Creating a Secure Password
Creating a Secure Password
Section titled “Creating a Secure Password”Creating a secure password is the first line of defense in safeguarding your personal information. Having a weak password or a weak password strategy leaves your account vulnerable to unauthorized access which will have obvious negative consequences. However creating a secure password may actually entail modifying your overall password strategy for your digital self. Using the same password for all your accounts is the absolute worst strategy. Adopting a stronger strategy including randomly generated passwords is a much better strategy but likely requires a password manager client so that you can keep track of everything.
Weak passwords
Section titled “Weak passwords”There are many differing opinions on weak passwords but there are a few commonalities, many of which we’ve heard before:
- If your password is in the dictionary, you are doing it wrong. Hackers using a dictionary attack will break your password with ease.
- If you use the same password across two or more sites, your strategy is weak. If your shopping password is the same as your gmail password and one becomes compromised, your identity is no longer your own. Never reuse or recycle passwords.
- Avoid using adjacent keystroke passwords like “qwerty” and “122345”.
- Avoid using personal information like your social security number, spouse’s name, or birthday dates.
- Simply tweaking a dictionary word with numerals and symbols isn’t enough. Hacking tools are sophisticated enough to replace letters with symbols. It will not take a program very long to come up with P@ssw0rd, Password123!@# or L3tme1n.
- Using the same password and adding the website name to it is not useful. If someone compromises your password on siteX which is “passwordsiteX”, what do you think is an attacker’s first guess for your gmail account?
- Storing your passwords in your browser can be a bad idea. Browser security is an ongoing issue as is personal computer security. If anyone else has physical access or gains remote access to your computer, your browser passwords could be compromised.
Creating secure passwords
Section titled “Creating secure passwords”What is the best secure password strategy? Everyone seems to have a different opinion and it is obviously impossible to identify the best and most secure method in creating and managing passwords. That being said, we have compiled a list of options. Before we get to those, let’s look at what our minimum password requirements are.
Password requirements
Section titled “Password requirements”A reasonable set of password requirements:
For passwords with less than 20 characters:
- The password must be 8 characters or longer;
- The password must contain at least 1 lowercase and uppercase letter; and
- The password must contain at least one number or symbol.
Passwords with 20 or more characters have no other requirements. These passwords can be all lower case and do not require any symbols. This allows users to employ large passphrases (see below).
If a hacker were to target a site specifically, they will start with passwords that meet the minimum requirements (a password that is only 8 characters long which contains one lowercase and one uppercase letter with one number or symbol). The longer your password is, the harder it is for hackers to break it. Users are encouraged to have a password with more than 20 characters.
“correct horse battery staple” approach
Section titled ““correct horse battery staple” approach”XKCD published a very popular and divisive comic strip on the subject of password strength known as “correct horse battery staple”. The idea is to use four common words together as a passphrase that will be easily remembered instead of one word with upper case, lower case, symbols, and numbers.
Hi Detroit442,
I have come across your article about creating strong passwords, as a mere member I can’t edit the article to add my suggestion. I would like to share what I learned with you, so that you could perhaps implement it in the article.
I personally use the correct horse battery staple method, but with a tweak. Instead of only using 4 common words, I type on my keyboard so that each letter is shifted one to the left. So c becomes v, o becomes p and p becomes [ (for US layout). Using this method, for me (Czech layout), the phrase correcthorsebatterystaple becomes vpttrvzjptdrnszzrtxdzsúůr. It’s simple and it completely obscures the meaning of the word. You can write the words on your monitor, but when writing the password, you just shift one to the left.
— m4iler
Diceware passphrase
Section titled “Diceware passphrase”If you like tabletop D&D RPGs you will love the diceware passphrase method. Just remember to store your password list in an encrypted format along with a backup somewhere in the cloud such as Dropbox.
Random passwords
Section titled “Random passwords”Random, per-site passwords provide excellent protection against account hijacking and identity theft. Password generators come with a random password generator. To safely store/remember them you can use a password manager (read on).
Password managers
Section titled “Password managers”Using a password manager can be extremely helpful in creating strong secure passwords. Generally a password manager will create random passwords and will remember which password is associated with each site you visit.
List of password managers
Section titled “List of password managers”Online
Section titled “Online”- Proton Pass (apps for all major mobile devices and desktop platforms)
Windows
Section titled “Windows”- KeePassX (KeePass 1.x compatible)
Mobile
Section titled “Mobile”- 1Password (Android and iOS)
- KeePassAndroid (Android; KeePass 1.x compatible)
- KeePass Touch (iOS; KeePass 1.x and 2.x compatible)
- MiniKeePass (iOS; KeePass 1.x and 2.x compatible)
- Locko (iOS)
Further considerations
Section titled “Further considerations”Using a password manager that can function across all your devices will make it easy to get into the habit of using long passphrases. Proton Pass, for example, works on all platforms and requires very little configuration but may require a subscription. KeePass can work across all major platforms at no cost but requires configuration that some users may find daunting (installation of plug-ins, browser extensions, and use of cloud storage).
Using a strong password will greatly reduce the chances your account will become compromised which enhances the overall security of your accounts. With all these tools available, there is no reason you need to continue to use weak and simple passwords.
