Ads by TechWords

See your link here
Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
 

Secrets to the best passwords

Variety makes them easy to remember, hard to guess

July 14, 2003 12:00 PM ET

Computerworld - The use of good, hard-to-guess passwords can make it difficult for a malicious hacker to break into your computer account. Avoiding predictable keywords and using different methods to introduce variety into your passwords makes it easy for you to remember them but virtually impossible for others to guess them.

Here are some tips on creating winning passwords.


Use keywords related to a theme. Choose a common, significant event: a honeymoon, the birth of a child, a new car, a new job.


Example phrases associated with a birth might be blueeyes, hurry, onemorepush, crankyRN, coldbracelet, roomsix and icechips. Ideas associated with a new car could be deepblue, 6CDs, 5speed and TiresThatGrip.


The idea here is that you use a variety of words associated with an event that other people would not readily guess. Remember that you may also need to mix in uppercase letters and numbers when you create a new password. For instance, "hurry" could become hUrry66 or Hur5ry.


Substitute numbers for letters based upon their appearance. With a little imagination, you can visualize numbers that bear resemblance to letters.





















































Number Letter
1 L
2 Z
3 E
4 A
5 S
6 b
7 Z
8 B
9 g
0 O



When you create a password, substitute a number where a letter would appear, according to the chart above. Some examples:
  • scuba becomes 5cu8a
  • water becomes w4t3r
  • icecream becomes 1c3cr34m
Substitute numbers for letters based upon their location on the keyboard. The uppermost row of letters on the keyboard, QWERTYUIOP, has a row of numbers right above it: 1234567890. You can substitute a number for a corresponding letter according to this chart.



















































Number Letter
1 Q
2 W
3 E
4 R
5 T
6 Y
7 U
8 I
9 O
0 P



So when you create a password, carry out the substitution from the chart. Some examples:

  • scuba becomes sc7ba
  • purple becomes 07r0l3
  • rocket becomes 49ck35

Consistently capitalize the nth letter(s) of your password. Some systems require that at least one character be uppercase. Many people capitalize the first character, but this is too predictable. Instead, always capitalize the second, third or fourth letter, or perhaps always the last or next-to-last. Some examples: huRry, roCky, puRple, roCket.

For further interest, you can capitalize more than one letter, for instance the first and third, or the second and fourth.


Avoid predictable week-to-week or month-to-month changes. One example of a predictable pattern to avoid: eyesJan01, eyesFeb02, eyesMar03, etc. If someone was lucky enough to discover your password long ago, you don't want him to be able to predict what it will be in the future.













Peter H. Gergory



Store passwords in Counterpane Labs' Password Safe tool. All passwords are encrypted with the robust Blowfish algorithm. A nifty feature of Password Safe is that when you double-click on a previously stored password entry, it silently copies it to the clipboard so you can paste in the password even if others are watching you type.

Check the quality of your password at SecurityStats.com. This Web site performs calculations based on the complexity and "guessability" of your password and tells you how good your password is. Remember that your password is transmitted over the Internet in the clear, so you should try similar passwords instead of your actual passwords to get an idea of the characteristics of a good one.


Adopt ISO17799 password quality guidelines. Ask the IT department to implement best practices for password management in accordance with ISO17799, a widely recognized information security standard. According to the standard, here are some guidelines for passwords:


  • They should be at least six characters long.
  • They should be free of consecutive identical characters.
  • Don't use all numbers or all letters.
  • Avoid reusing or recycling old passwords.
  • Require that passwords be changed at regular intervals.
  • Force users to change temporary passwords at the next log-on.
  • Maintain a record of previous user passwords and prevent their reuse.
  • Change all vendor default passwords.
  • Eliminate or lock shared-user accounts.

Warning: Don't use any of the password examples that appear in this article!

A note about password length: Some information security (infosec) professionals will bristle at ISO17799's recommendation for a mere six characters in a password. Some have told me that six characters are insufficient, based on the time it takes to crack a password. My response is this: Typically, hackers don't care about the length of passwords when choosing to crack open a computer account.


Organizations are rife with guest accounts, group accounts, accounts with no passwords, a lack of password expirations, passwords that can be easily guessed and opportunities to exploit technical weaknesses or perform social engineering. With all of these easy opportunities, computer accounts with good six-character passwords are only a trifle weaker than those with eight-character passwords. My point is that infosec professionals need to focus more on the compliance of good user-account hygiene than on the length of passwords.



Special Report

Tips From Security Experts
Stories in this report:


Additional Resources

POLL RESULTS
Accelerate your knowledge of the IT world you inhabit by viewing the results of a series of polls taken by your IT peers. These polls of 100+ IT professionals each are available for full viewing. They cover key topics such as virtualization, processor performance, green IT, cloud computing and many others. Be a part of the buzz.
WHITE PAPER
Technology is complex. Keeping it running productively shouldn't be. To that end, you want to minimize the number of solutions needed in-house to simplify operations, maintenance, and support. Kodak offers a best-practices model. One company provides support for both scanner and software, for fast problem resolution without vendor finger-pointing. Download now!
WHITE PAPER
Utilizing demand intelligence improves the precision of pricing, product assortments, channel/store placement, and promotion, which are all essential for sustainable revenue management performance. Learn more, download this free whitepaper today.

White Papers & Webcasts

Centralized Data Backup and Your WAN
Is your organization prepared to tackle the massive challenge of protecting your data in a cost effective and timely manner? With a growing...  

Why Compliance Pays
This OnDemand webcast explores the relationship that firms with best compliance records have higher revenue, greater customer retention, lower financial losses from data...

An All-in-One Approach to Web Security
Granting web access to employees poses challenges to IT administrators and introduces unique security risks. Even as companies have perfected their security techniques...  

Best Practices for Managing Business Risks from the Use of IT
(Source: Symantec) Based on exhaustive benchmarks conducted by the IT Policy Compliance, this session highlights the relationship between business risks and use of...

The Hidden Dangers of Spam
Beyond the well-understood productivity drain that spam inflicts on businesses, threats posed by illicit email circulating through a network are causing many security...  

Managing And Protecting Your Ever Increasing Mobile Assets
(Source: Absolute Software) Your users are becoming more mobile each day. This is great for productivity - yet challenging for IT control. Natalie...

Open Source Security Myths Dispelled
(Source: Astaro) Open Source Software is computer software whose source code is available to the general public. This openly viewable nature...  

Sun OpenSSO Enterprise Webinar
(Source: Sun) This webinar replay discusses Sun OpenSSO Enterprise innovation--the single, open-source solution that helps your business solve the challenges around internal access...

Best Practices for Backing Up VMware® with Veritas NetBackup™
VMware® is used by enterprises large and small to increase the efficiency and cost-effectiveness of their IT operations. With this in mind, Symantec...  

Agile Enterprise Content Management (ECM) for Rapid ROI
(Source: IBM) Content rich business processes are a core feature of daily operations at just about any organization today. Very often these essential...