Friday, January 30, 2009

6 Ways To Pick Better Passwords

Everyone who uses the internet must user usernames and passwords and that’s just the way it is. Whether it’s for email, instant messaging or any web site that has authentication of any type, passwords are par for the course.

Years ago most people would have only a handful of usernames and passwords to remember, but with the explosion of social media, online video/audio/photo/file storage and so on, many people have 15 or more.

The way most people get around this is to the use same username/password for all their accounts. This is stupid because if one system you use is compromised where your authentication information is found, all your stuff is then "in the open", so to speak.

I’ll cover how to choose passwords that can be different yet remembered by you easily in the list below.

1. Avoid repeating characters

Example: cccrazylikeafox

The "ccc" is the repeating set of characters. Don’t do this.

2. Use mixed case

Uppercase: CRAZYLIKEAFOX

Lowercase: crazylikeafox

Mixed case: CraZylIkeAfOX

3. Use mixed case letters and numbers

Example: 27CrAzylIkeAFox93

4. Use other characters (if allowed)

Example: 27-C_rA:zy#lIkeAF#

Note: Some web sites don’t allow this (but they all should).

5. Let a password manager choose the password

Example: Use KeePass Password Safe

Example screen shot:

image

Yes, the above is a crazy password, but that’s the whole point. With 183-bit quality it would be extremely difficult for anyone to find out what it is.

And obviously you should use the password manager software to remember it for you - encrypted, of course.

6. Use a random physical address

This actually does make for fairly good passwords.

Go to Google Maps, pick a town and state that you don’t live in (nor have you ever), type in a type of business and use its physical address as your password.

Example: I choose Boise, Idaho. I’ve never been there and have never set foot in that state. Then I type restaurant and find a place called Elmer’s. The physical address is 1385 S Capitol Blvd.

The password would be written as 1385SCapitolBlvdBoiseID.

According to KeePass Password Safe, this is a 114-bit quality password and well into the "green", which is pretty darned good. The fact it’s also 23 characters long and contains letters of mixed case and numbers also helps out quite a bit.

image

To note: You will remember this easier than trying to come up with random words and phrases, because more often than not there are time you have to commit physical addresses to memory just trying to get to places - so this is nothing new to you.

I will note again that if you choose to go with this method, pick locations you’ve never been to.

Was there anything I missed concerning better passwords?

0 comments:

Post a Comment