Windows Secrets

Subscribers: Sign in

Enter your e-mail address to get a free subscription.
We guarantee your privacy
Skip to content
  • Home
  • Newsletter Archives
    • Current
    • LangaList Plus
    • Patch Watch
    • Wacky Web Week
    • Security Baseline
  • E-Books
  • Lounge
  • About us
    • Refunds
    • Privacy Policy
    • Advertise
  • Contact
  • Your Account
    • Upgrade
    • Preferences
    • Bonus Download
    • Unsubscribe
Home>How to ease your password hassles

Windows Secrets Newsletter • Issue 90 • 2007-01-04 • Circulation: over 400,000


Table of contents 
  • LangaList Plus: How to ease your password hassles
  • LangaList Plus: Get control over your browser and desktop
  • Woody's Windows: Vista timesaver #1 — bring back my menus
  • Perimeter Scan: Buyer’s guide to upgrade-checking software

 
LangaList Plus

How to ease your password hassles

Fred langa By Fred Langa

Just as in 2006, one of 2007′s top themes is likely to be online security.

So, let’s begin the New Year with some very useful password security tips and tools, and then look at an "update aggregator" service — and more!

The way to use easier but safer passwords

My Dec. 14 story, "A free but high-powered password generator," yielded some great reader mail, such as this note from Eldin Leighton:
  • "I’ve been using a free, very small, but effective program called Acerose Password Vault for over two years. The program includes a very strong password generator and it stores all password entries in one file that is also password protected and encrypted. I’ve had no problems with it whatsoever. If one is traveling, this program is small enough to fit on a memory stick, so it could be used on any computer, since nothing has to be installed in order to use it.
Thanks, Eldin. That password article also generated some good debate right here among the Windows Secrets staff, too. Different people have different methods of producing relatively secure, hard-to-crack but easy-to-remember passwords.

Editorial director Brian Livingston, for example, pointed out the technique recommended in Perfect Passwords, a book by Mark Burnett, our former contributing editor and a friend of well-known hacker Kevin Mitnick.

Brian says, “Mark spent years studying millions of passwords that ordinary people had created and analyzing the latest cracker tools that try thousands of passwords a second. He concludes in his book that the best passwords are 15 or 16 characters long, ideally 3 words separated by punctuation, with one or more of the words misspelled. The presence of meaningful word-like strings makes such passwords memorable without people having to write them on stickies pasted to their monitors. Both the length and the lack of dictionary words are what makes the password strong.”

That’s great advice, and indeed it may be the very best way to remember passwords without external aid. But my problem is password proliferation: I currently have separate passwords for over 450 Web sites and services.

While some of those sites (discussion boards, for example) are extremely low-risk and thus don’t require ultra-high security passwords, others (banks, PayPal, credit-card sites, my business-related sites, etc.) do need very safe passwords. I prefer not to use the same password over and over on different sites, and there are simply too many separate sites for me to remember all the passwords without assistance.

For me, the solution is RoboForm. This program is available in a free version that stores a limited number of logons/passwords, and a $29.95 "Pro" version without that limitation.

RoboForm password generator Figure 1. RoboForm not only generates high-security passwords, but also automatically fills in Web forms after you’ve entered them once.

RoboForm works with your browser (including IE 7 and Firefox 2.0) to recognize Web-based forms (such as logon boxes).

If you’ve previously visited a site, and RoboForm was active, the software will automatically fill in the form with your correct user name and password (and any other information the site may require). If it’s your first visit to the site, RoboForm will automatically memorize whatever login, password and other information you provide to that site, and will automatically enter that information as needed on future visits.

RoboForm then deep-encrypts and stores your logins, passwords and related info on your hard drive (or on a thumb drive for portable use).

RoboForm also has an excellent, built-in password generator that can produce random passwords — letters, numbers and punctuation — of any specified length up to an incredible 512 characters.

At each day’s first use of RoboForm, you have to enter one master password to enable the software. It then takes over the task of managing all your logins and passwords from there. Thus, you only have to remember one high-security password (or passphrase, using Brian’s excellent method) to have access to all your other passwords, no matter how many you have.

Maybe I just need more ginkgo biloba. But barring a better memory, a tool like RoboForm is the only way I can keep all my passwords straight!

Are third-party update tools safe?

Reader and frequent contributor Steve Groginsky recently discovered AutoPatcher, an interesting free tool. But it’s of a class of tools that raises a yellow “caution” flag:
  • “Have you seen AutoPatcher yet? I came across it in the MajorGeeks RSS just now. The program is apparently a compilation of Windows updates and a way to automatedly install the selected updates off-line without user input.

    “I read all about it on the AutoPatcher site, and it looks good. It’s freeware, although unfortunately, adding all the new patches and components added to the size. For the full release of AutoPatcher XP, this means 330 megabytes and requires a high-speed connection to download. Another option is to order a CD or DVD on the site.

    “The author emphasizes the efficacy of using AutoPatcher to install updates on several computers, but I think that it makes a perfect companion to a slipstreamed install disk [as I describe in an InformationWeek column —Fred] in case it is needed after reinstalling Windows. There are ‘Full’ and ‘Lite’ updates issued periodically, so you only need to get a bigger one once, and there are separate versions for different versions of Windows.”
I agree, Steve. AutoPatcher seems to be a good tool, and has evolved over the years since I first covered it in the LangaList back on Jan. 26, 2004. (Windows Secrets also has more recent coverage in the July 13, 2006 issue.)

My concern with third-party update sites is that you’re tinkering with the core software. Some low-level patches require a reboot or that you temporarily disable your antivirus tools. It’s unlikely, but these actions can subvert a third-party updater into a medium for malicious Trojan software.

More pertinent is the fact that AutoPatcher doesn’t support new Microsoft patches until several days after they’ve been released. For example, Microsoft released new patches on Dec. 12 last month, but the update package from AutoPatcher wasn’t available until Dec. 21, as explained at its site. Many people don’t wish to wait this long to install critical patches.

Plus, programming errors in the update-bundling software itself can introduce new problems that are absent from Microsoft’s official updates. (Lord knows, Microsoft’s updates have enough problems on their own!) The AutoPatcher December release contained just such a programmatic error — sort of a bonus bug — a fact explained by the developers in the post linked to in the previous paragraph. A fix must be downloaded separately, until the site releases its January 2007 update package.

AutoPatcher has a long and honorable track record, and I believe it to be an above-board operation. Still, you should be aware of the potential dangers of using any third-party update aggregator, and use all such services with caution.

How to quickly drain your capacitors

In my Dec. 14 article, reader Michael Thomas recommended that you wait at least 10 seconds before turning your computer back on when performing a full power-down. That short delay allows the system’s capacitors to lose their charge. This, in turn, completely resets any status information that may be held in your PC’s components.

Several readers, including Darryl Howerton, offered a small speed-up tip:
  • “An easier way is to simply press the power button after unplugging the computer or turning the power supply switch off.

    “This will cause the capacitors to drain almost immediately, eliminating the wait.”
You’re right, Darryl, thanks. I’ve also found that the more caffeine I’ve had, the longer those 10 seconds can seem. I’ll remember this tip for my next caffeine-overdose day!

Remote options to help you support friends

As a Windows Secrets reader, you’re probably the one that co-workers, family and friends turn to for help with their PCs. Perhaps Andrew Miller’s question will relate to your situation, too:
  • “I recently spend an hour on the phone with my mother trying to explain how to copy a couple of files from a CD-ROM to her computer. I wished I’d taped the conversation. It was like all the funny help desk stories you hear.

    “I first had to explain that the mouse was not a something that would bite her, and that the cup holder had another purpose.

    “Anyway, my question is what is the best, easiest, and cheapest way to setup remote access to her PC, so I don’t have to go through this again.”
There are many options, Andrew. XP has three related “remote control” tools built in: Remote Desktop, Remote Desktop Web Connection, and Remote Assistance. (You can read a full description in my InformationWeek column, “XP’s ‘Remote Control’ Option.”)

XP’s tools may be worth trying, because you probably already have them in some form — but there are limitations.

For example, only XP Pro can be a full “host” or server for Remote Desktop. XP Home can only be the “client” that logs into the server. And you can run into problems with some firewalls, too.

Fortunately, there are other excellent (and free!) tools available if the XP tools won’t cut it.

There’s LogMeIn, for example. It’s a free, Web-based tool that gives you basic remote control over any PC to which you have access. (A Pro version of the service offers more options, but costs $20 per month for a two-PC setup.)

TightVNC and UltraVNC are well-regarded free, open-source, remote-control tools.

Finally, Paul Thurrott’s column in the paid section of the Mar. 24, 2005, newsletter reviews even more remote-control options, both free and commercial. (He recommends LogMeIn for users who don’t need heavy file-transfer capabilities.)

One of those tools will certainly do the trick for you — and your Mom!

Fred Langa edited the LangaList e-mail newsletter from 1997 to 2006, when it merged with Windows Secrets. Prior to that, he was editor of Byte Magazine and editorial director of CMP Media, overseeing Windows Magazine and others.

The following LangaList Plus tips are in today’s paid newsletter:

• Tame those annoying Outlook prompts
• Firefox requires upgrade to be Vista default
• How to protect your privacy in a Flash!
• The right way to update Windows XP
• Taming your PC’s boot sequence
• Turn your “My COmputer” icon into a toolbar
• Restore a missing “Send To” shortcut in Explorer
• Are rewriteable CDs safe for backups?

 
LangaList Plus

Get control over your browser and desktop

Mark edwards By Mark Joseph Edwards

There’s always room for improvement in today’s browsers and e-mail clients, particularly when an improvement eliminates your frustration!

This week, I present advice on how to get rid of annoying Outlook prompts, how to gain better control over your browser, how to manage your desktop boot sequence, and much more.


Tame those annoying Outlook prompts

Sometimes Microsoft’s security enhancements also enhance people’s level of frustration. Such is the case with Outlook and its warning dialogs. Muriel Fox writes:
  • “I’m contacting you as a last resort. I’ve been told by my broadband company, by my (Dell) computer company, and by my paid Palm tech support that the problem cannot be solved. But I hope you’ll figure something out.

    “Ever since I switched to Microsoft Office XP, I’ve been getting the following message in Microsoft Outlook when I try to send an e-mail [by clicking] ‘New’ or ‘Reply’ or ‘Forward’:

    A program is trying to access email addresses you have stored in Outlook. Do you want to allow this? If this is unexpected it may be a virus and you should choose No.

    “I need to click Yes in order to proceed. I’ve been told that this prompt is caused because I use my Palm organizer through Microsoft Outlook (in addition to my desktop), and Palm is not compatible with Microsoft Office XP, although it was compatible with my previous Microsoft Office 2005. They say there’s no way to eliminate the prompts. I installed the Service Pack for Office XP, but that didn’t help.

    This article is part of our paid content. Subscribe.

    Already a paid subscriber? Click here to login.


 
Woody's Windows

Vista timesaver #1 — bring back my menus

Woody leonhard By Woody Leonhard

If you aren’t yet totally immersed in Windows Vista, you will be soon.

Welcome to the first of a series of columns about Vista: what you need to know to get up and running quickly, safely, with a minimum of fuss and glitz.


Where the heck did they put the menus?

That’s the first question I hear from new Vista users.

If you’ve used Windows XP for more than a week, you’ve undoubtedly had occasion to dig into Windows Explorer’s menus. To map a network drive, for example, you click Tools, Map a Network Drive. To undo a copy or a rename, you click Edit, Undo. To have Windows show filename extensions or hidden folders, you choose Tools, Folder Options, View.

You can even use XP’s Windows Explorer menus to move up one level in the folder hierarchy: pull down the View menu, then click Go To, Up One Level.

All of those are simple actions with XP’s Windows Explorer. Just click the right menu, and it’s done lickety-split.

This article is part of our paid content. Subscribe.

Already a paid subscriber? Click here to login.


 
Perimeter Scan

Buyer’s guide to upgrade-checking software

Ryan russell By Ryan Russell

You aren’t going to find all the security updates you need from any single tool, and not all tools are completely accurate.

My fellow columnist, Susan Bradley, wrote in her Dec. 14 column about using multiple tools to check how well-patched your systems are. In today’s column, I give you the results of my preliminary tests of these software packages.


BigFix is a solution for large enterprises

A link in Susan’s column mentioned using BigFix to scan for missing patches. I’m not going to cover BigFix much for two reasons: One, I work there. Two, the BigFix Enterprise Suite (BES) is designed to manage large groups of computers. It can handle as many as 250,000 computers per server. It’s probably overkill for anything fewer than 1,000 seats.

Anyone is certainly welcome to download from Bigfix.com the time-and-seat-limited trial to see what it does. You will, however, need to install it on a server version of Windows.

Keep in mind that the product was never designed to scan a single machine. For this reason, I didn’t use it to analyze the test PC that I ran the other software on.

BES checks for third-party apps as well as bad patches, if you’ve installed the correct “product sets.” That’s about as much of a plug as is appropriate from me.

This article is part of our paid content. Subscribe.

Already a paid subscriber? Click here to login.


YOUR SUBSCRIPTION

The Windows Secrets Newsletter is published weekly on the 1st through 4th Thursdays of each month, plus occasional news updates. We skip an issue on the 5th Thursday of any month, the week of Thanksgiving, and the last two weeks of August and December. Windows Secrets is a continuation of four merged publications: Brian's Buzz on Windows and Woody's Windows Watch in 2004, the LangaList in 2006, and the Support Alert Newsletter in 2008.

Publisher: WindowsSecrets.com, 1218 Third Ave., Suite 1515, Seattle, WA 98101 USA. Vendors, please send no unsolicited packages to this address (readers' letters are fine).

Editor in chief: Tracey Capen. Senior editors: Fred Langa, Woody Leonhard. Copyeditor: Roberta Scholz. Program director: Tony Johnston. Contributing editors: Yardena Arar, Susan Bradley, Scott Dunn, Michael Lasky, Scott Mace, Ryan Russell, Lincoln Spector, Robert Vamosi, Becky Waring. Product manager: Andy Boyd. Advertising director: Eric Gilley.

Trademarks: Microsoft and Windows are registered trademarks of Microsoft Corporation. The Windows Secrets series of books is published by Wiley Publishing Inc. The Windows Secrets Newsletter, WindowsSecrets.com, Support Alert, LangaList, LangaList Plus, WinFind, Security Baseline, Patch Watch, Perimeter Scan, Wacky Web Week, the Logo Design (W, S or road, and Star), and the slogan Everything Microsoft Forgot to Mention all are trademarks and service marks of WindowsSecrets.com. All other marks are the trademarks or service marks of their respective owners.

HOW TO SUBSCRIBE: Anyone may subscribe to this newsletter by visiting our free signup page.

WE GUARANTEE YOUR PRIVACY:

1. We will never sell, rent, or give away your address to any outside party, ever.
2. We will never send you any unrequested e-mail, besides newsletter updates.
3. All unsubscribe requests are honored immediately, period.  Privacy policy

HOW TO UNSUBSCRIBE: To unsubscribe from the Windows Secrets Newsletter,
  • Visit our Unsubscribe page.
Copyright © 2012 by WindowsSecrets.com. All rights reserved.

Table of contents

Top-scoring articles in the past 12 months
  • Leaving long cookie trails throughout the Web 5.00
  • Windows-like security for Android devices 5.00
  • Win7′s no-reformat, nondestructive reinstall 4.53
  • The sorry tale of the (un)Secure Sockets Layer 4.42
  • RPV: Win7′s least-known data-protection system 4.33
  • Recovery: the last step in total data security 4.30
  • Time for a .NET update we can’t ignore 4.30
  • Getting the most from Windows Search — Part 1 4.25
  • Revising printing habits saves money and trees 4.25
  • Upgrades end in erratic, partial hangs 4.25
  • Pros and cons of a ‘keyfile’ password 4.21
  • Beating back Duku and a plethora of other threats 4.20
  • Office 2007 gets its final service pack 4.19
  • Putting Registry-/system-cleanup apps to the test 4.19
  • One year and 99 security bulletins later 4.18
  • 1.8TB external drive goes down hard 4.17
  • Don’t pay for software you don’t need — Part 3 4.16
  • Internet Explorer gets another round of patches 4.15
  • Is your free AV tool a ‘resource pig?’ 4.15
  • Vacation’s over; it’s a big round of patches 4.15
  • Remote access leads to remote attacks 4.15
  • Keeping you up to date: say no to .NET — again 4.14
  • Take control of Google’s privacy policy settings 4.14
  • Office File Validation patch leads to problems 4.14
  • The advanced system-recover toolkit 4.13
  • New “419″ scam involves PayPal and Western Union 4.12
  • Readers’ best personal-privacy tips 4.11
  • Getting the most from Windows Search — Part 2 4.11
  • Re-examining Dropbox and its alternatives 4.10
  • Easily edit Windows’ right-click context menus 4.09
Connect with us Follow us on Twitter Connect with us on Facebook View our RSS Feeds
  • Home|
  • Newsletter|
  • About Windows Secrets|
  • Advertise with us|
  • Unsubscribe|
  • Sitemap|
  • Affiliates|
Trademarks: Microsoft and Windows are registered trademarks of Microsoft Corporation. The Windows Secrets series of books is published by Wiley Publishing Inc. The Windows Secrets Newsletter, WindowsSecrets.com, WinFind, Windows Gizmos, Security Baseline, Patch Watch, Perimeter Scan, Wacky Web Week, the Logo Design (W, S or road, and Star), and the slogan Everything Microsoft Forgot to Mention all are trademarks and service marks of iNET Interactive. All other marks are the trademarks or service marks of their respective owners.
iNET Interactive Copyright © 2011 iNET Interactive.
All rights reserved.
Terms of Use  |  Privacy Policy
Internet Services
  • Web Hosting Talk
  • HostingCon
  • Hosting Catalog
  • Host Voice
Web Development
  • Hot Scripts
  • DB Forums
Digital Marketing
  • ABestWeb
  • Search Marketing Standard
  • PayPerClickUniverse
  • SEMCompare
Consumer Tech
  • Windows Secrets
  • Overclockers
  • Mac Forums

Learn more about
advertising opportunities across the iNET Interactive Network.

LiquidWeb