Staying Safe Online pt.3: Good Password Etiquette
Creating a Strong Password:
When creating a password, it is important that it meets three criteria. A good password must:
- Be at least eight characters in length, but preferably more. I have heard of people using passwords of 64 characters.
- Include a mix of uppercase and lowercase numbers.
- Contain numbers and special characters.
Each of these intends to increase the complexity of the password, and increase the amount of time it will taker for a cyber-criminal to guess the password through a method called a brute-force attack. Brute-forcing is when a hacker tries every possible combination until they find the correct one, and by increasing the complexity of the password you increase the amount of guesses needed until it becomes infeasible.
Each of your accounts should use a secure password, as detailed above, but they should also use a unique one. You shouldn’t use the same password for different accounts.
Using a Unique Password:
It is an unfortunate truth that websites get hacked, and quite often data is stolen. This data can contain personal data like names, but can also contain login details. Cyber criminals often try to use this leaked data, together with peoples habit to use the same password for multiple accounts, to try and gain access to other accounts than the one that got leaked.
Using different passwords for each account minimises this risk. If your password for facebook gets leaked for example, they can’t use that password to access your emails.
Using a Password Manager:
If you are following good password practices, it will be impossible to remember all of your passwords. You could write them all down on a piece of paper, but using a password manager is much more convenient.
A password manager allows you to store all your passwords in a secure manner. There are many different password managers to choose from, each with pros and cons, so you should do some research into which is best for you. Personally I use KeePass, but there are many other good options such as 1Password and Dashlane (This post is not sponsored by anyone, these are just highly rated services).
A password manager with auto-fill can also help to protect you against phishing (which you can read my guide on here, because if it doesn’t automatically fill in your password then that is a clue that the website you are on might not be legitimate.
Conclusion:
Having a strong password will make it more difficult to guess, using unique passwords reduces the damage if you are hacked, and using a password manager makes the practice easier.