PDA

View Full Version : Trying To Prevent E-gold Hacking


forwardone
06-02-04, 08:05 AM
In an effort to help prevent E-gold hacking I thought I would post part of an article I read very recently.

Quote:

The E-g0ld account that we had h@cked had a passphrase made up of exactly 10 characters and a number, which is currently the maximum length the software can cr@ck in a reasonable timescale. However, each extra letter or digit increases the time to cr@ck the passphrase increase from hours to days, to weeks/months/years, which means the longer the passphrase the harder it is to crack, increasing geometrically with each character added.

Ok, what's the moral of the story?

1) Increase the length of your passphrases to at randomly generated alphanumeric characters of length 11 or more.
2) Include punctuation characters into your passphrase as the h@cking software currently doesn't look for these characters, as this would increase the time to find standard passphrases significantly and therefore h@ckers will look for simpler codes to cr@ck instead.
3) In the future the software will no-doubt be updated to look for passphrases of length 11+ and will include punctuation characters.

However, what are on your side of the E-g0ld user are the real-world bandwidth limitations, which would take current algorithms nearly 100-years to break passphrases of length 15. We would therefore recommend passphrases of length 16 of more; including punctuation and your E-g0ld should be safe from cr@cking software in this lifetime!

Please note the following: -

1) Longer passphrase are harder to remember and have the consequences that they are easily forgotten and often are required to be written down, which introduces new security issues, but at least you are being proactive and not just waiting for an accident to happen!
2) You are still very much required to take reasonable security precautions, such as use of up-of-date firewalls and anti-virus software to prevent viruses/h@ckers compromising your computer in order to gain your E-g0ld passphrase.
------------------------------------------------------------------------------------

Some interesting points there, I think. =D>

Geoff

curly
06-03-04, 03:57 AM
Although E-gold have added the new security feature recently of a PIN, please don't let your guard down.

From another forum someone who is a program owner and very astute on the web got caught out by a keylogger on his machine, which got all his details and hacked his e-gold account anyway.

Cheers,

Curly

forwardone
06-03-04, 12:44 PM
Agreed, Curly.

It was the information on the length of password that particularly interested me, but I suppose it makes sense when you analyse it.

As you say though, we should never let our guard down on the matter of security. :-({|=

If anyone`s concerned about their own Internet security, the Resources page has some very useful, and often free, downloads to help better protect their computer. \:D/

Geoff

memorex
06-07-04, 12:18 AM
No matter what your Passphrase is or how hard it is to crack the main feature of all security is in the computer operators defense system and their own personal attitude to computer security.
It will never be a safe enviroment unless the operators use safe practices at all times .
i.e. Always use the SRK never enter E-Gold from another site always use your own link which you are sure is the authentic link check for the security padlock.
There are other mainstream thoughts but a simple strategy will suffice your security.
Which may seem to be elongated in the initial start but becomes part of the normal run of the mill after a short time.

regards
gwins