Monday, January 15, 2007

First step to secure your online accounts




This article is not purely a technical one but is intended to spread awareness to use complex passwords for online accounts:-
I have heard a lots from my frens and some people complaining about their online accounts being hacked. We all know that these days people use online accounts:- Email, Shopping, Bank, Phone and other work related ID and passwords too often. I want to give some scenarios on how that accounts can be hacked without any special tech skills and how can you prevent them, atleast make it tougher for hackers to crack for it. I am not a very well techie guy that can hack into any account. But have ideas on how to prevent them. Atleast wana give some basic first step:-
Well very common things that people do is set their account passwords too common. Like name, last name, phone number, wife name, kid name, apt name, work phone or employer name. Take an example. If someone meet a person online. N if someone intends to hack her/his email account then they use the pshycological skills. They will try to collect more personal information from chat like a/s/l, name, last name, city, state, country, boyfren/girlfren name, school name, college name, best fren name, employer name, fav stars, etc etc....They will form a word list of that person. Download an tool from web, from which u can generate more combinations of words from the available list (collected from chatting, mailing and phoning). Now they will use some brute force technique. It will try all possible passwords with ur email ID automatically till it hits the match. N boom account is cracked. This is the common technique used by many peple especially to crack public mail accounts (*ot*mail and *ahoo).
Another plot:- A dummy webpage of *ahoo logon page or bank acoount page is e-mailed to you (which is exactly same looks). Asking you to enter the credentials. Wen you enter the credentials that details are e-mailed to the bad intentioned Culprit who wanted to see your user ID and passwords. So never fill any info on a webpage that u recieve by e-mail. For bank sites always rely on digital certificates ..(I will go in details in my next blog)
To avoid being the victim, try to define a complex password. Do not reveal more info to strangers or new frens or even to ur closest fren. Try to create a proverb or rhyming word which does not have any of ur common information. Try to keep one Capital letter, and alpha numeric word and ofcourse give a long password. the long the password, the long time it takes and more difficult to crack it.
Thanks for reading this blog.
Lets make the online world more secure

0 comments: