@brampatelski
brampatelski
How do things....
Tips?
Change often
Long (8+)
Unique
Remember
Don't write down
UPPERCASE
Complex
l33tsp34k
P@ssw0rd
* Checks all boxes
3 positions
10 options
10 positions
3 options
10
3
10
3
= 1000
= 59049
Make your passwords looooooooonnnngggg
80+ accounts? Complex password rules? Good luck
with random pw-generator:
My superl33t complex unique PW leaked out
* Broken
HASH
HASH
super-secret-app-key
ENCRYPT
* Not this one
This one:
Becomes...
APT-names:
APT-names:
* Link
Mostly script kiddies
SELECT * FROM users
WHERE user = '$USR'
AND password = '$PWD';
SELECT * FROM users
WHERE user = 'bram'
AND password = 'qwerty';
bram
qwerty
SELECT * FROM users
WHERE user = '$USR'
AND password = '$PWD';
SELECT * FROM users
WHERE user = '' or true--'
AND password = 'qwerty';
' or true--
<empty>
SELECT * FROM users
WHERE user = '' or true--
SELECT * FROM users
WHERE user = '$USR'
AND password = '$PWD';
SELECT * FROM users
WHERE user = 'sinead o'connor'
AND password = '';
sinead o'connor
<empty>
A = g mod p
B = g mod p
S = B mod p
S = A mod p
a
a
b
b