Showing posts with label MAKEs. Show all posts
Showing posts with label MAKEs. Show all posts

Tuesday, March 27, 2012

Little Snapper Makes Saving Research Easy

Like most college students these days, I’m finding more and more of my research material online, compared to in books like before. In fact, some of my papers are entirely based off of webpages and web related research material. However, I’m prone to losing site that I find and quote when it comes down to citing sources.


Enter Little Snapper. This slightly expensive app, by most college student’s standards ($40), has the magical ability to capture entire webpages, without the need to do several screenshots. These archives work great for reading webpages offline if you’re traveling and have to catch up on research on the go. Also, it helps with organizing your screen grabs so you’ll never lose that important research journal or online article again.


I’ve used Little Snapper for a while now, organizing screenshots of everything from inspirational designs for my design classes to full-length articles for research classes.

Thursday, March 22, 2012

ProFont Makes Terminal and Code Readable at Nearly Any Size [Fonts]

Windows/Mac/Linux: If you've ever hacked around in your computer's terminal or command prompt, you've had moments where there's way too much text to fit on your screen. ProFont, made especially for terminals and programming, is meant to be tiny, so you can read lots of data all at once.


Coders are more than a little particular about their comfortable setup, so ProFont may not be a new default setting in editors of choice. But for those want to give it a go, or for casual users who'd like something that's very readable at any size, ProFont is a nifty little font that lets you fit more text onto a screen and scan it for what you're looking for. I learned about ProFont from a programmer who said it was his first post-installation step on any Mac he uses, and I've found a small but dedicated set of fans for ProFont on the web.


Installing ProFont isn't always obvious. Here's a good how-to for Ubuntu, and an easily installed version for Windows. The Mac version from Tobias Jung's site should be straightforward to plug in.

ProFont for Windows, for Macintosh, for Linux | Tobias Jung

Friday, March 16, 2012

Using Common Phrases Makes Your Passphrase Password Useless: Here’s How to Pick a Better Phrase [Security]

 We've discussed how using passphrases as passwords can boost your security, but if you've chosen a phrase used in every-day speech, you're not doing yourself—or your data—any favors. According to a new Cambridge study, a common phrase, like, say, "outofthepark," is only marginally more secure than a dictionary word, and anyone looking to crack your password already knows to try common phrases along with common words. If you prefer passphrases, here's how to make them more secure.


 


The reason that many password systems won't allow you to choose dictionary words as you passwords—or at least require you to add numbers, capitals, or special characters to those words—is because the first thing a hacker will do to try and guess a password is try every word in the dictionary to see if they can get in. Even swapping out "i" for "1" or "e" for "3" often isn't enough—the fact that those tricks have been around for as long as they have means that those common substitutions are easily added to your dictionary list and included with the brute force attack. The goal of encouraging passphrases instead is to create credentials that are entirely nonsensical to a password cracking utility, but memorable to the human who needs to access a given system every day. Photo by Francis Storr.


The trouble though is that so many people, when they embrace passphrases, use common phrases from books, popular movies, memorable quotes, sports teams, or other proper nouns that are easily guessed. A group of researchers from Cambridge University recently published a study (PDF link) where they found that using a dictionary of these common phrases allowed them to crack open about 8,000 passphrases in Amazon's old PayPhrase system. They conclude that passphrases as a password system ultimately provide less then 30 bits of security, which they note is too weak to withstand most online attacks. Ars Technica explains what this means in plain terms:



The "30 bits of security" means the chances of a single guess cracking a four-word passphrase would be one in 2^30. What's more, the two-word phrases cracked in the study provided just 2^20.8 (or 20,656/0.0113) bits of security. Another way of expressing the same finding is that a dictionary of slightly less than 21,000 phrases is enough to guess the login credentials that slightly more than 1 percent of people in the real world will use.


Admittedly, 1 percent of phrases is a very small number, but it's still cause for concern, and drives home the point: any security system, even if it's well built and sufficiently complex, can easily fall prey to user-introduced patterns. In the end, the user—and their password—is almost always the weakest link.


 


This doesn't mean that all hope is lost for passphrases, or that you should give up on them and go back to standard strong passwords. Honestly, if you can combine the two, you should—the strength of a strong password with letters, numbers, varying case, and special characters is improved significantly when strung together as a phrase. The key is to pick a phrase that's easy for you to remember, but not, for example, your favorite sports team, or the name of your city and state strung together, or the make and model of your car. Yes, it diminishes the ease of memorization, but it vastly improves your security.


The study explicitly points out that "multi-word phrases, if chosen naively according to natural language tendencies, are not as effective at mitigated guessing attacks as alternate choices, such as choosing 2 random words or choosing a personal name at random." So, in order to boost your passphrase security, you need to pick words that matter to you, but don't matter to anyone else. For example, "NissanAltima" may not be a dictionary word, but it's a proper noun that's easily guessed. Instead, you might try "My03AltimaIsBlue."


When we discussed The XKCD passphrase generator, we pointed out another more secure method worth repeating. If you want to use your favorite lyric from a song, grab the first couple of characters from the words in your favorite line, instead of stringing the whole lyric together. We proposed that a Jackson 5 lover might extract a password from the lyrics "Oh baby give me one more chance to show you that I love you" and come up with "obgmomctsytily," which is significantly more secure.


The XKCD Password Generator itself is a robust tool to generate passwords, mostly because the words it strings together are random—they have no meaning behind them, and would be difficult to break in a dictionary attack, and even harder if you mix case and special characters. You could also take it up a notch and use the shift-to-right method for your passwords, which really makes them unintelligible.


Finally, once you've done all of this, and built a great passphrase that's difficult to crack and hard to break, do yourself a favor and plug it into a password management system like LastPass, KeePass, or 1Password, so you can use different strong passphrases for every service you use, and one memorable one to get into your password vault.

Wednesday, March 14, 2012

Alt.SXSW: MAKE’s Take on the Festival

 


Hot on the heels of alt.GDC comes alt.SXSW. What does “alt.” mean? It’s a throwback to the old alt. domains on USENET and refers to MAKE taking a slightly askew view of these large commercial tech events, in search of maker stories amongst the conventional mayhem. We have a video team and some bloggers at SXSWi and are doing live streaming of the event, making it up as we go along. And this is alt.SXSWi (interactive), so we want to hear your ideas for what we should cover, where we should point our cameras. Send your thoughts and feedback to #makesxsw @make.