The Guide to Password Security
(and Why You Should Care)
Find out how your password security can be compromised, and
how to create and manage secure passwords.
Passwords — especially those not supported by two-step verification — are your last lines of defense against prying eyes. This guide will help you understand how those passwords are exposed, and what you can do to keep them locked down.
HOW ARE PASSWORDS EXPOSED?
Before we dive into the how-tos of creating secure passwords, it’s important to understand why you need a supersecure password to begin with. After all, you might be thinking, “Who would want to hack my accounts?”
There are a few ways your account passwords can be compromised.
1. Someone’s out to get you. There are many people who might want to take a peek into your personal life. If these people know you well, they might be able to guess your e-mail password and use password recovery options to access your other accounts.
2. You become the victim of a brute-force attack. Whether a hacker attempts to access a group of user accounts or just yours, brute-force attacks are the go-to strategy for cracking passwords. These attacks work by systematically checking all possible passphrases until the correct one is found. If the hacker already has an idea of the guidelines used to create the password, this process becomes easier to execute.
3. There’s a data breach. Every few months it seems another huge company reports a hacking resulting in millions of people’s account information being compromised. And with the recent Heartbleed bug, many popular websites were affected directly.
WHAT MAKES A GOOD PASSWORD?
Although data breaches are out of your control, it’s still imperative to create passwords that can withstand brute-force attacks and relentless frenemies. Avoiding both types of attacks is dependent on the complexity of your password.
Ideally, each of your passwords would be at least 16 characters, and contain a combination of numbers, symbols, uppercase letters, lowercase letters, and spaces. The password would be free of repetition, dictionary words, usernames, pronouns, IDs, and any other predefined number or letter sequences.
Mastering the art of passwords
The 10 password commandments
How to check password strength
The security-savvy community evaluates password strength in terms of “bits,” where the higher the bits, the stronger the password. An 80-bit password is more secure than a 30-bit password, and has a complex combination of the aforementioned characters. As a result, an 80-bit password would take years longer to crack than a 30-bit password.
Ideal passwords, however, are a huge inconvenience. How can we be expected to remember 80-bit (12-character) passwords for each of our various Web accounts? That’s where many people turn to password managers like LastPass, Dashlane and 1Password.
KEEPING TRACK OF SECURE PASSWORDS
If you follow one of the most important commandments of passwords, you know that you absolutely must have a unique password for every service you use. The logic is simple: if you recycle the same password (or a variation of it), and a hacker cracks one account, he or she will be able to access the rest of your accounts.
Obviously, you can’t be expected to memorize dozens of complicated, 16-character-long passwords.
This guide thoroughly explores the different options for managing your passwords, including things like storing them on a USB drive, and even writing them down. Although it’s ultimately up to you, he presents a strong argument for using the ol’ sticky note method.
Using a Password Manager
Password managers store all of your passwords for you and fill out your log-in forms so that you don’t have to do any memorizing. If you want supersecure passwords for your online accounts (which is recommended), but you don’t want to memorize them all (also recommended), this is the way to go.
There are many options available, but a few crowd favorites are LastPass, Dashlane and 1Password. All three password managers essentially work the same way. There is a desktop program (or mobile app), which you’ll use to manage your passwords. Then, there’s a browser extension that automatically logs you into accounts as you browse the Web.
If you haven’t yet started using one, let me preemptively say: you’re welcome. Password managers are huge headache-savers, and you’ll wonder how you ever commanded the Web without one.
The tiny caveat is that you’ll still have to memorize one thing: Your master password. This unlocks all your other passwords. Make your master password extra-secure by composing it of at least 12 characters to ensure that it’s not vulnerable to any brute-force attacks. LastPass and other password managers like Dashlane and 1Password also have mobile apps, so you can easily access your passwords when you’re signing into accounts on your phone or tablet.
It’s worth noting, however, that just like any software, password managers are vulnerable to security breaches. In 2011, LastPass experienced a security breach, but users with strong master passwords were not affected.
Sharon Profis (@sharonprofis)
January 1, 2016