Search This Blog

Follow me on Twitter

Showing posts with label password. Show all posts
Showing posts with label password. Show all posts

June 18, 2012

You Need Secure Passwords For Your Accounts - How To Make One


Last week 3 prominent websites revealed that passwords to log into their respective accounts were stolen.  It was also reported but not confirmed that presidential candidate Mitt Romney’s Hotmail account was hacked as well. When you add to the fact that there are people who use the same passwords for each website they set up an account for, there is more than ample reason to be concerned.  Keep in mind even the strongest password would not have protected you from the LinkedIn and eHarmony hacks.  This is because the files containing passwords were hacked. You need to do what you can to protect your online accounts from being hacked.
So you may ask how do you have a password that is difficult to hack?  I said earlier that there are those who use the same password for everything.  You have separate keys for your home, car, office, etc.  You should also have a different password for all of your accounts.  If you were to have the same key for your home, car, and office, someone would only need to get that one key to have access to all.  The same concept is true for passwords. A person gets that one password and they have the key to all. 
Your password needs to have at least 1 of the following: Upper case letter, numeric character and at least one special character (*,$,@).  How long should your password be? Your password should be a minimum of 8-12 characters. I personally would opt for the latter. A few years ago, a computer professional using the name of John P. wrote how quickly he could crack a password based upon the password length and types of characters used while on a computer. For 3 characters it was 0.86 seconds using all types of characters (uppercase, lowercase, numbers, characters) and .02 seconds using only lowercase characters in your password. For 8 characters the times were 2.10 centuries and 2.42 days respectively. The assumption is that you were not using a word in the dictionary. Going from 8 to 9 characters increased the time to 20 millennia and 2.07 months respectively.  And yes, your password should not contain words in any language.
So how do we create a secure password?  Think of a sentence that you can remember.  For example “My Dog Was Born in 2011.”  With that sentence we can create a password “Mdwbi2011!” This password represents the sentence by using the first letter in each word, adding “2011” and then adding an exclamation at the end. We capitalize the letter “M” since it is the first word of the sentence. As mentioned, we do not want to use the same password for each account. So what do we do to create a unique password for each account. Most will suggest adding a prefix prior to the acronym password noted above. To be different, add at the end the first three characters of the account.  For example using Facebook, your password would be “Mdwbi2011!fac”
By using the example above as a basis for creating passwords for the sites you use, you can greatly reduce the chance that your password will be hacked as your passwords will be much more secure and much harder to break.
While we are on the subject of passwords, it is easy and convenient to enable the option to remember passwords. This will enable anyone using the computer to log onto the site without knowing your password.  Especially when using a laptop, you should disable this option whenever it is given. It is another layer in staying secure. Further I have worked with clients who leave their list of passwords on the same desk as their computer in full view of all. I have heard stories of relatives, housekeepers and others copying these to access their sites and get information they would not have gotten otherwise. If you are keeping a list of passwords, keep it in a safe place but not such a safe place that you forget where you put it. 
If you have questions regarding password security or other technology issues I can be reached at (917) 572-3468.

Computer Concierge NY LLC, provides expert computer and technology services in the Bayside, NY area, Including Queens, Albertson, Bayside Hills, Bay Terrace, Bellrose, College Point, Douglaston, Floral Park,  Flushing, Forest Hills, Great Neck, Jamaica Estates, Kew Gardens, Kings Point, Lake Success, Manhasset, Mineola, Munsey Park,  New Hyde Park, North Hills, North Shore Towers, Oakland Gardens, Plandome, Rego Park, Roslyn, The Bay Club, Thomaston, University Gardens, Williston Park, Whitestone and Other Areas in the Bayside vicinity.  

October 12, 2011

Password Protection Revisited

A few months back I did a post on password protection.  http://bit.ly/d4nvD5.   As a follow up there are additional items to consider regarding password protection.  My previous post mentioned that a secure password should have a minimum of 8 characters.  The thinking regarding this minimum number is changing to where a minimum of 12 and up to 14 characters should be used for a secure password.  Microsoft has a website where you can check your password strength as shown.  http://bit.ly/1F3MKA  They recommend a minimum of 14 characters.


An important thing to consider is when you set up a user name and password on a site, you may have to answer at least 1 security question.  This is in the event you forget your password, the site will ask you a question that you need to answer correctly in order to regain access to your account.  Perhaps the most common is asking for your mother's maiden name.  As I am noting in the next paragraph, be careful of how you answer these questions.  You do not have to give a correct answer but remember the answer you give.


A while back I wrote on how your future employer gets to know you before they meet you.  http://bit.ly/9AGqbR  In it I mentioned why you need to be careful about what you post online.  Here is another reason.  What you post can directly and indirectly be used to obtain information that can answer those security questions and not necessarily posted by you.  For example the question of your mother's maiden name.  If your mother is a Facebook friend of yours and uses her maiden name as part of her name, there is the answer to the question of your mother's maiden name.  For the question of your mother's maiden name, you may want to use something else like a neighbor's last name, a friend's maiden name, etc.   Discover Card asks the question "What city were you married in?"  If you have been married more than once, you can use the city of your first marriage.  I think you get what I am saying here.  During the 2008 presidential election, Sarah Palin's personal email account was hacked because a lot of her personal information was out there and the hacker knew the information needed to answer her security question.


In closing, be careful again of what you post online.  This information can be used to access online accounts that you would not want others to access.

May 3, 2011

Password Protection

Just like you want a good lock to protect your home and valuables from unwanted intruders, you want a good password to protect your financial and other personal data from prying eyes both online and offline. A good strong password will allow you safer online transactions.


A few years ago, a computer professional using the name of John P. wrote how quickly he could crack a password based upon the password length and types of characters used while on a computer. For 3 characters it was 0.86 seconds using all types of characters (uppercase, lowercase, numbers, characters) and .02 seconds using only lowercase characters in your password.  For 8 characters the times were 2.10 centuries and 2.42 days respectively. The assumption is that you were not using a word in the dictionary. Going from 8 to 9 characters increased the time to 20 millennia and 2.07 months respectively.




That said, certain websites financial websites in particular have a protocol that must be followed when setting up a password on their site.


A good password includes upper and lower case letters, numbers and symbols and has a minimum of 8 characters. There are password checkers out there to check the strength of your password.  A good one is Passwordmeter.com  


“Whisper32” is a freeware password manager program to download.  You can store passwords on it.  You need to have a password to open your saved file.  Click to open Whisper32 download.


You also should NEVER use the following as passwords as they will make it easier to crack your password:

a.      Your name & other personal information like birthday, spouse’s name, SS#, etc
b.      Sites name
c.       “Password”
d.      Dictionary words in any language
e.      Sequences or related characters – 123456, abcdef, 222222


While we are on the subject of passwords, it is easy and convenient to enable the option to remember passwords.  This will enable anyone using the computer being used to log into the site without knowing your password.  Especially when using a laptop, you should disable this option whenever it is given.  It is another layer in staying secure. Needless to say always disable when you are on a public computer.  Also when you are on a public computer, before you leave and you are still using the web browser remember to delete all browsing history, cookies, etc.  In Internet Explorer 8 select the Tools option from the menu.  Then select "Internet Options" and then "Browsing History". Select "Delete" to delete. 


By following the above, you will make your internet browsing much safer and secure from hackers and intruders.