Ads Top

Are your passwords effective?

The most common passwords

     Password security is essential.  People who are able to hijack your accounts can take or spend your money, do damage to your reputation, or break enough rules (while pretending to be you) that your account is suspended.  So, to combat this, companies will enforce password rules like:

  • Use at least 1 number
  • Use at least 1 capital letter
  • Use at least one special character (ex: '#','@', '$', '%')

     Is this really that effective?  It certainly makes your password less "guessable" than the most common passwords found in leaks, but that's not saying much.  Jake, a computer scientist from Iowa used a couple of tools to determine the length of time it would take to crack a password.  The first, HSIMP ("How strong is my password?") determines how long it would take to brute-force the password (like trying all combinations in a 3-digit combination lock).  The second, Passfault Analyzer, uses more sophisticated algorithms to determine if a password could be cracked.  

     The results show that, though variety matters, length amplifies your security more easily. 

 This is why some recommend, not a password but a passphrase.  To use a sentence is a more secure method by far than using an 8-character password with a number and a symbol.



WPEngine released an in-depth analysis on recent credential leaks and found out the most common passwords, which numbers are often used leaked passwords, which "key walks" are most common (ex: qwerty), etc..  At the end of the article, they release the passwords of high-profile users whose credentials were compromised.  They are listed by their organization and position at the time that the article was published. 










The worst password in the list belonged to a senior manager at IBM with a Google software engineer close behind. 
  So next time you're changing a password, remember to add some length along with complexity for much better security.
https://crambler.com/password-security-why-secure-passwords-need-length-over-complexity/
https://wpengine.com/unmasked/

No comments:

Powered by Blogger.