PASSWORD SECURITY
Use length to your advantage. Create a password that has eight or more characters since this is usually the minimum for most password requirements. The longer the password the more secure it is likely to be.
Password strength is a measure of the effectiveness of a password in resisting guessing and brute-force attacks. In its usual form, it estimates how many trials an attacker who does not have direct access to the password would need, on average, to guess it correctly. The strength of a password is a function of length, complexity, and unpredictability.
Using strong passwords lowers overall risk of a security breach, but strong passwords do not replace the need for other effective security controls. The effectiveness of a password of a given strength is strongly determined by the design and implementation of the factors (knowledge, ownership, inherence). The first factor is the main focus in this article.
The rate at which an attacker can submit guessed passwords to the system is a key factor in determining system security. Some systems impose a time-out of several seconds after a small number (e.g. three) of failed password entry attempts. In the absence of other vulnerabilities, such systems can be effectively secured with relatively simple passwords. However the system must store information about the user passwords in some form and if that information is stolen, say by breaching system security, the user passwords can be at risk.
Passwords are created either automatically (using randomizing equipment) or by a human; the latter case is more common. While the strength of randomly chosen passwords against a brute force attack can be calculated with precision, determining the strength of human-generated passwords is challenging.
Typically, humans are asked to choose a password, sometimes guided by suggestions or restricted by a set of rules, when creating a new account for a computer system or Internet Web site. Only rough estimates of strength are possible, since humans tend to follow patterns in such tasks, and those patterns can usually assist an attacker.[2] In addition, lists of commonly chosen passwords are widely available for use by password guessing programs. Such lists include the numerous online dictionaries for various human languages, breached databases of plaintext and hashed passwords from various online business and social accounts, along with other common passwords. All items in such lists are considered weak, as are passwords that are simple modifications of them. For some decades, investigations of passwords on multi-user computer systems have shown that 40% or more are readily guessed using only computer programs, and more can be found when information about a particular user is taken into account during the attack.
Secure your passwords
Passwords are the first line of defense against cyber criminals. It’s crucial to pick strong passwords that are different for each of your important accounts and it is good practice to update your passwords regularly. Follow these tips to create strong passwords and keep them secure.
Use a unique password for each of your important accounts like email and online banking
Choosing the same password for each of your online accounts is like using the same key to lock your home, car and office – if a criminal gains access to one, all of them are compromised. So don’t use the same password for an online newsletter as you do for your email or bank account. It may be less convenient, but picking multiple passwords keeps you safer.
Keep your passwords in a secret place that isn’t easily visible
Writing down your passwords isn’t necessarily a bad idea. But if you do this, don’t leave notes with your passwords in plain sight, on your computer or desk.Use a long password made up of numbers, letters and symbols
The longer your password is, the harder it is to guess. So make your password long to help keep your information safe. Adding numbers, symbols and mixed-case letters makes it harder for would-be snoops or others to guess or crack your password. Please don’t use ‘123456’ or ‘password,’ and avoid using publicly available information like your phone number in your passwords. It’s not very original, and it isn’t very safe
Try using a phrase that only you know
One idea is to think of a phrase that only you know, and make it be related to a particular website to help you remember it. For your email you could start with “My friends Tom and Jasmine send me a funny email once a day” and then use numbers and letters to recreate it. “MfT Jsma f1ad” is a password with lots of variations. Then repeat this process for other sites.Use length to your advantage. Create a password that has eight or more characters since this is usually the minimum for most password requirements. The longer the password the more secure it is likely to be.
Form a "random" sequence of words and/or letters. Create a phrase or series of letter that is seemingly "random" but is easy to remember. Call this your "base-word."
Add numbers to the base-word to make it more secure.
Use punctuation and symbols to "complicate" it further.
Create complexity with upper and lowercase letters.
Generate similar but altered passwords.
No comments:
Post a Comment