Print Page   |   Your Cart   |   Sign In
Business
Group HomeGroup Home Blog Home Group Blogs
Search all posts for:   

 

View all (686) posts »
 

The Guide to Password Security (and Why You Should Care)

Posted By Gabriel Salcido, Arizona Small Business Association, Thursday, August 7, 2014

Find out how your password security can be compromised, and how to create and manage secure passwords.


Reports of a massive security breach circulated this week. There are a lot of questions about the extent of this alleged breach, but if you're concerned that your password and credentials have been taken, we recommend updating your passwords. Here's our advice for creating a strong password you can actually remember.

How are passwords exposed?

Before we dive into the how-tos of creating secure passwords, it's important to understand why you need a supersecure password to begin with. After all, you might be thinking, "Who would want to hack little old me?"

There are a few ways your account passwords can be compromised.

  1. Someone's out to get you. Enemies you've created, exes from your past, a nosy mother, an intrusive spouse -- there are many people who might want to take a peek into your personal life. If these people know you well, they might be able to guess your e-mail password and use password recovery options to access your other accounts. (Can you tell I'm speaking from experience?)

  2. You become the victim of a brute-force attack. Whether a hacker attempts to access a group of user accounts or just yours, brute-force attacks are the go-to strategy for cracking passwords. These attacks work by systematically checking all possible passphrases until the correct one is found. If the hacker already has an idea of the guidelines used to create the password, this process becomes easier to execute.

  3. There's a data breach. Every few months it seems another huge company reports a hacking resulting in millions of people's account information being compromised. And with the recent Heartbleed bug, many popular websites were affected directly.

What makes a good password?

Although data breaches are out of your control, it's still imperative to create passwords that can withstand brute-force attacks and relentless frenemies. Avoiding both types of attacks is dependent on the complexity of your password.

Ideally, each of your passwords would be at least 16 characters, and contain a combination of numbers, symbols, uppercase letters, lowercase letters, and spaces. The password would be free of repetition, dictionary words, usernames, pronouns, IDs, and any other predefined number or letter sequences.

The geeky and security-savvy community evaluates password strength in terms of "bits," where the higher the bits, the stronger the password. An 80-bit password is more secure than a 30-bit password, and has a complex combination of the aforementioned characters. As a result, an 80-bit password would take years longer to crack than a 30-bit password.

Ideal passwords, however, are a huge inconvenience. How can we be expected to remember 80-bit (12-character) passwords for each of our various Web accounts?

Creating secure passwords

In his guide to mastering the art of passwords , Dennis O'Reilly suggests creating a system that both allows you to create complex passwords and remember them.

For example, create a phrase like "I hope the Giants will win the World Series in 2013!" Then, take the initials of each word and all numbers and symbols to create your password. So, that phrase would result in this: IhtGwwtWSi2013!

The next option is to use a password generator, which come in the form of offline programs and Web sites. The best choice here would be to use an offline generator, like the appropriately named Random Password Generator, so that your created passwords can't be intercepted.

While you experiment with different passwords, use a tool like How Secure is my Password? to find out if it can withstand any cracking attempts. This particular Web site rates your password's strength based on how long it would take to crack. If it's too easy, the meter will let you know what elements you can add (or remove) to strengthen it.

how-1.png


Check the strength of your passwords at the How Secure Is My Password site, which indicates how difficult your password is to crack, and whether it's on the site's common-password list.
Screenshot by Eric Franklin/CNET

Microsoft offers its own online strength checker, and promises that the form is completely secure. Mac users can use the built-in Password Assistant to check their passwords' security.

Enable two-step-verification

Any time a service like Facebook or Gmail offers "two-step verification," use it. When enabled, signing in will require you to also enter in a code that's sent as a text message to your phone. Meaning, a hacker who isn't in posession of your phone won't be able to sign in, even if they know your password.

You only have to do this once for "recognized" computers and devices. Here's how to set up two-step verification for many popular websites.

Keeping track of secure passwords

If you follow one of the most important commandments of passwords, you know that you absolutely must have a unique password for every service you use. The logic is simple: if you recycle the same password (or a variation of it), and a hacker cracks one account, he or she will be able to access the rest of your accounts.

Obviously, you can't be expected to memorize dozens of crazy, 16-character-long passwords.

This guide thoroughly explores the different options for managing your passwords, including things like storing them on a USB drive, and even writing them down. Although it's ultimately up to you, he presents a strong argument for using the ol' sticky note method.

Using a password manager

Password managers store all of your passwords for you and fill out your log-in forms so that you don't have to do any memorizing. One of the most secure and intuitive password managers is LastPass.

lastpass-vault.png

The LastPass password vault in Chrome.
LastPass Inc.

LastPass is unique in that it is made of two parts, coupling an offline program with a browser plug-in. All encryption and decryption happens on your computer so that your data doesn't travel over the Internet and is not stored on any servers.

As you create new accounts or change your passwords, LastPass will ask you if you'd like to create them using its password generator, which is designed to generate hard-to-crack passwords.

If you choose those routes, you'll still have to remember at least one thing: your master LastPass password. Do be sure to make it extra-secure and composed of at least 12 characters to ensure that it's not vulnerable to any brute-force attacks.

It's worth noting, however, that just like any software, LastPass is vulnerable to security breaches. In 2011, LastPass experienced a security breach , but users with strong master passwords were not affected.




Source: cnet.com

Tags:  hack  password  security 

Share |
Permalink | Comments (0)
 

Join Fasturtle on 12/12

FT

Join Eric Olsen, Fasturtle Digital, with Search Engine Optimization (SEO) & Content:
How SEO and content marketing can help bring relevant traffic to your website.

REGISTER

Join ASBA

ASBA

ASBA is the most powerful resource for your business in Arizona. We ensure the tools we offer are valuable and support the growth, education and connections necessary for today’s top business minds.

LEARN MORE

Partner Program

ASBA

ASBA’s Partner Program delivers your brand throughout Arizona. Share insights, connect with small business and highlight your company’s involvement with the association. Contact Jodi Towns to get started.

LEARN MORE

RSVP

Coffee Connect with ASBA

REGISTER

Date: Held monthly
Time: Click for times based on location

RSVP

ASBA Speed Networking

REGISTER

Date: Held monthly
Time: Click for times based on location

Have Questions on Health Insurance?

Health Insurance

Do you have questions on plans for Individual, sole proprietor, or group? We can get the answers needed to make sure you find the right plan for you and your employees.

LEARN MORE

ASBA Ask a Lawyer

ASU Law Group

ASU Law Group is here to help you with your small business legal needs! Fill out the form today and an ASU Law Group attorney will reach out to you. Only for Business/APEX members.

ASK A LAWYER

Upcoming Events

Health+Plus

Join ASBA at any of our upcoming events!

REGISTER

Association Management Software Powered by YourMembership  ::  Legal