<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Even me. . . &#187; security</title>
	<atom:link href="http://even.archlinux-br.org/blog/tag/security/feed" rel="self" type="application/rss+xml" />
	<link>http://even.archlinux-br.org/blog</link>
	<description>some things about some things.</description>
	<lastBuildDate>Wed, 18 Feb 2009 16:36:40 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Melhore a seguranÃ§a de seu Linux I</title>
		<link>http://even.archlinux-br.org/blog/melhore-a-seguranca-de-seu-linux-i</link>
		<comments>http://even.archlinux-br.org/blog/melhore-a-seguranca-de-seu-linux-i#comments</comments>
		<pubDate>Thu, 02 Oct 2008 19:26:37 +0000</pubDate>
		<dc:creator>Kessia Pinheiro</dc:creator>
				<category><![CDATA[linux]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[tutoriais]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[server]]></category>

		<guid isPermaLink="false">http://even.archlinux-br.org/blog/?p=49</guid>
		<description><![CDATA[Trabalhar com seguranÃ§a de informaÃ§Ã£o, ou pelo menos pesquisar, estudar e testar muito isso, requer fazer alguns procedimentos para que a mÃ¡quina nÃ£o facilite a vida de um possÃ­vel visitante indesejado. Antes de pensar em ferramentas, precisamos pensar na mÃ¡quina crua, no post_install(). Primeiro de tudo, independente da distribuiÃ§Ã£o, a maioria dos arquivos base sÃ£o [...]]]></description>
			<content:encoded><![CDATA[<p>Trabalhar com seguranÃ§a de informaÃ§Ã£o, ou pelo menos pesquisar, estudar e testar muito isso, requer fazer alguns procedimentos para que a mÃ¡quina nÃ£o facilite a vida de um possÃ­vel visitante indesejado. Antes de pensar em ferramentas, precisamos pensar na mÃ¡quina crua, no post_install().</p>
<p>Primeiro de tudo, independente da distribuiÃ§Ã£o, a maioria dos arquivos base sÃ£o os mesmos, como fstab, login.defs, securetty&#8230;  EntÃ£o, vamos precisar melhorar o que vem de genÃ©rico numa instalaÃ§Ã£o, pois vocÃª em seu desktop pode nÃ£o se incomodar em ter alguns padrÃµes no seu linux, mas um sysadmin precisa se preocupar.</p>
<p>Tudo Ã© questÃ£o de configuraÃ§Ã£o geral, entÃ£o estaremos tratando do diretÃ³rio <code>/etc</code> lÃ³gico. ComeÃ§e pelos seguintes arquivos:</p>
<p><code>login.defs:</code></p>
<p class="note">
#Permite uma nova tentativa de login em 5 segundos no caso de falha<br />
<b>FAIL_DELAY    5</b><br />
#Registra tambÃ©m contas de usuÃ¡rio falsas quando hÃ¡ tentativas de login com falhas<br />
<b>LOG_UNKFAIL_ENAB    yes</b><br />
#Registra tambÃ©m logins realizados com sucesso<br />
<b>LOG_OK_LOGINS    yes</b><br />
#Define /var/log/sulog como arquivo que detÃªm os registros do uso de su<br />
<b>SULOG_FILE    /var/log/sulog</b><br />
#Registra tentativas de mudanÃ§a de usuÃ¡rio<br />
<b>SYSLOG_SU_ENAB    yes</b>
</p>
<p><code>host.conf:</code></p>
<p class="note">
#Procura os nomes primeiro no DNS, depois no arquivo local<br />
<b>order bind, hosts</b><br />
#Retorna todos os endereÃ§os vÃ¡lidos para uma mÃ¡quina<br />
<b>multi on</b><br />
#Tenta impedir spoofing de hostname<br />
<b>nospoof on</b><br />
#Gera mensagem de alerta no caso de spoofing utilizando o syslog<br />
<b>spoofalert on</b>
</p>
<p><code>securetty:</code></p>
<p class="code">
# cp /etc/securetty{,.old}<br />
# >/etc/securetty
</p>
<p class="note">
#Permite que o root logue apenas uma vez em apenas um terminal<br />
#Se vocÃª nÃ£o quer que o root faÃ§a login, comente as linhas abaixo<br />
<b>console<br />
vc/1</b>
</p>
<p><code>shells:</code></p>
<p class="note">
#Habilite somente os shells que vocÃª usa<br />
<b>/bin/bash<br />
/bin/sh</b><br />
#Somente se vocÃª usar screen<br />
<b>/bin/screen</b>
</p>
<p>Desative o suid em partiÃ§Ãµes home, var, tmp:</p>
<p><code>fstab:</code><br />
Utilize as opÃ§Ãµes abaixo nas respectivas partiÃ§Ãµes:</p>
<pre>
/var	        nosuid,nodev,noexec
/home           nosuid,nodev
/usr	        nodev
</pre>
<p class="note">
#Exemplo de partiÃ§Ã£o:<br />
<b>/dev/sdb1    /home     reiserfs    nodev,nosuid,auto 1   2</b>
</p>
<p><strong><u>Retire todos os usuÃ¡rios que nÃ£o possuem shell vÃ¡lida e sÃ£o inÃºteis (como games, irc, list, lp etc). </u></strong></p>
<p>VocÃª deve impedir reinicalizaÃ§Ã£o com <code>ctrl+alt+del</code> (apÃ³s isso, precisa fazer #init q):</p>
<p><code>inittab:</code></p>
<p class="note">
#Comentar a linha abaixo:<br />
<b>#a::ctrlaltdel:/sbin/shutdown -t3 -r now</b>
</p>
<p>Configure o ntp para sincronizar hora em um dos <a href="http://www.rnp.br/ntp/ntp-stratum2.html">servidores da RNP</a> (eu os considero muito confiÃ¡veis).</p>
<p>Adicione o conteÃºdo abaixo no <code>/etc/profile</code>:</p>
<p class="note">
<b>TMOUT=3600<br />
export TMOUT</b>
</p>
<p><code>ssh/sshd_config:</code></p>
<p class="note">
#Configure uma porta diferente da 22<br />
<b>Port 2130</b><br />
#Por favor, utilize a versÃ£o 2&#8230;<br />
<b>Protocol 2</b><br />
#Define o tempo mÃ¡ximo que o usuÃ¡rio tem para digitar a senha<br />
<b>LoginGraceTime 30</b><br />
#NÃ£o permite que root logue via ssh<br />
<b>PermitRootLogin no</b><br />
#NÃ£o permite senhas em branco<br />
<b>PermitEmptyPasswords no</b><br />
#Impede que se use a interface grÃ¡fica via ssh<br />
<b>X11Forwarding no</b>
</p>
<p>Continua no prÃ³ximo capÃ­tulo&#8230;</p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Feven.archlinux-br.org%2Fblog%2Fmelhore-a-seguranca-de-seu-linux-i';
  addthis_title  = 'Melhore+a+seguran%C3%A7a+de+seu+Linux+I';
  addthis_pub    = '';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
<div class="pdf24Plugin-cp-box"><form method="post" action="http://doc2pdf.pdf24.org/doc2pdf/wordpress.php" target="pdf24PopWin" onsubmit="window.open('about:blank', 'pdf24PopWin', 'scrollbars=yes,width=400,height=200,top=0,left=0'); return true;"><input type="hidden" name="blogCharset" value="VVRGLTg=" /><input type="hidden" name="blogPosts" value="MQ==" /><input type="hidden" name="blogUrl" value="aHR0cDovL2V2ZW4uYXJjaGxpbnV4LWJyLm9yZy9ibG9n" /><input type="hidden" name="blogName" value="RXZlbiBtZS4gLiAu" /><input type="hidden" name="blogValueEncoding" value="base64" /><input type="hidden" name="postTitle_0" value="TWVsaG9yZSBhIHNlZ3VyYW7Dp2EgZGUgc2V1IExpbnV4IEk=" /><input type="hidden" name="postLink_0" value="aHR0cDovL2V2ZW4uYXJjaGxpbnV4LWJyLm9yZy9ibG9nL21lbGhvcmUtYS1zZWd1cmFuY2EtZGUtc2V1LWxpbnV4LWk=" /><input type="hidden" name="postAuthor_0" value="S2Vzc2lhIFBpbmhlaXJv" /><input type="hidden" name="postDateTime_0" value="MjAwOC0xMC0wMiAxNjoxMDozNw==" /><input type="hidden" name="postContent_0" value="PHA+VHJhYmFsaGFyIGNvbSBzZWd1cmFuw6dhIGRlIGluZm9ybWHDp8Ojbywgb3UgcGVsbyBtZW5vcyBwZXNxdWlzYXIsIGVzdHVkYXIgZSB0ZXN0YXIgbXVpdG8gaXNzbywgcmVxdWVyIGZhemVyIGFsZ3VucyBwcm9jZWRpbWVudG9zIHBhcmEgcXVlIGEgbcOhcXVpbmEgbsOjbyBmYWNpbGl0ZSBhIHZpZGEgZGUgdW0gcG9zc8OtdmVsIHZpc2l0YW50ZSBpbmRlc2VqYWRvLiBBbnRlcyBkZSBwZW5zYXIgZW0gZmVycmFtZW50YXMsIHByZWNpc2Ftb3MgcGVuc2FyIG5hIG3DoXF1aW5hIGNydWEsIG5vIHBvc3RfaW5zdGFsbCgpLjwvcD4KPHA+UHJpbWVpcm8gZGUgdHVkbywgaW5kZXBlbmRlbnRlIGRhIGRpc3RyaWJ1acOnw6NvLCBhIG1haW9yaWEgZG9zIGFycXVpdm9zIGJhc2Ugc8OjbyBvcyBtZXNtb3MsIGNvbW8gZnN0YWIsIGxvZ2luLmRlZnMsIHNlY3VyZXR0eSYjODIzMDsgIEVudMOjbywgdmFtb3MgcHJlY2lzYXIgbWVsaG9yYXIgbyBxdWUgdmVtIGRlIGdlbsOpcmljbyBudW1hIGluc3RhbGHDp8OjbywgcG9pcyB2b2PDqiBlbSBzZXUgZGVza3RvcCBwb2RlIG7Do28gc2UgaW5jb21vZGFyIGVtIHRlciBhbGd1bnMgcGFkcsO1ZXMgbm8gc2V1IGxpbnV4LCBtYXMgdW0gc3lzYWRtaW4gcHJlY2lzYSBzZSBwcmVvY3VwYXIuPC9wPgo8cD5UdWRvIMOpIHF1ZXN0w6NvIGRlIGNvbmZpZ3VyYcOnw6NvIGdlcmFsLCBlbnTDo28gZXN0YXJlbW9zIHRyYXRhbmRvIGRvIGRpcmV0w7NyaW8gPGNvZGU+L2V0YzwvY29kZT4gbMOzZ2ljby4gQ29tZcOnZSBwZWxvcyBzZWd1aW50ZXMgYXJxdWl2b3M6PC9wPgo8cD48Y29kZT5sb2dpbi5kZWZzOjwvY29kZT48L3A+CjxwIGNsYXNzPSJub3RlIj4KI1Blcm1pdGUgdW1hIG5vdmEgdGVudGF0aXZhIGRlIGxvZ2luIGVtIDUgc2VndW5kb3Mgbm8gY2FzbyBkZSBmYWxoYTxiciAvPgo8Yj5GQUlMX0RFTEFZICAgIDU8L2I+PGJyIC8+CiNSZWdpc3RyYSB0YW1iw6ltIGNvbnRhcyBkZSB1c3XDoXJpbyBmYWxzYXMgcXVhbmRvIGjDoSB0ZW50YXRpdmFzIGRlIGxvZ2luIGNvbSBmYWxoYXM8YnIgLz4KPGI+TE9HX1VOS0ZBSUxfRU5BQiAgICB5ZXM8L2I+PGJyIC8+CiNSZWdpc3RyYSB0YW1iw6ltIGxvZ2lucyByZWFsaXphZG9zIGNvbSBzdWNlc3NvPGJyIC8+CjxiPkxPR19PS19MT0dJTlMgICAgeWVzPC9iPjxiciAvPgojRGVmaW5lIC92YXIvbG9nL3N1bG9nIGNvbW8gYXJxdWl2byBxdWUgZGV0w6ptIG9zIHJlZ2lzdHJvcyBkbyB1c28gZGUgc3U8YnIgLz4KPGI+U1VMT0dfRklMRSAgICAvdmFyL2xvZy9zdWxvZzwvYj48YnIgLz4KI1JlZ2lzdHJhIHRlbnRhdGl2YXMgZGUgbXVkYW7Dp2EgZGUgdXN1w6FyaW88YnIgLz4KPGI+U1lTTE9HX1NVX0VOQUIgICAgeWVzPC9iPgo8L3A+CjxwPjxjb2RlPmhvc3QuY29uZjo8L2NvZGU+PC9wPgo8cCBjbGFzcz0ibm90ZSI+CiNQcm9jdXJhIG9zIG5vbWVzIHByaW1laXJvIG5vIEROUywgZGVwb2lzIG5vIGFycXVpdm8gbG9jYWw8YnIgLz4KPGI+b3JkZXIgYmluZCwgaG9zdHM8L2I+PGJyIC8+CiNSZXRvcm5hIHRvZG9zIG9zIGVuZGVyZcOnb3MgdsOhbGlkb3MgcGFyYSB1bWEgbcOhcXVpbmE8YnIgLz4KPGI+bXVsdGkgb248L2I+PGJyIC8+CiNUZW50YSBpbXBlZGlyIHNwb29maW5nIGRlIGhvc3RuYW1lPGJyIC8+CjxiPm5vc3Bvb2Ygb248L2I+PGJyIC8+CiNHZXJhIG1lbnNhZ2VtIGRlIGFsZXJ0YSBubyBjYXNvIGRlIHNwb29maW5nIHV0aWxpemFuZG8gbyBzeXNsb2c8YnIgLz4KPGI+c3Bvb2ZhbGVydCBvbjwvYj4KPC9wPgo8cD48Y29kZT5zZWN1cmV0dHk6PC9jb2RlPjwvcD4KPHAgY2xhc3M9ImNvZGUiPgojIGNwIC9ldGMvc2VjdXJldHR5eywub2xkfTxiciAvPgojID4vZXRjL3NlY3VyZXR0eQo8L3A+CjxwIGNsYXNzPSJub3RlIj4KI1Blcm1pdGUgcXVlIG8gcm9vdCBsb2d1ZSBhcGVuYXMgdW1hIHZleiBlbSBhcGVuYXMgdW0gdGVybWluYWw8YnIgLz4KI1NlIHZvY8OqIG7Do28gcXVlciBxdWUgbyByb290IGZhw6dhIGxvZ2luLCBjb21lbnRlIGFzIGxpbmhhcyBhYmFpeG88YnIgLz4KPGI+Y29uc29sZTxiciAvPgp2Yy8xPC9iPgo8L3A+CjxwPjxjb2RlPnNoZWxsczo8L2NvZGU+PC9wPgo8cCBjbGFzcz0ibm90ZSI+CiNIYWJpbGl0ZSBzb21lbnRlIG9zIHNoZWxscyBxdWUgdm9jw6ogdXNhPGJyIC8+CjxiPi9iaW4vYmFzaDxiciAvPgovYmluL3NoPC9iPjxiciAvPgojU29tZW50ZSBzZSB2b2PDqiB1c2FyIHNjcmVlbjxiciAvPgo8Yj4vYmluL3NjcmVlbjwvYj4KPC9wPgo8cD5EZXNhdGl2ZSBvIHN1aWQgZW0gcGFydGnDp8O1ZXMgaG9tZSwgdmFyLCB0bXA6PC9wPgo8cD48Y29kZT5mc3RhYjo8L2NvZGU+PGJyIC8+ClV0aWxpemUgYXMgb3DDp8O1ZXMgYWJhaXhvIG5hcyByZXNwZWN0aXZhcyBwYXJ0acOnw7Vlczo8L3A+CjxwcmU+Ci92YXIJICAgICAgICBub3N1aWQsbm9kZXYsbm9leGVjCi9ob21lICAgICAgICAgICBub3N1aWQsbm9kZXYKL3VzcgkgICAgICAgIG5vZGV2CjwvcHJlPgo8cCBjbGFzcz0ibm90ZSI+CiNFeGVtcGxvIGRlIHBhcnRpw6fDo286PGJyIC8+CjxiPi9kZXYvc2RiMSAgICAvaG9tZSAgICAgcmVpc2VyZnMgICAgbm9kZXYsbm9zdWlkLGF1dG8gMSAgIDI8L2I+CjwvcD4KPHA+PHN0cm9uZz48dT5SZXRpcmUgdG9kb3Mgb3MgdXN1w6FyaW9zIHF1ZSBuw6NvIHBvc3N1ZW0gc2hlbGwgdsOhbGlkYSBlIHPDo28gaW7DunRlaXMgKGNvbW8gZ2FtZXMsIGlyYywgbGlzdCwgbHAgZXRjKS4gPC91Pjwvc3Ryb25nPjwvcD4KPHA+Vm9jw6ogZGV2ZSBpbXBlZGlyIHJlaW5pY2FsaXphw6fDo28gY29tIDxjb2RlPmN0cmwrYWx0K2RlbDwvY29kZT4gKGFww7NzIGlzc28sIHByZWNpc2EgZmF6ZXIgI2luaXQgcSk6PC9wPgo8cD48Y29kZT5pbml0dGFiOjwvY29kZT48L3A+CjxwIGNsYXNzPSJub3RlIj4KI0NvbWVudGFyIGEgbGluaGEgYWJhaXhvOjxiciAvPgo8Yj4jYTo6Y3RybGFsdGRlbDovc2Jpbi9zaHV0ZG93biAtdDMgLXIgbm93PC9iPgo8L3A+CjxwPkNvbmZpZ3VyZSBvIG50cCBwYXJhIHNpbmNyb25pemFyIGhvcmEgZW0gdW0gZG9zIDxhIGhyZWY9Imh0dHA6Ly93d3cucm5wLmJyL250cC9udHAtc3RyYXR1bTIuaHRtbCI+c2Vydmlkb3JlcyBkYSBSTlA8L2E+IChldSBvcyBjb25zaWRlcm8gbXVpdG8gY29uZmnDoXZlaXMpLjwvcD4KPHA+QWRpY2lvbmUgbyBjb250ZcO6ZG8gYWJhaXhvIG5vIDxjb2RlPi9ldGMvcHJvZmlsZTwvY29kZT46PC9wPgo8cCBjbGFzcz0ibm90ZSI+CjxiPlRNT1VUPTM2MDA8YnIgLz4KZXhwb3J0IFRNT1VUPC9iPgo8L3A+CjxwPjxjb2RlPnNzaC9zc2hkX2NvbmZpZzo8L2NvZGU+PC9wPgo8cCBjbGFzcz0ibm90ZSI+CiNDb25maWd1cmUgdW1hIHBvcnRhIGRpZmVyZW50ZSBkYSAyMjxiciAvPgo8Yj5Qb3J0IDIxMzA8L2I+PGJyIC8+CiNQb3IgZmF2b3IsIHV0aWxpemUgYSB2ZXJzw6NvIDImIzgyMzA7PGJyIC8+CjxiPlByb3RvY29sIDI8L2I+PGJyIC8+CiNEZWZpbmUgbyB0ZW1wbyBtw6F4aW1vIHF1ZSBvIHVzdcOhcmlvIHRlbSBwYXJhIGRpZ2l0YXIgYSBzZW5oYTxiciAvPgo8Yj5Mb2dpbkdyYWNlVGltZSAzMDwvYj48YnIgLz4KI07Do28gcGVybWl0ZSBxdWUgcm9vdCBsb2d1ZSB2aWEgc3NoPGJyIC8+CjxiPlBlcm1pdFJvb3RMb2dpbiBubzwvYj48YnIgLz4KI07Do28gcGVybWl0ZSBzZW5oYXMgZW0gYnJhbmNvPGJyIC8+CjxiPlBlcm1pdEVtcHR5UGFzc3dvcmRzIG5vPC9iPjxiciAvPgojSW1wZWRlIHF1ZSBzZSB1c2UgYSBpbnRlcmZhY2UgZ3LDoWZpY2EgdmlhIHNzaDxiciAvPgo8Yj5YMTFGb3J3YXJkaW5nIG5vPC9iPgo8L3A+CjxwPkNvbnRpbnVhIG5vIHByw7N4aW1vIGNhcMOtdHVsbyYjODIzMDs8L3A+CjxzY3JpcHQgdHlwZT0idGV4dC9qYXZhc2NyaXB0Ij4KICBhZGR0aGlzX3VybCAgICA9ICdodHRwJTNBJTJGJTJGZXZlbi5hcmNobGludXgtYnIub3JnJTJGYmxvZyUyRm1lbGhvcmUtYS1zZWd1cmFuY2EtZGUtc2V1LWxpbnV4LWknOwogIGFkZHRoaXNfdGl0bGUgID0gJ01lbGhvcmUrYStzZWd1cmFuJUMzJUE3YStkZStzZXUrTGludXgrSSc7CiAgYWRkdGhpc19wdWIgICAgPSAnJzsKPC9zY3JpcHQ+PHNjcmlwdCB0eXBlPSJ0ZXh0L2phdmFzY3JpcHQiIHNyYz0iaHR0cDovL3M3LmFkZHRoaXMuY29tL2pzL2FkZHRoaXNfd2lkZ2V0LnBocD92PTEyIiA+PC9zY3JpcHQ+Cg==" /><a href="http://pt.pdf24.org" target="_blank" title="PDF"><img src="http://even.archlinux-br.org/blog/wp-content/plugins/pdf24-post-to-pdf/img/sheep_16x16.gif" alt="PDF" border="0" /></a> <span class="pdf24Plugin-cp-space">&nbsp;&nbsp;</span> <span class="pdf24Plugin-cp-text">Enviar artigo em PDF para</span> <input class="pdf24Plugin-cp-input" style="margin: 0px;" type="text" name="sendEmailTo" value="Digite endereço de e-mail" onmousedown="this.value = '';" /> <input class="pdf24Plugin-cp-submit" style="margin: 0px;" type="submit" value="Enviar" /></form></div>
]]></content:encoded>
			<wfw:commentRss>http://even.archlinux-br.org/blog/melhore-a-seguranca-de-seu-linux-i/feed</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
		<item>
		<title>UÃ©, qual Ã© a senha mesmo?</title>
		<link>http://even.archlinux-br.org/blog/qual-e-a-senha-mesmo</link>
		<comments>http://even.archlinux-br.org/blog/qual-e-a-senha-mesmo#comments</comments>
		<pubDate>Fri, 04 Jul 2008 15:10:57 +0000</pubDate>
		<dc:creator>Kessia Pinheiro</dc:creator>
				<category><![CDATA[code]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[scripts]]></category>
		<category><![CDATA[bash]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://even.archlinux-br.org/blog/?p=36</guid>
		<description><![CDATA[Quem nunca fez essa pergunta Ã© porque: tem muita boa memÃ³ria, daquelas que faz contas de 15 dÃ­gitos de cabeÃ§a em 10s. anota tudo num papel (ou parede, mesa, qualquer coisa riscÃ¡vel), atÃ© a senha do banco, e fica pescando. joga tudo num .txt e fica pescando. Qual jÃ¡ fez tem as seguintes saÃ­das: acaba [...]]]></description>
			<content:encoded><![CDATA[<p>Quem nunca fez essa pergunta Ã© porque:</p>
<ol>
<li>tem muita boa memÃ³ria, daquelas que faz contas de 15 dÃ­gitos de cabeÃ§a em 10s.</li>
<li>anota tudo num papel (ou parede, mesa, qualquer coisa riscÃ¡vel), atÃ© a senha do banco, e fica pescando.</li>
<li>joga tudo num .txt e fica pescando.</li>
</ol>
<p>Qual jÃ¡ fez tem as seguintes saÃ­das:</p>
<ol>
<li>acaba lembrando depois da 5Âª tentativa.</li>
<li>desiste e tenta depois de 2 dias e acaba lembrando.</li>
<li>desiste e assume que esqueceu mesmo, sÃ³ depois de 20 tentativas, e pede pro admin resetar a senha.</li>
</ol>
<p>Para quem nunca fez a pergunta (exceto quem tem excelente memÃ³ria) tem sÃ©rios problemas. Primeiro de seguranÃ§a. Quem nunca viu no banco: &#8220;NÃ£o anote sua senha num papel.&#8221;? PoisÃ©, eu gosto de pensar que se eu tenho idÃ©ia de onde achar algo relevante sobre mim mesma, alguÃ©m tambÃ©m poderÃ¡ descobrir tambÃ©m. </p>
<p>Nem papel, nem .txt puro. O que descobri depois de muitas vezes pertubar meu amigo <a href="hdoria.archlinux-br.org">Hugo DÃ³ria</a> foi que eu precisava de um programa que gerenciasse minhas senhas. Bem, juro que tentei o Kwallet e o Revelation. Mas, sh**, interface grÃ¡fica nÃ£o ajudou muito, sÃ³ fez depender do mouse para&#8230; tudo! EntÃ£o, na minha busca por uma wallet perfeita descobri que o <a href="http://www.linux.com/articles/114238">Linux.com</a> tinha feito um &#8220;How-to&#8221; de um wallet em linha de comando. Mas&#8230; &#8220;eu tenho que digitar muita coisa, nÃ£o vou lembrar disso!&#8221;.</p>
<p>DaÃ­ encontrei aquilo que eu procurava (ainda tem umas frescuras, mas vÃ¡ lÃ¡): um <a href="http://mbrisby.blogspot.com/2007/07/gpg-based-password-wallet.html">Wallet com GPG</a> feito em Shell Script! Wow! Vamos lÃ¡, testar.</p>
<p>DependÃªncias: dialog, vim e gpg.</p>
<p>Baixe o script aqui: <a href='http://even.archlinux-br.org/blog/wp-content/uploads/2008/07/wallet'>wallet</a>.</p>
<p>Sugiro colocar em algum lugar na home e adicionar o diretÃ³rio no $PATH (lembre de adicionar no seu ~/.bashrc) .</p>
<p class="code">
$ mkdir ~/bin<br />
$ cd ~/bin<br />
$ wget http://even.archlinux-br.org/blog/wp-content/uploads/2008/07/wallet<br />
$ chmod 700 wallet<br />
$ export PATH=$PATH:~/bin
</p>
<p>Depois tem que criar o arquivo de configuraÃ§Ã£o dizendo onde o wallet irÃ¡ salvar suas senhas:</p>
<p class="code">
$ echo &#8220;PASSWD_LIST=~/path/to/your/password/file&#8221; > ~/.walletrc
</p>
<p>Pronto! Agora para editar sua wallet:</p>
<p class="code">
$ wallet -e
</p>
<p>E para visualizar a wallet:</p>
<p class="code">
$ wallet
</p>
<p>It&#8217;s amazing!</p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Feven.archlinux-br.org%2Fblog%2Fqual-e-a-senha-mesmo';
  addthis_title  = 'U%C3%A9%2C+qual+%C3%A9+a+senha+mesmo%3F';
  addthis_pub    = '';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
<div class="pdf24Plugin-cp-box"><form method="post" action="http://doc2pdf.pdf24.org/doc2pdf/wordpress.php" target="pdf24PopWin" onsubmit="window.open('about:blank', 'pdf24PopWin', 'scrollbars=yes,width=400,height=200,top=0,left=0'); return true;"><input type="hidden" name="blogCharset" value="VVRGLTg=" /><input type="hidden" name="blogPosts" value="MQ==" /><input type="hidden" name="blogUrl" value="aHR0cDovL2V2ZW4uYXJjaGxpbnV4LWJyLm9yZy9ibG9n" /><input type="hidden" name="blogName" value="RXZlbiBtZS4gLiAu" /><input type="hidden" name="blogValueEncoding" value="base64" /><input type="hidden" name="postTitle_0" value="VcOpLCBxdWFsIMOpIGEgc2VuaGEgbWVzbW8/" /><input type="hidden" name="postLink_0" value="aHR0cDovL2V2ZW4uYXJjaGxpbnV4LWJyLm9yZy9ibG9nL3F1YWwtZS1hLXNlbmhhLW1lc21v" /><input type="hidden" name="postAuthor_0" value="S2Vzc2lhIFBpbmhlaXJv" /><input type="hidden" name="postDateTime_0" value="MjAwOC0wNy0wNCAxMjowNzo1Nw==" /><input type="hidden" name="postContent_0" value="PHA+UXVlbSBudW5jYSBmZXogZXNzYSBwZXJndW50YSDDqSBwb3JxdWU6PC9wPgo8b2w+CjxsaT50ZW0gbXVpdGEgYm9hIG1lbcOzcmlhLCBkYXF1ZWxhcyBxdWUgZmF6IGNvbnRhcyBkZSAxNSBkw61naXRvcyBkZSBjYWJlw6dhIGVtIDEwcy48L2xpPgo8bGk+YW5vdGEgdHVkbyBudW0gcGFwZWwgKG91IHBhcmVkZSwgbWVzYSwgcXVhbHF1ZXIgY29pc2EgcmlzY8OhdmVsKSwgYXTDqSBhIHNlbmhhIGRvIGJhbmNvLCBlIGZpY2EgcGVzY2FuZG8uPC9saT4KPGxpPmpvZ2EgdHVkbyBudW0gLnR4dCBlIGZpY2EgcGVzY2FuZG8uPC9saT4KPC9vbD4KPHA+UXVhbCBqw6EgZmV6IHRlbSBhcyBzZWd1aW50ZXMgc2HDrWRhczo8L3A+CjxvbD4KPGxpPmFjYWJhIGxlbWJyYW5kbyBkZXBvaXMgZGEgNcKqIHRlbnRhdGl2YS48L2xpPgo8bGk+ZGVzaXN0ZSBlIHRlbnRhIGRlcG9pcyBkZSAyIGRpYXMgZSBhY2FiYSBsZW1icmFuZG8uPC9saT4KPGxpPmRlc2lzdGUgZSBhc3N1bWUgcXVlIGVzcXVlY2V1IG1lc21vLCBzw7MgZGVwb2lzIGRlIDIwIHRlbnRhdGl2YXMsIGUgcGVkZSBwcm8gYWRtaW4gcmVzZXRhciBhIHNlbmhhLjwvbGk+Cjwvb2w+CjxwPlBhcmEgcXVlbSBudW5jYSBmZXogYSBwZXJndW50YSAoZXhjZXRvIHF1ZW0gdGVtIGV4Y2VsZW50ZSBtZW3Ds3JpYSkgdGVtIHPDqXJpb3MgcHJvYmxlbWFzLiBQcmltZWlybyBkZSBzZWd1cmFuw6dhLiBRdWVtIG51bmNhIHZpdSBubyBiYW5jbzogJiM4MjIwO07Do28gYW5vdGUgc3VhIHNlbmhhIG51bSBwYXBlbC4mIzgyMjE7PyBQb2lzw6ksIGV1IGdvc3RvIGRlIHBlbnNhciBxdWUgc2UgZXUgdGVuaG8gaWTDqWlhIGRlIG9uZGUgYWNoYXIgYWxnbyByZWxldmFudGUgc29icmUgbWltIG1lc21hLCBhbGd1w6ltIHRhbWLDqW0gcG9kZXLDoSBkZXNjb2JyaXIgdGFtYsOpbS4gPC9wPgo8cD5OZW0gcGFwZWwsIG5lbSAudHh0IHB1cm8uIE8gcXVlIGRlc2NvYnJpIGRlcG9pcyBkZSBtdWl0YXMgdmV6ZXMgcGVydHViYXIgbWV1IGFtaWdvIDxhIGhyZWY9Imhkb3JpYS5hcmNobGludXgtYnIub3JnIj5IdWdvIETDs3JpYTwvYT4gZm9pIHF1ZSBldSBwcmVjaXNhdmEgZGUgdW0gcHJvZ3JhbWEgcXVlIGdlcmVuY2lhc3NlIG1pbmhhcyBzZW5oYXMuIEJlbSwganVybyBxdWUgdGVudGVpIG8gS3dhbGxldCBlIG8gUmV2ZWxhdGlvbi4gTWFzLCBzaCoqLCBpbnRlcmZhY2UgZ3LDoWZpY2EgbsOjbyBhanVkb3UgbXVpdG8sIHPDsyBmZXogZGVwZW5kZXIgZG8gbW91c2UgcGFyYSYjODIzMDsgdHVkbyEgRW50w6NvLCBuYSBtaW5oYSBidXNjYSBwb3IgdW1hIHdhbGxldCBwZXJmZWl0YSBkZXNjb2JyaSBxdWUgbyA8YSBocmVmPSJodHRwOi8vd3d3LmxpbnV4LmNvbS9hcnRpY2xlcy8xMTQyMzgiPkxpbnV4LmNvbTwvYT4gdGluaGEgZmVpdG8gdW0gJiM4MjIwO0hvdy10byYjODIyMTsgZGUgdW0gd2FsbGV0IGVtIGxpbmhhIGRlIGNvbWFuZG8uIE1hcyYjODIzMDsgJiM4MjIwO2V1IHRlbmhvIHF1ZSBkaWdpdGFyIG11aXRhIGNvaXNhLCBuw6NvIHZvdSBsZW1icmFyIGRpc3NvISYjODIyMTsuPC9wPgo8cD5EYcOtIGVuY29udHJlaSBhcXVpbG8gcXVlIGV1IHByb2N1cmF2YSAoYWluZGEgdGVtIHVtYXMgZnJlc2N1cmFzLCBtYXMgdsOhIGzDoSk6IHVtIDxhIGhyZWY9Imh0dHA6Ly9tYnJpc2J5LmJsb2dzcG90LmNvbS8yMDA3LzA3L2dwZy1iYXNlZC1wYXNzd29yZC13YWxsZXQuaHRtbCI+V2FsbGV0IGNvbSBHUEc8L2E+IGZlaXRvIGVtIFNoZWxsIFNjcmlwdCEgV293ISBWYW1vcyBsw6EsIHRlc3Rhci48L3A+CjxwPkRlcGVuZMOqbmNpYXM6IGRpYWxvZywgdmltIGUgZ3BnLjwvcD4KPHA+QmFpeGUgbyBzY3JpcHQgYXF1aTogPGEgaHJlZj0naHR0cDovL2V2ZW4uYXJjaGxpbnV4LWJyLm9yZy9ibG9nL3dwLWNvbnRlbnQvdXBsb2Fkcy8yMDA4LzA3L3dhbGxldCc+d2FsbGV0PC9hPi48L3A+CjxwPlN1Z2lybyBjb2xvY2FyIGVtIGFsZ3VtIGx1Z2FyIG5hIGhvbWUgZSBhZGljaW9uYXIgbyBkaXJldMOzcmlvIG5vICRQQVRIIChsZW1icmUgZGUgYWRpY2lvbmFyIG5vIHNldSB+Ly5iYXNocmMpIC48L3A+CjxwIGNsYXNzPSJjb2RlIj4KJCBta2RpciB+L2JpbjxiciAvPgokIGNkIH4vYmluPGJyIC8+CiQgd2dldCBodHRwOi8vZXZlbi5hcmNobGludXgtYnIub3JnL2Jsb2cvd3AtY29udGVudC91cGxvYWRzLzIwMDgvMDcvd2FsbGV0PGJyIC8+CiQgY2htb2QgNzAwIHdhbGxldDxiciAvPgokIGV4cG9ydCBQQVRIPSRQQVRIOn4vYmluCjwvcD4KPHA+RGVwb2lzIHRlbSBxdWUgY3JpYXIgbyBhcnF1aXZvIGRlIGNvbmZpZ3VyYcOnw6NvIGRpemVuZG8gb25kZSBvIHdhbGxldCBpcsOhIHNhbHZhciBzdWFzIHNlbmhhczo8L3A+CjxwIGNsYXNzPSJjb2RlIj4KJCBlY2hvICYjODIyMDtQQVNTV0RfTElTVD1+L3BhdGgvdG8veW91ci9wYXNzd29yZC9maWxlJiM4MjIxOyA+IH4vLndhbGxldHJjCjwvcD4KPHA+UHJvbnRvISBBZ29yYSBwYXJhIGVkaXRhciBzdWEgd2FsbGV0OjwvcD4KPHAgY2xhc3M9ImNvZGUiPgokIHdhbGxldCAtZQo8L3A+CjxwPkUgcGFyYSB2aXN1YWxpemFyIGEgd2FsbGV0OjwvcD4KPHAgY2xhc3M9ImNvZGUiPgokIHdhbGxldAo8L3A+CjxwPkl0JiM4MjE3O3MgYW1hemluZyE8L3A+CjxzY3JpcHQgdHlwZT0idGV4dC9qYXZhc2NyaXB0Ij4KICBhZGR0aGlzX3VybCAgICA9ICdodHRwJTNBJTJGJTJGZXZlbi5hcmNobGludXgtYnIub3JnJTJGYmxvZyUyRnF1YWwtZS1hLXNlbmhhLW1lc21vJzsKICBhZGR0aGlzX3RpdGxlICA9ICdVJUMzJUE5JTJDK3F1YWwrJUMzJUE5K2Erc2VuaGErbWVzbW8lM0YnOwogIGFkZHRoaXNfcHViICAgID0gJyc7Cjwvc2NyaXB0PjxzY3JpcHQgdHlwZT0idGV4dC9qYXZhc2NyaXB0IiBzcmM9Imh0dHA6Ly9zNy5hZGR0aGlzLmNvbS9qcy9hZGR0aGlzX3dpZGdldC5waHA/dj0xMiIgPjwvc2NyaXB0Pgo=" /><a href="http://pt.pdf24.org" target="_blank" title="PDF Free"><img src="http://even.archlinux-br.org/blog/wp-content/plugins/pdf24-post-to-pdf/img/sheep_16x16.gif" alt="PDF Free" border="0" /></a> <span class="pdf24Plugin-cp-space">&nbsp;&nbsp;</span> <span class="pdf24Plugin-cp-text">Enviar artigo em PDF para</span> <input class="pdf24Plugin-cp-input" style="margin: 0px;" type="text" name="sendEmailTo" value="Digite endereço de e-mail" onmousedown="this.value = '';" /> <input class="pdf24Plugin-cp-submit" style="margin: 0px;" type="submit" value="Enviar" /></form></div>
]]></content:encoded>
			<wfw:commentRss>http://even.archlinux-br.org/blog/qual-e-a-senha-mesmo/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
