Mailing Lists: Apple Mailing Lists

Image of Mac OS face in stamp
 
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: SSH authentication failures



Noah Abrahamson wrote:

0) Use a really good password, something like "Ludwig45/entomologist" or even kookier. This might sound crazy, but it's perhaps your strongest defense. If a crazy, complicated password is daunting -- and you're tempted to use something shorter and simpler -- consider writing

Also consider character substitution on a phrase to make it a far more complicated password, taking something like


    jackandjillwentupthehill

can become:

    j@(k@j1llw3nt^th3h1ll

Replacing

    "a"'s with @
    "c"   with (
    "and" with @
    "i"'s with 1 (numeral one)
    "e"'s with 3
    "up"  with ^

Same phrase, just a heck of a lot more complicated to crack it. Also a lot easier to remember for many than just a random kooky password. :)

One of my personal favorites is to use words/phrases from another language and do the above to them. I also tend to not substitute every time, for instance I'd leave the last part as hill to add to the complexity.

(just) this single password on a sticky note and putting it in your wallet or pocketbook. Hard core security freaks hate this, but if you're like me and can't remember things very well (hey, the 90s were rough), it's a acceptable approach. I can deal with the exceptionally remote risk that someone will mug me outside Borders, steal my wallet, guesses correctly that I manage servers, figures out the specific hostname of the specific server at the specific company, figures out the corresponding account name, and then busts into the machine. You can use Keychain.app or a thumbdrive or something, but that may limit which or what type of computer you can use to retrieve the info. Sticky notes in wallets never crash (except when you wash your wallet in laundry).

If you go this route and rely on it be sure to keep a copy locked up in a firesafe somewhere. If your wallet's stolen or you wash it and you suddenly can't get into your server it's going to be a very bad thing. :)


--
Kevin Staggers
Systems & Network Administrator
Roane County Schools
email@hidden

_______________________________________________
Do not post admin requests to the list. They will be ignored.
Macos-x-server mailing list      (email@hidden)
Help/Unsubscribe/Update your Subscription:
http://lists.apple.com/mailman/options/macos-x-server/email@hidden

This email sent to email@hidden
References: 
 >SSH authentication failures (From: Dan Tappin <email@hidden>)
 >Re: SSH authentication failures (From: "Philon Terving" <email@hidden>)
 >Re: SSH authentication failures (From: Bill Leonard <email@hidden>)
 >Re: SSH authentication failures (From: Noah Abrahamson <email@hidden>)



Visit the Apple Store online or at retail locations.
1-800-MY-APPLE

Contact Apple | Terms of Use | Privacy Policy

Copyright © 2007 Apple Inc. All rights reserved.