It's a Catch-22 situation: People rarely use strong passwords because they are impossible to remember, and yet they've been told time and again never to write them down, which only makes them harder to memorize.
There's got to be a better way, you say. Well, to a degree, there already is. Programmer Chris Zarate has created an online password generator application that functions in a way I've never seen before. It actually works with a user's bad memory rather than against it.
The premise is simple. You supply a single master password -- it doesn't matter what it is, and it doesn't have to be secure -- and the application generates a bookmarklet that takes the domain name of the site you're visiting and creates a password to use in that domain by hashing it against your master password. The bookmarklet is not a program; it's simply a bookmark that, when selected, pops up a text window (via JavaScript) that contains the password to use for that domain.
Bookmarklets
Requires Free Membership to View
SearchSecurity.co.UK members gain immediate and unlimited access to breaking UK industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.co.UK today!
Michael S. Mimoso, Editorial DirectorThis is a creative and powerful solution to a problem that isn't going to go away soon.
Serdar Yegulalp is editor of the Windows Power Users Newsletter. Check it out for the latest advice and musings on the world of Windows network administrators -- and please share your thoughts as well!
This tip originally appeared on SearchWinSystems.com.
This was first published in March 2006