Thursday, February 5, 2009
This Week's Sign That The Muchacolypse is Upon Me
I've concluded that online social networks are the cloud computing version of friends, i.e. virtualized versions of prior generation social contacts, where you fulfill 80% of your need for friends with abstract slices of a vaguely-understood cloud of peopletime. Not that there's anything wrong with that. Bowling night changes, sure, as the beer isn't as tasty. But the music is better.
Wednesday, February 4, 2009
A Low Moment in the History of Self-Reference
Note that the Security Question section of my profile on the acm.org web site will not let you enter "What is my Security Question?" as your Security Question in conjunction with an answer of "What is my Security Question?" presumably because user names and passwords should not be identical. I gently question the validity of that presumption, since this isn't supposed to be a username and password.
Your Security Question/Answer are at risk to (in highest-lowest order of my estimation of probability):
Your Security Question/Answer are at risk to (in highest-lowest order of my estimation of probability):
- Using Q/A pairs that are answerable via the public domain, e.g. What is your mother's maiden name? My Goofy Q/A is in this sense more secure than many more common formulations (at least it was until I published this vignette on the Internet under my name, etc, unless of course this whole post is part of an elaborate honey pot trap, including my exposure of the existence of said elaborate honey pot);
- Technical attacks against the client and server to recover/intercept the same information. My Goofy Q/A is as secure as any other Q/A in this regard;
- Brute forcing of Q and A, whether bit by bit or variants like word by word. Haven't tested whether sites like acm.org protect against this. There is presumably some set of Q/A questions - let's call them Armoured Goofy - that is more resistant to brute forcing than My Goofy Q/A, e.g. "What is the absolutely longest, highest entropy, m0st ^b!i^z(a_r(r@e #$@#$#@ Security Question ... I can construct?" followed by "longest possible combination of a highest entropy bizarreness I can construct as an answer". But I'm not going there.
Subscribe to:
Posts (Atom)