Password Tips for 2016

password1Passwords – Is mine strong enough?  How do I know?  Every time I write a password article I feel as if this subject has already been done to death by me and others.  But I always get more positive feedback on this subject than others I consider more interesting, so we offer the following suggestions:

  • Use different passwords for personal and work systems.  That way if you are cracked on place, the other is still secure.
  • If you write down and save your passwords, you are better off using paper or a notebook than recording them in an Excel spreadsheet.  If your computer is hacked, that spreadsheet is toast.  And store your notebook were it is not easily accessed by someone else.
  • Change your passwords periodically.  That way if yours are stolen off a web server and solved on a list somewhere, they won’t be useful to the bad guys for very long.
  • Longer passwords are better because most passwords are solved using computers and software that makes millions of guesses per second.  At ten or more characters, it would take a machine over a hundred years to solve using current techniques.
  • Use a different password for every device or website
  • Use multi-factor authentication whenever it is available.
  • Avoid creating or using shared accounts.  If you don’t share your toothbrush with this person, why would you share your login credentials?
  • Always change the default password when setting up new devices.  Default user names and passwords are easily found online, on the manufacturer’s support site as well as websites that aggregate this information in a single list.  (Check out www.defaultpassword.com)
  • To make all this easier for you, use a password manager such as LastPass or Dashlane.

While that may not be all of the best ideas, it is certainly enough of them.  If you were only going to pick one of them, choose the last one.

 

0

About the Author:

I am a cybersecurity and IT instructor, cybersecurity analyst, pen-tester, trainer, and speaker. I am an owner of the WyzCo Group Inc. In addition to consulting on security products and services, I also conduct security audits, compliance audits, vulnerability assessments and penetration tests. I also teach Cybersecurity Awareness Training classes. I work as an information technology and cybersecurity instructor for several training and certification organizations. I have worked in corporate, military, government, and workforce development training environments I am a frequent speaker at professional conferences such as the Minnesota Bloggers Conference, Secure360 Security Conference in 2016, 2017, 2018, 2019, the (ISC)2 World Congress 2016, and the ISSA International Conference 2017, and many local community organizations, including Chambers of Commerce, SCORE, and several school districts. I have been blogging on cybersecurity since 2006 at http://wyzguyscybersecurity.com

Add a Comment


This site uses Akismet to reduce spam. Learn how your comment data is processed.