Best Practices for Creating and Using Passwords

 In Backup & Recovery, Corporate IT, Identity & Access Management, IT for Law Practices, IT for Manufacturing, IT for Pharmaceutical, Managed IT Services, Security

Hello everyone, I am sorry this blog is a little longer than usual, but it is important and 10 minutes could save you a lot of time and money. With more and more people relying on multiple online accounts, like banking, Facebook, google, and with recent security concerns, we thought we would give you some recommendations on passwords. You will never be totally and completely risk free, but you can limit your risk to having personal information compromised.

The Two Rules of Passwords

Never use the Same Password Across Accounts

First, never, ever, ever use the same password for more than one account. You might ask why or say that’s too many passwords to remember. Well we have some tricks below to help you remember your passwords. But why different passwords for different accounts? It limits access to your information if you are ever compromised. For example: if I use the same password for Facebook, email, and banking and my Facebook password is intercepted, people could use that password to access my bank account. If you had three different passwords for those accounts and your Facebook account was compromised then they person would only have access to your Facebook account not your bank.

Create a Strong Password with These Tips

Second, use a strong password. We have included some guidelines for choosing a strong password below. The stronger the password the harder it is for someone to crack. The longer and more complex the better, most of my passwords are over 12 characters and follow the rules below. Are they easy to remember, no they are not, but that is why I use the tools below.

Suggested guidelines for choosing a strong password

  1. Minimum of 8 characters, the longer the better
  2. Allowed characters are upper case letters, lower case letters, numbers and these special characters: pound (#), dollar ($), at (@), and underscore (_)
  3. First character of the password must be a letter of the alphabet
  4. Must include characters from at least three of these four categories:
    1. English uppercase characters (A – Z)
    2. English lowercase characters (a – z)
    3. Base 10 digits (0 – 9)
    4. Non-alphanumeric (#, $, @ or _ only)

A good password is one that is hard to guess. The following guidelines are to be used when determining if a potential password is indeed a strong password.

  • Never use a common password or a derivative:E.g. goddess, 123456, 098765, abcdef, private, qwerty, secret, sexyguy, snoopy, or password
  • Never use personal infoE.g. your name, initials, location, postal or zip code or license plate family/friend’s names including maiden, birthdays, pets word/number combinations of any of the above
  • Any of the above spelled backwards.

The best password is completely random (e.g. nY#4jvb) but those are the hardest to remember. It is true that the harder it is to remember a password, the harder it is to guess. Conversely, if the password is easy to remember it is also easy to guess. To compromise, try to make a password a phrase or combination of easy words and then use the requirements as listed to strengthen the password.

A Step-by-Step Example of the Process

For instance, on the commute into work you passed a Honda Civic converted into a stretch limo. It was a memorable event, so it’s a good place to start.

Rule 1 dictates that passwords must be at least 8 characters. Using civiclimo fits that requirement. Rule 3 also dictates that passwords must start with a letter, and this password meets that requirement.

Rule 2 says that passwords must have mixed case: civiclimo doesn’t have any uppercase, so it becomes CivicLimo.

Rule 4 states that at least one non-alphabetic (number or #, $, @, _) character be used, so with one character substitution we have C1vicLimo. This password meets the complexity requirements.

To make it really strong, you can use each rule more than once, e.g. C1v1c_Lim0. This password still derives from the memorable event (A Stretch Civic Limo) but now it is totally unrecognizable as a word.

You may want to write your password down to help you remember it. If you do write it down, store the written password in a locked location. Under your keyboard, monitor, telephone, underside of your desk, etc. are the first places people will look.

Please do not use the examples provided as your password.

Sample Password Manager

Web Address Web Site Name Email Used Username Password
www.amazon.com Amazon myemail@yahoo.com myAmazon MyPassW0rd!

Or you can use this handy little card to keep your passwords in plain sight.

Discovernet :: Best Practices for Creating & Using Passwords

 

This is only a sample card, for security please create your own or ask us how.

Using to store your Amazon Password you can decode it as follows

1st letter is a – > a (Column 2, Row 1)

2nd letter is m – > jv (Column 7, Row 2)

3rd letter is a -> AN6

4th letter is z -> xs7

5th letter is o – > enb

So your Amazon password becomes ajvAN6xs7enb

I know this is a lot to take it but remember it is your personal data and finances at risk. Please if you have any questions let us know and we would be happy to help you.

Recent Posts

Leave a Comment