Showing posts with label password. Show all posts
Showing posts with label password. Show all posts

8 May 2016

Are your passwords safe?

Intel Security has celebrated World Password Day with reminders of how best protect to individuals data by using multiple ways to authenticate themselves online:

Avoid easy-to-guess logins
While many users make their passwords short and clever for this reason, these types of logins are fairly easy to guess. Cybercriminals often reference the most common password combinations as their first login-guessing tool. Simple keyboard patterns like qwerty or 12345678 are as insecure as passwords like welcome or login.

Make strong, complex passwords
For starters, long ones are always better than short ones. Make sure to include numbers, lowercase and uppercase letters, as well as symbols. The more complex it is, the harder it will be for cybercriminals to crack the code.

Forget universal passwords
Don’t use the same password everywhere. If your data is leaked from one source, you don’t want to give away the master key to all of your online services.

Personal details are public
Important dates, facts, habits and preferences from your life can play a role when generating passwords. Cybercriminals often try variations based on personal details when they try to brute-force accounts. Place of birth? Favourite food? An important anniversary date? Easily found on the Internet.

Consider biometrics
Many phones today have thumbprint scanners (think Apple’s Touch ID). Voice recognition technologies are advancing, too. We’re rapidly entering an age where we can use our own bodies to verify our identities. While it’s certainly convenient, biometric security may not replace all of our passwords. But it will serve as another layer of security when authenticating into devices, confirming that we are who we say we are.

Regular maintenance
Check regularly on account security. If you hear of a data breach, take the time to make sure your information has not been compromised. Change passwords regularly, and not by making a small edit to the existing one.

Use a password manager
Look to a password management solution to generate secure, complex logins for your accounts and store them for you.

Use multifactor authentication
Anytime you can require multiple login-steps to access a device, take advantage of it. This makes a huge difference in terms of your account security. A complex password plus text message confirmation? A PIN plus a fingerprint? These are great security features, and are even stronger when paired.

Be on your guard
When data isn’t easy to obtain, cybercriminals have other methods to resort to. Techniques like social engineering — where cybercriminals disguise themselves as friends, family or figures of authority to trick a user into taking a certain action online — are powerful, and can easily dupe us into giving up personal, sensitive information.

Interested?

Read the WorkSmart Asia blog post about password generation - dated 2014, but still relevant

posted from Bloggeroid

7 May 2015

Intel Security launches #PasswordConfession contest on World Password Day

Intel Security is marking the 3rd Annual World Password Day, which falls on May 7, with a social media-based contest to raise awareness.

“Passwords are a basic aspect of using online platforms, apps and mobile devices however, users often overlook setting secure passwords which helps to keep their information safe. It’s important that users put into practice some simple habits that will help to keep their personal information safe from cyber criminals,” said Vice President, Consumer, APAC at Intel Security, David Freer. He advises employees at businesses to:

  • Change passwords regularly
  • Enable multi-factor identification
  • Use unique passwords for every account
  • Avoid the casual sharing of passwords
  • Lock devices with a PIN or password
  • Let a manager memorise the passwords
  • Stop using passwords that consist of one word, making them "long and strong"

In observance of World Password Day, Intel is encouraging people to share a password confession via a picture, video, tweet or status update using the hash tag #PasswordConfession. Participants stand to win a one-year premium subscription to True Key by Intel Security.

Want more? Read the WorkSmart Asia blog post on:
Intel's predictions on the future of passwords, and the WorkSmart SG blog post on password generation.

1 April 2014

The minefield that is password generation

Search for 'password' and 'hieroglyph' on Twitter, and some variation of this joke pops up: "Sorry, your password must contain 1 uppercase letter, a number, a punctuation symbol, a haiku and your first-born". 

It may be taking things too far, but the the joke is barely a joke these days. Everyone understands that strong passwords are a must to prevent hackers from getting hold of your account. Easy passwords such as '123456' or 'password' as your password are typically banned in the corporate world, as are passwords which consist of letters only, or numerals only. 

Despite this, the recently announced Adobe hack has turned up the most common passwords used for Adobe accounts. As reported by Online Computers and Communications, '123456' takes the top spot with 1,911,938 accounts, while 'password' comes in third. Second place was '123456789', with variations of sequential digits in 7th and 11th place as well. The thing is, weak passwords are simply easier to remember.

Software is usually satisfied with a combination of numbers together with letters in both capital and small letters. To make them memorable however, passwords are often based on personal details - I know several moms who have created email addresses combining the names of their kids and their dates of birth, for example, and it seems likely this extends to passwords. Another cop-out is to use easy-to-remember key combinations, such as numbers and letters in straight lines. Unfortunately, these are too easy for the hackers and password cracker software.

In late December 2013, Scientific American wrote about a new way to create strong passwords. Essentially, you combine unlikely images together to create bizarre sentences, such as a cat driving a car, and then use these sentences in some way so as to come up with a password: 'lolspeed80' for example. The images should theoretically stick in your mind because they are so bizarre. And since the images, sentences and passwords derived would be unique to you, such passwords would be pretty hard to guess as well - a win-win.

Unless you forget that bizarre unique password, which is possible if you don't use the password for a long time or have to re-generate new passwords too frequently. Or what if great minds think alike and a cat-lover who drives picks the same two images that you did, derives the same sentence, and generates the same password? 

That's when Microsoft's TelepathWords comes into play. Visit the site and see if the tool can guess your password. Because if it can, so can a hacker.

One way of hedging on the risk is to require passwords to be changed regularly. Two factor authentication, such as offered by CA Technologies, is another way of gaining a bit more peace of mind. I know of organisations which require a separate dongle to be connected before a login occurs; and of course Singapore banks like DBS and UOB issue tokens that generate random numbers for online logins.

Nothing can be 100% safe, but it can certainly be made safer. Does your company have some way of ensuring that passwords are hard to guess and which are protected in other ways? It's worth considering adding some form of security if not.