Translate

Thursday, September 20, 2012

10 Golden Rules For Your Password Security

Looking for total password security? Sorry, you're out of luck. There's no such thing. 
 
For a start, crooks might hack their way into a site where you use your password and steal it from there -- like they do somewhere around the world virtually every day. A couple years back, crooks stole 32 million from a single social networking site and posted the whole lot online. Or you could come up with a clever jumble of letters and numbers but, using what law enforcement calls a "brute force attack," the criminals could employ automated password software to make a billion guesses a second until they get the right one. But here's the good news: You can take action right now that will virtually eliminate the risk of your password ever being guessed and limit the chance of it being stolen.


And it's not as hard as you might think.
I've drawn up a list of 10 Golden Rules to safeguard your password security, drawing on the advice of experts -- with a good dose of common sense mixed in.
Here they are:
1. Make them long. It used to be that a password of, say, eight characters was considered safe enough but with the increasing power of computers, those brute force attacks can run through billions of possible combinations in minutes. Each character you add increases the number of possible combinations astronomically. Here's the simple explanation: A one-letter password would only take a maximum of 26 guesses -- right? -- but two letters would create 26 x 26 possible combinations = 676 guesses. One more letter would require 26 x 26 x 26 = 17,576 guesses, and another would need 456,976 guesses.
Do you get the picture?
But, as I said, computers can run through that number of guesses in a fraction of a second, so we recommend at least 12 characters, which would take billions of billions of guesses -- and that would take centuries to do!
2. Don't make sense. In other words, don't use actual words, combinations of words, place names, slang, names and nicknames, birth dates, meaningful abbreviations (like "ILY" -- "I Love You"), your email address or the name of the website you're visiting. The first thing hackers do is run what they call a "dictionary attack," which does what its name suggests -- it checks every word in the dictionary AND then every possible combination of words. Some words are particularly dumb password favorites; for example in the hack attack I mentioned earlier, almost 95,000 victims had used the word "Password," while another 51,000 used "iloveyou," and still others used “qwerty,” and would you believe this one: “qazwsx.”
3. Use the strength of characters. Don't just use letters; use numbers and symbols -- those characters you mainly get using your "Shift" key and a number (though there are other symbols on the keyboard too). Also, use both upper and lower case letters since most logins are "case sensitive" -- they require you to type the letter in exactly the case in which the password was set up. By using these additional combinations of characters, you are once again multiplying vastly the number of guesses a hacker would have to make.
4. Don't use sequences. In some ways, sequences of consecutive numbers and letters are even worse than using whole words. Again, referring back to that big hack attack, the list of passwords published on the Internet showed that nearly 300,000 victims used "123456, or 987654, or another simple combination thereof." Even a keyboard sequence of "~!@#$%" -- the first six symbols on your keyboard -- had more than 17,000 password users.
5. Use a different password for each site. Once they've got your password, crooks will try it on any number of sites, using automated programs. So, if, for instance, you use the same password for Amazon and your bank account, if they get one, they'll be able to access both. You may consider using the same password for sites where you think your security is unimportant if it's compromised, but that's a potentially dangerous practice because criminals can piece together the information about you that they obtain from multiple sites if they can log on to them all. At the very least, don't use the same password/username combo.
6. Change them regularly. As we said at the outset, even if you do all the right things, you password could still be stolen, both by hackers and by malware on your PC. Make it a habit to change them all regularly, especially those connected with banking and online purchases. Yes, I know it's tiresome but, with some of the techniques I discuss below, it can be done.
7. Make them easy to remember -- for you. With seemingly unpredictable mixtures of letters, numbers and symbols, how are you going to remember them? A couple of tricks can help you call individual ones to mind more easily. For instance, a password using a repeated pattern of symbols could be harder to guess than a random mixture of characters if it actually has more characters and a higher total of symbols. Thus, D0g!(!(!(!(!(! would be easier to remember but tougher to crack than PrXyc5NFn4k77. Another possibility is to turn a memorable sentence into a single password, substituting letters, symbols and numbers. For instance, remember this statement from John F. Kennedy?
"Ask not what your country can do for you, but what you can do for your country."
That could become "Ask?nwyCocdo4ubutwucdo4urCo." In this case the question mark is the odd symbol that most people forget to put in a password, and it is less likely to be cracked, so are outhers, such as @#()?<>| and even ~. "Nwy” is a common term, so is “4” for either Four or For, and while not spelling the entire word out, we should all know what “u” is, right? Upper case "C" is used for country just to ensure a good mix of upper and lower case.
8. Store them safely. Now that you've got all those passwords buzzing around in your head, how are you going to remember which goes with what? You might be able to think of a clever way of linking a particular site name with a password, but a more reliable bet is to use a password manager which encrypts them -- stores them in a way hackers can't read. Some Internet security software comes with built-in password savers but you can also download or buy dedicated programs, some of which will actually generate random passwords for you (4u!). They require a master password (which should be really tough!); don't trust one that doesn't. Alternatively, some security experts say you can write your password sentence (not the actual password) or a clue to it on paper and store it in your wallet. I don't think this is a good idea.
My best advice: Use a good password manager like LastPass, KeePass or 1Password. Create one very strong password you can remember to access your password manager. Then, you can let the password manager create strong random passwords for each site you visit -- and you don't have to remember them since they are stored in your password manager. I find that works rather well.
9. Don't share them with anyone. Just don't. Well, maybe your "significant other" -- but that's your call.
10. Check the security of sites you use. As we've explained, there are some things you just don't have any power over -- like the security of organizations that store your password. But you can take the time to check what they do to keep it safe. Do they encrypt them? The big hack victim we've referred to didn't. How many login attempts will they permit before blocking access?
Ultimately, your personal and financial security is in their hands, so you need to know.
All of this may seem like a challenge but look at it this way. In 10 years, the Internet has moved from a peripheral activity for most of us to a central part of the way we run our lives. What will it be like in another 10 years? So, think about your password security now. 
 
Follow these 10 golden rules and you'll get close enough to achieving that password security -- so you can comfortably get on with the rest of your life, with less stress!



No comments:

Post a Comment

Please be considerate of others, and please do not post any comment that has profane language. Please Do Not post Spam. Thank you.

Powered By Blogger

Labels

Abduction (2) Abuse (3) Advertisement (1) Agency By City (1) Agency Service Provided Beyond Survival Sexual Assault (1) Aggressive Driving (1) Alcohol (1) ALZHEIMER'S DISEASE (2) Anti-Fraud (2) Aspartame (1) Assault (1) Auto Theft Prevention (9) Better Life (1) Books (1) Bribery (1) Bullying (1) Burglary (30) Car Theft (8) Carjackng (2) Child Molestation (5) Child Sexual Abuse (1) Child Abuse (2) Child Kidnapping (3) Child Porn (1) Child Rape (3) Child Safety (18) Child Sexual Abuse (9) Child Violence (1) Classification of Crime (1) Club Drugs (1) College (1) Computer (4) Computer Criime (4) Computer Crime (8) Confessions (2) CONFESSIONS (7) Cons (2) Credit Card Scams (2) Crime (11) Crime Index (3) Crime Prevention Tips (14) Crime Tips (31) Criminal Activity (1) Criminal Behavior (3) Crimm (1) Cyber-Stalking (2) Dating Violence (1) Deviant Behavior (6) Domestic Violence (7) E-Scams And Warnings (1) Elder Abuse (9) Elder Scams (1) Empathy (1) Extortion (1) Eyeballing a Shopping Center (1) Facebook (9) Fakes (1) Family Security (1) Fat People (1) FBI (1) Federal Law (1) Financial (2) Fire (1) Fraud (9) FREE (4) Fun and Games (1) Global Crime on World Wide Net (1) Golden Rules (1) Government (1) Guilt (2) Hackers (1) Harassment (1) Help (2) Help Needed (1) Home Invasion (2) How to Prevent Rape (1) ID Theft (96) Info. (1) Intent (1) Internet Crime (6) Internet Fraud (1) Internet Fraud and Scams (7) Internet Predators (1) Internet Security (30) Jobs (1) Kidnapping (1) Larceny (2) Laughs (3) Law (1) Medician and Law (1) Megans Law (1) Mental Health (1) Mental Health Sexual (1) Misc. (11) Missing Cash (5) Missing Money (1) Moner Matters (1) Money Matters (1) Money Saving Tips (11) Motive (1) Murder (1) Note from Birdy (1) Older Adults (1) Opinion (1) Opinions about this article are Welcome. (1) Personal Note (2) Personal Security and Safety (12) Porn (1) Prevention (2) Price of Crime (1) Private Life (1) Protect Our Kids (1) Protect Yourself (1) Protection Order (1) Psychopath (1) Psychopathy (1) Psychosis (1) PTSD (2) Punishment (1) Quoted Text (1) Rape (66) Ravishment (4) Read Me (1) Recovery (1) Regret (1) Religious Rape (1) Remorse (1) Road Rage (1) Robbery (5) Safety (2) SCAM (19) Scams (62) Schemes (1) Secrets (2) Security Threats (1) Serial Killer (2) Serial Killer/Rapist (4) Serial Killers (2) Sexual Assault (16) Sexual Assault - Spanish Version (3) Sexual Assault against Females (5) Sexual Education (1) Sexual Harassment (1) Sexual Trauma. (4) Shame (1) Sociopath (2) Sociopathy (1) Spam (6) Spyware (1) SSN's (4) Stalking (1) State Law (1) Stress (1) Survival (2) Sympathy (1) Tax Evasion (1) Theft (13) this Eve (1) Tips (13) Tips on Prevention (14) Travel (5) Tricks (1) Twitter (1) Unemployment (1) Victim (1) Victim Rights (9) Victimization (1) Violence against Women (1) Violence. (3) vs. (1) Vulnerable Victims (1) What Not To Buy (2)