Become a fan of Slashdot on Facebook

 



Forgot your password?
typodupeerror
×
Encryption

Generate Memorizable Passphrases That Even the NSA Can't Guess 267

HughPickens.com writes Micah Lee writes at The Intercept that coming up with a good passphrase by just thinking of one is incredibly hard, and if your adversary really is capable of one trillion guesses per second, you'll probably do a bad job of it. It turns out humans are a species of patterns, and they are incapable of doing anything in a truly random fashion. But there is a method for generating passphrases that are both impossible for even the most powerful attackers to guess, yet very possible for humans to memorize. First, grab a copy of the Diceware word list, which contains 7,776 English words — 37 pages for those of you printing at home. You'll notice that next to each word is a five-digit number, with each digit being between 1 and 6. Now grab some six-sided dice (yes, actual real physical dice), and roll them several times, writing down the numbers that you get. You'll need a total of five dice rolls to come up with each word in your passphrase. Using Diceware, you end up with passphrases that look like "cap liz donna demon self", "bang vivo thread duct knob train", and "brig alert rope welsh foss rang orb". If you want a stronger passphrase you can use more words; if a weaker passphrase is ok for your purpose you can use less words. If you choose two words for your passphrase, there are 60,466,176 different potential passphrases. A five-word passphrase would be cracked in just under six months and a six-word passphrase would take 3,505 years, on average, at a trillion guesses a second.

After you've generated your passphrase, the next step is to commit it to memory.You should write your new passphrase down on a piece of paper and carry it with you for as long as you need. Each time you need to type it, try typing it from memory first, but look at the paper if you need to. Assuming you type it a couple times a day, it shouldn't take more than two or three days before you no longer need the paper, at which point you should destroy it. "Simple, random passphrases, in other words, are just as good at protecting the next whistleblowing spy as they are at securing your laptop," concludes Lee. "It's a shame that we live in a world where ordinary citizens need that level of protection, but as long as we do, the Diceware system makes it possible to get CIA-level protection without going through black ops training."
Technology

The Internet of Things Just Found Your Lost Wallet 108

Nerval's Lobster writes Ever forgotten your wallet in a coffee shop or restaurant? Now there's a way to ensure it'll never happen again: Woolet, which its creators bill as a "smart wallet." It features a rechargeable battery, Bluetooth support, and the ability to synchronize with a smartphone app; if you walk 20-85 feet away from your wallet, the app will make a sound and guide you back to it. The platform's being financed on Kickstarter, and attracted attention from TechCrunch and some other places, but it begs the question: is this yet another example of connected devices run amok—shiny and interesting as a concept but not nearly useful enough for the population at large? What would it take for a connected device, whether a wallet or a smoke detector, to gain mass appeal?

Comment False savings (Score 1) 328

Yes, LEDs are far more efficient and use less electricity yada yada. However, it's pretty much guaranteed that this will not lead to cost savings.
Historically, every time a cheaper lighting technology came along, from candles to oil lamps to gas lamps to Edison bulbs to CFLs, people simply increase the amount of lighting and the length of time (into the night) that they keep the house lit up. I see nothing to suggest that conversion to LEDs will change this trend.

Patents

Has the Supreme Court Made Patent Reform Legislation Unnecessary? 99

An anonymous reader writes: As Congress gears up again to seriously consider patent litigation abuse—starting with the introduction of H.R. 9 (the "Innovation Act") last month—opponents of reform are arguing that recent Supreme Court cases have addressed concerns. Give the decisions time to work their way through the system, they assert. A recent hearing on the subject before a U.S. House Judiciary Committee (HJC) Subcommittee shined some light on the matter. And, as HJC Chairman Bob Goodlatte, a long-time leader in Internet and intellectual property issues, put it succinctly in his opening remarks: "We've heard this before, and though I believe that the Court has taken several positive steps in the right direction, their decisions can't take the place of a clear, updated and modernized statute. In fact, many of the provisions in the Innovation Act do not necessarily lend themselves to being solved by case law, but by actual law—Congressional legislation."
AI

Machine Intelligence and Religion 531

itwbennett writes: Earlier this month Reverend Dr. Christopher J. Benek raised eyebrows on the Internet by stating his belief that Christians should seek to convert Artificial Intelligences to Christianity if and when they become autonomous. Of course that's assuming that robots are born atheists, not to mention that there's still a vast difference between what it means to be autonomous and what it means to be human. On the other hand, suppose someone did endow a strong AI with emotion – encoded, say, as a strong preference for one type of experience over another, coupled with the option to subordinate reasoning to that preference upon occasion or according to pattern. what ramifications could that have for algorithmic decision making?

Slashdot Top Deals

THEGODDESSOFTHENETHASTWISTINGFINGERSANDHERVOICEISLIKEAJAVELININTHENIGHTDUDE

Working...