It seems like every year or two I update my online password rules. Today’s post is prompted by four customers who came to me with online accounts that were compromised. Once I dug into their computers I realized the most likely culprit was the use of bad passwords. Most of them were short and most of them contained a word followed by a number. Worst of all, each customer used the same passwords for multiple accounts.
Long passwords are important
Most important is having a long password that doesn’t have any logical order. Passwords should have a combination of characters is no particular order. And most important, each online account should have a different password that is changed regularly.
The last time I wrote one of these I talked about having at least 10 character passwords. My new rule is 12 characters. It seems long, but remember you want to make people guess and keep guessing. Based on a truly randomized mix of characters, which I’ll go over later, it would take roughly 10 million years to crack at approximately 1.5 billion guesses per second.
Random combinations are vital
A good password uses numbers, capital and lower case letters and symbols. Symbols are things like the exclamation mark and parenthesis. These characters should be a jumbled up mess with no order at all. Years ago it was acceptable to substitute letters for characters and create a code book that was unique to the creator. AI tools can use leaked passwords and patterns to narrow down new potential passwords which greatly increases the odds of guessing new. In other words, your secret code is much easier to crack with the use of AI.
Most people who come into the shop because their accounts were compromised use a very basic (and antiquated) method of creating a password. I would say 80% use their pet’s name, followed by a number. And if they’re being fancy will use an exclamation mark. Something like “Felix34!”. Short of the number of characters, they technically are following my rules – sort of. There are capitals, lower case, numbers and a symbol.
Unique passwords across the internet
Repeating passwords from online account to online account is also very dangerous. Let’s assume the password for a bank account was compromised. If the hacker were to go from bank 1 to bank 2 and then to the retirement account and they all used the same password, the owner of those accounts would be in a really bad place and their accounts would be empty. In 2021 a customer had this very scenario happen and he never recovered his money.
Every two months the passwords should be changed. Yup, you heard me right. Keep the passwords fresh so in the event one of them gets leaked or there’s a breach at one of your banks your passwords are less likely to end up on the dark web. At the end of the day your money and personal information will be safer.
Keep your passwords off your computer
Your computer is not the place to stash your passwords. Browsers have been saving passwords for years which makes it really convenient for us not to have to remember all sorts of passwords. Most of us who save passwords are far less likely to change them which, as I said earlier, increases the chances of being compromised. Also, if the computer or laptop they’re stored on falls into the wrong hands all bets are off. Save a lot of headache and write passwords on a paper that never leaves the house and is away from the computer.
The importance of two factor authentication
When I first started preaching about two factor authentication (2FA) customers would look at me blankly and say something about how inconvenient it is. If you’re not familiar with 2FA, it’s a six digit code texted to a phone after the password is entered correctly. That code must be entered on the device that is accessing the account. If, let’s say, you’re out to dinner and you receive a 2FA code on your phone it means someone has your password and it should be changed ASAP. The person will not be able to access your account without that code so your account is safe until you change the password.
Good passwords vs bad ones
Finally, let’s look at some really good passwords versus some really bad ones. Tz4@nR8&pW1% uses these rules and would take a very long time to decipher or guess. Another one based on the same rules: j6!Fq3#Kd9^B. Neither is logical. Compare my first two examples to using a pet name and you get something like MaxTheDog123 or BellaIsCute12!. With a little knowledge of the account holder these passwords can be cracked in a relatively short amount of time.