Passwords - how often to change?

General Discussion Started Last reply 26 posts
This could go into the technical section but I think it would create more of a debate here.

There are recommendations on how often we should change passwords. How often do you change yours? I have changed only once at that was after the big security alert by NCSoft. Why? Because I find it riskier to change my password than leaving it alone.

Changing passwords means I have to access my main account. The more often I do this the more risk I have of someone with a snoop program being able to see my main account. Also changing passwords will not help against a brute attack unless you change your password to something that was already tried as the brute force happens. Chances of this happening is almost nill. I will not guess about NCSoft's security measures and know nothing of it and would rather leave it alone.

When I do need to change passwords it is often done after a fresh installation of the operating system. I have an older pc reserved for this. So what about you? How often do you change your password and why do you do it that often?

I just thought of something. Maybe they need a password to change the password.
About once a month and from a different computer than I use to play.
Once only-and to a completely random bunch of keys.
God it was hard to learn it.
i was told a random code of 4 digits cant be broken that means a code of 8 numbers or letters best is letters and numbers in a single code
Any code can be broken its just how long it will take to break it.
From what I have seen on these forms its not the password itself thats ever found out. Its people useing a program to randomly guess the Birthday and Secret Code. Then they change the password and any info possible to something new. Best way to keep yourself safe is to keep your Account Login a secret with out that they have nothing to start with.

i was told a random code of 4 digits cant be broken


Exsqueeze me? That's only 10,000 tries...

From what I have seen on these forms its not the password itself thats ever found out. Its people useing a program to randomly guess the Birthday and Secret Code. Then they change the password and any info possible to something new. Best way to keep yourself safe is to keep your Account Login a secret with out that they have nothing to start with.


Actually the weakest part of the security is discussing family and friends etc with other players. These are often hints to what poorly chosen passwords might be.
I also play Legend of Mir 2 and many people on that use MSN and seem to share info over that. Suddenly you get a "hacked" thread because someone has been lax with their own security.
Even admitting in a thread like this about types of password you use is a weakness.
4 digits for a password is too few and the password parser shouldn't accept one so short. The best type of password is an alphanumeric one with both cases and as long as possible.
I change about 1 time every three months using a random password generator written in VB. It generates whatever I set it to. Alpha only, alpha numeric, can include sysmbols and both upper and lower case. Remembering the new passwords is harder than anything else.

Remembering the new passwords is harder than anything else.


That's why I tape my PW's to my computer monitor. . <looks around> whaaaat? :p
I change it when my work password expires because we have an insane complexity requirements and I use that PW for L2 too.
I've used the same password since OB. The way I see it, they need my account name to crack my password ;)

About once a month and from a different computer than I use to play.



this is about the best thing you can do.

After my last 2 acc's got hacked, and I never never shared my acc name or PW to any one.

Best advice, Never log into your master acc on the same computer as you play on.

Make sure you have a firewall, and make sure you have anti-virus with anti spyware and anti maleware.

Also change your game pw once a month (remember not from the same computer, or Network).

Make sure that the computer your getting on isn't on the same Network as you play on, because they can track your IP to your Router, from there they can get into your network and monitor your out going info, and you'd never know that they are there. ( I go to school for this crap, I know what I'm saying...ask DM he'll agree)
on a secure system if you nevber share your account you never need to change your password
Greetings,


i was told a random code of 4 digits cant be broken that means a code of 8 numbers or letters best is letters and numbers in a single code



You surely have no idea about Cryptography... (http://en.wikipedia.org/wiki/Cryptography)

A random code of 4 numbers can be broken easy. Even your 8 digit I could break easily.

Do you know what secure socket layer (SSL) is ?

You should change your passwords often (3 months max) kinda like an oil change.

If faced with any threat, change your passwords. It's free and it's for your protection.

Have Fun ! ™

Darkmotion
Board Devil (http://yodup.club.fr/critiques_bouquins/historique/sagafolco.htm) / Fired ! (http://forums.mmoradio.com/forumdisplay.php?f=66)
normally, a PW is made up with at least 8 characters, with at least 4 differents characters type :
small letter
capital letter
special character like &, #, (, ...
number

if you are paranoiac, u can change your pw each month, but but who do this?
personally, i changed mine twice since OB.
i sorry did i miss something is your account also not protected with a username :P
people who can crack at this complex level not gonna waste their time in your 2$ L2 account they spend their time cracking banks and [censored]
Given that I earn my money with cryptography and security issues, I have changed my password(s) once since open beta, and that was with the global reset of all accounts.

The reason is simple:
There is no way to try to change my password without playNC sending me an E-mail about the attempt.

Since I have never gotten any such e-mail (unless it was me, who attempted the change to test the security), I can be sure, that there is no brute force attack on my account on the run.

As a brute force attack is done by a computer or a network, you only need ONE secure password. There is no added security in changing passwords while you have never been under attack.

That is like playing a guessing game. Imagine this:
"I will think of 10 numbers. All between 1 and 100. You got 5 guesses to get the last number I thought off."
The previous 9 numbers are absolutely obsolete for guessing the last number.

It is the same with lottery. If you change your numbers from pull to pull, you still got the exact same chance to win, as if you just kept your original numbers.

So I change my password, whenever I see a reason for it. As I am the only person to access my computer and I use a password for Lineage2, that I do not use for any other game or site (including this website), and I got internet security on my local network.... I see no aded security in changing my password.

Cryptic Kitten
So tell me whats the odds of breaking a 13 digit alphanumerical user/password?

Cause i have a 16 digit alphanumerical for WoW :)

So tell me whats the odds of breaking a 13 digit alphanumerical user/password?


Case sensitive? 62^13?
Changing your PW is only effective if someone knows your password.

It has no effect whatsoever on someone attempting to guess or bruteforce the PW.

On secure systems, like a work environment, they make you change it often, because they work off the assumption that if someone gets your PW they are going to use it to access the work system repeatedly in order to steal data over a period of time. Therefore, a periodic change stops the data thief every so often.

L2 is not like that, typically the bad guy is only going to access your account a few times. Unless you happen to get lucky and change your PW between the time the bad guy gets it and the time he steals your stuff, it's not going to do much good.

I've used the same password since OB. The way I see it, they need my account name to crack my password ;)


Exacly ;)
Keeping both acc name and pasword as random stuff also helps. As well as putting in real secret question that probably no1 knows and not putting your's birthday on display on forums.
I only changed it once and that is (as many) at the big crack issue LII had.

I only would change if I thought I had a risk factor to deal with. Then again, I never share this type of information nore is it written down or stored somewhere (don't laugh I have a friend who does that and she wonders why she get's hacked LOL).


Changing your PW is only effective if someone knows your password.

It has no effect whatsoever on someone attempting to guess or bruteforce the PW.

On secure systems, like a work environment, they make you change it often, because they work off the assumption that if someone gets your PW they are going to use it to access the work system repeatedly in order to steal data over a period of time. Therefore, a periodic change stops the data thief every so often.

L2 is not like that, typically the bad guy is only going to access your account a few times. Unless you happen to get lucky and change your PW between the time the bad guy gets it and the time he steals your stuff, it's not going to do much good.



based on that you could say you should change your password every few hours to be safe
seriously if you dont give it out or have a keylogger there is no point in changeing it


i was told a random code of 4 digits cant be broken


Exsqueeze me? That's only 10,000 tries...



Actually it is 62 ^4 = 14,776,336

Edit: But I guess he did say digits. So if he did mean strickly numbers, you'd be correct.

Edit: But I guess he did say digits.


:)

See, it was a trick question.