Skip to content
Musa's Musings
Musa's Musings

Prevention is better than cure. Balancing powerful technologies with educated users

  • Home
    • #CyberAware
    • #CybersecurityRoadtrip
  • Musa CyberCafe Podcast
  • TBSP of Healing
  • Musa’s Musings
  • Reference Link Library
  • My account
    • Shop
    • Cart
    • Checkout
  • No Access
0
Musa's Musings

Prevention is better than cure. Balancing powerful technologies with educated users

Password Security

MansiMusa, October 4, 2016October 5, 2016

The Problem: Almost every site these days asks for a username and password. Some of the sites have their own requirement like it must have an uppercase and two alphanumerics and the length must at least be 10 characters. Okay that may have been an exaggeration but it seriously does feel as if the requirements are so high and and give you a fake sense of security. That’s right, FAKE! A prime example is shown below where Facebook says the password: “Password1” is a strong password just because it fits the requirement to their algorithm. I’m sure most people will agree that this is no where near to being a “strong” password.

FacebookSecurity

Password creation: This brings up the question how to make a strong password? Some people have suggested to make an algorithm: 1) use a common word* 2) append to it with a phrase related to the website and use it as a prefix, suffix or add it in the middle. Of course there are many caveats to this “simple” algorithm. Firstly, don’t use information that you think is confidential like birthdates or SSN because let’s face it, it’s not. You may also try to use “@” to replace “a” or “3” to replace “e” etc.

Brian Krebs has a good article on this that can be found HERE. In it, he advises that the “best” practice is to make a list of all the websites that require your login, next to it put down your login id and a clue for the password. I would think this is somewhat faulty since if it’s not encrypted the file can be accessed by unauthorized users and then it would just come down to guess and check especially if you use the same password across multiple sites.

Password management: Some people also use password managers like 1Password to keep track of their numerous logins. However, that’s just so counter-intuitive for me. The old phrase, “don’t put all your eggs in the same basket” comes to mind.  PCMag recently compared various vendors in 2016, their results for the paid password managers can be found HERE and their results for the free password managers can be found HERE.

For more information regarding the predictable pitfalls,  The Specops Password Report offers some insights.

What are some of your password creating & managing tips?
Here is a comic from XKCD that sums up the current situation in password security:

password_strength

 

Share this:

  • Click to share on Twitter (Opens in new window)
  • Click to email a link to a friend (Opens in new window)
  • Click to share on LinkedIn (Opens in new window)
#CyberAware

Post navigation

Previous post
Next post

Related Posts

#CyberAware

Life as an Asian & Pacific Islander (API ) Hacker

May 31, 2022

Share this:

  • Click to share on Twitter (Opens in new window)
  • Click to email a link to a friend (Opens in new window)
  • Click to share on LinkedIn (Opens in new window)
Read More
#CyberAware

Cybersecurity News

June 4, 2017June 4, 2017

Here are few of my go-to links for news regarding the industry, sorted by the type of media. I have also included their Twitter handle, as let’s face it, that’s an effective tool that allows the user to see all the materials in one place. Print 1) Security Magazine 2) Krebs On…

Share this:

  • Click to share on Twitter (Opens in new window)
  • Click to email a link to a friend (Opens in new window)
  • Click to share on LinkedIn (Opens in new window)
Read More
#CyberAware

#LoveSTEMSD or is it SD Loves STEM?

March 6, 2017June 5, 2017

The Biocom Institute Festival of Science and Engineering started this past Saturday with an Expo Day! 100+ tents and booths were set up. These vendors ranged from universities such as UCSD, to enterprises such as Microsoft, to media outlets such as KGTV ABC 10 to professional organizations such as ACS. Essentially,…

Share this:

  • Click to share on Twitter (Opens in new window)
  • Click to email a link to a friend (Opens in new window)
  • Click to share on LinkedIn (Opens in new window)
Read More

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Let's Connect!

LinkedIn
Twitter
©2023 Musa's Musings | WordPress Theme by SuperbThemes
 

Loading Comments...