English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Too many passwords?

David
Kaspersky Lab Expert
Posted March 03, 14:06  GMT
Tags: Passwords
0.1
 

How many web sites do you log into? Your bank? Facebook, Myspace and any number of other social networking sites? Auction sites? Shopping sites? Maybe lots of others too. Every site, of course, requires you to create a password. And if the site is serious about security, it may even set certain rules. For example, it may insist that your password is at least eight characters, or must contain non-alpha-numeric characters, or must use at least one uppercase letter, etc.

The problem is, with so many online accounts, how do you remember a unique password for each one? We all know that it's unwise to use the same password for them all. And it's not much better simply to recycle them - e.g. 'david1', 'david2', 'david3', etc.

There is a solution. Instead of trying to remember individual passwords, start with a fixed component and then apply a simple scrambling formula. Here's an example: start with the name of the online resource, let's say 'mybank'. Then apply your formula: e.g.

1. Capitalize the fourth character.
2. Move the second last character to the front.
3. Add a chosen number after the second character.
4. Add a chosen non-alphanumeric character to the end.

This would give you a password of 'n1mybAk;'.

There is an alternative method too. Instead of using the name of the online resource as the fixed component, create your own passphrase and use the first letter of each word. So if your passphrase is 'the quick brown fox jumps over the lazy dog' the fixed component of each password starts out as 'tqbfjotld'. Then apply your four step rule.

Using either of these methods gives you a unique password for each online account, but all you have to remember is the same four steps each time.

Passwords aren't the only case in which humans can prove to be the weakest link in security. Finding ways to 'patch' our human resources is every bit as important as applying security updates to computers. Click here for further discussion of the human dimension in Internet security.


1 comments

david.b

2013 Feb 06, 15:07
0
 

More on Passwords from David Emm

Privacy PC guys have made a detailed transcription of an interview with Mr. Emm: Create, save and store secure passwords: http://privacy-pc.com/how-to/create-save-store-secure-passwords-interview-with-david-emm.html

Reply    
If you would like to comment on this article you must first
login


Bookmark and Share
Share

Analysis

Blog