
<p>Lets face it, most of the time in the name of creating a uncrackable password, we create something that looks straight out of some script from a forgotten civilization. We easily forget such passwords in a couple of days. Finally to avoid going through the &#8220;forgot password&#8221; process, we more or less settle down for simple passwords.</p>
<p>Although nowadays we have alternate ways of logging into our computers (fingerprints, iris scan, etc. ) , getting online still needs a username &amp; password. Websites typically recommend passwords of minimum 8 characters long and contain atleast one upper case letter, one number and one punctuation character. With all this I typically go around creating my passwords are as follows -
<ol>
<li>Pick up some words that have some unique memory associated with it. For example, I have a friend who had named her cat &#8220;Tan Thita&#8221; after the mathematical symbol &#8220;tanθ&#8221;. The fact that a cat was given such a name is what made that memory unique. That&#8217;s one word. Next I pick some word that&#8217;s associated to the first one, like &#8220;feline&#8221;. Notice how I selected a word that&#8217;s strongly attached to the first word. Something like &#8220;purr&#8221; can also e selected but then you have to link &#8220;tan thita&#8221; to &#8220;cat&#8221; to &#8220;purr&#8221; which is a bit longer linkage for me. Now you can again go ahead and select a third word, say, &#8220;dog&#8221;, or we can go ahead with only two words we just selected.</li>
<li>Pick 3 &#8211; 4 characters from each word &#8211; &#8220;Tan&#8221; &#8220;Thi&#8221;, &#8220;Fel&#8221; or &#8220;Feli&#8221;, &#8220;dog&#8221;. Now just concatenate 3 of these words while keeping the starting of each part in uppercase &#8211; &#8220;TanThiFel&#8221; or &#8220;TanFelDog&#8221;&#8230;. the list can go on. If you see the final word that&#8217;s created is already exceeding the minumum size of 8 characters.</li>
<li>Add a number and a punctuation to this word. Or alternately, replace one or two characters with a number and a punctuation. For example &#8220;TanThiFel&#8221; can be changed to &#8220;Tan1ThiFel+&#8221; or &#8220;Ta1ThiFel!&#8221;. If you carefully notice the number and punctuation are somewhat related. In the first word &#8220;Tan1ThiFel+&#8221; the key for number &#8220;1&#8243; is the lefthand-most number in the keyboard and the &#8220;+&#8221; sign is the righthand-most key in the same row. If you take the second word, &#8220;Ta1Thifel!&#8221;, instead of adding &#8220;1&#8243; I replaced &#8220;n&#8221; with &#8220;1&#8243; and added a punctuation character at the last that&#8217;s from the same key as &#8220;1&#8243;.</li>
</ol>
<p> There are a gazillion ways to create strong passwords using simple ideas like these. For me the main motive is that I must be able to remember my passwords while keeping them strong enough to avoid them getting cracked. I typically use 16 character passwords since it is much more difficult to crack them than 8 character ones. If you too want to use 16 character passwords, just extend the password rules to 2 upper case, 2 numbers and 2 punctuation marks instead of one of each.</p>
<p>Happy passwording ;) :D</p>
<p>- Vinay.V
<div class="blogger-post-footer">This post is from <a href="http://www.onofftips.com">On/Off Tips</a> which is a member blog of <a href="http://www.techmag.biz/techmag_blog_group">TechMag Blog Group</a>. All rights are reserved.</div>
]]></content:encoded>
			<wfw:commentRss>http://thejeshgn.com/2007/04/16/how-to-choose-passwords/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
