Skip to content

Services, Wiki-Artikel, Blog-Beiträge und Glossar-Einträge durchsuchen

↑↓NavigierenEnterÖffnenESCSchließen
Think up secure passwords - new IT security project available!
Offensive Security

Think up secure passwords - new IT security project available!

For each new account, the user must come up with secure passwords. No easy task - after all, every password has to be memorized and, in the worst case scenario...

Vincent Heinen Vincent Heinen Abteilungsleiter Offensive Services
Updated: October 7, 2024 3 Min. read
OSCP+ OSCP OSWP OSWA

TL;DR

The website passwort-ausdenken.de generates a personal kryptonizer - a printable encryption card that maps simple memorable words into complex passwords containing uppercase, lowercase, numbers, and special characters. Users only need to remember a base word; the card does the transformation. Since both the card (possession) and the word (knowledge) are required, this functions as a form of two-factor authentication for password creation.

Table of Contents (3 sections)

For each new account, the user must come up with secure passwords. No easy task - after all, every password has to be memorized and, in the worst case scenario for the user, changed regularly. In the early days of the Internet, the problem was still manageable - but now every Internet user has about 100 accounts in his or her life - it is hardly possible to remember passwords securely.

Passwort-ausdenken.de creates personal kryptonizer!

A kryptonizer is an encryption card that can be used to transform simple words into complex passwords. Only someone who has the card and the “simple word” can derive the password. Whoever visits the website will be presented with an individual kryptonizer. On passwort-ausdenken.de anyone can have such a card generated. Don’t like the letters and numbers? As soon as the website is reloaded, a new kryptonizer is created. If you want to participate directly, you can do that too. Under “extended card” everybody can create his personal kryptonizer and print it out afterwards. On the printout the kryptonizer is shown 2x. One version is for the wallet - the other one is a backup card in case the wallet gets lost.

This is how password-thinking.com is used!

If the kryptonizer is printed or saved, anyone can think up secure passwords. The only thing left to do now is to remember and think up words. If you use the kryptonizer e.g. with the word “Facebook” the password is: 5oW#37737mm% With passwort-ausdenken.de anyone can create a personal kryptonizer.

With passwort-ausdenken.de anyone can create a personal kryptonizer. Each expression has a start sequence. In this sequence the requirements for a complex password are fulfilled. There is an upper and lower case letter as well as a special character and a number. For the next time you need one word. If you take “Bolognese”, every letter is now replaced by another one on the card. The B becomes a 7, the O becomes an m, the L becomes a % and so on. Finally, with the word Bolognese you get the password “5oW#7m%mm3D3”.

Possession and knowledge necessary to derive password!

In a sense, this is a softened two-factor authentication on the user side. After all, it is necessary to know something and own something. In theory, it is of course sufficient to guess the password. But with Facebook or Bolognese this is easier than with “5oW#7m%mm3D3”. We wish you a lot of fun while thinking up the words and creating the passwords!

Next Step

Our certified security experts will advise you on the topics covered in this article — free and without obligation.

Free · 30 minutes · No obligation

Share this article

About the author

About the Author

Vincent Heinen
Vincent Heinen

Abteilungsleiter Offensive Services

E-Mail

M.Sc. IT-Sicherheit mit über 5 Jahren Erfahrung in offensiver Sicherheitsanalyse. Leitet die Durchführung von Penetrationstests mit Spezialisierung auf Web-Applikationen, Netzwerk-Infrastruktur, Reverse Engineering und Hardware-Sicherheit. Verantwortlich für mehrere Responsible Disclosures.

OSCP+ OSCP OSWP OSWA
Certified ISO 27001ISO 9001AZAVBSI

Cookielose Analyse via Matomo (selbst gehostet, kein Tracking-Cookie). Datenschutzerklärung