In The Lord of the Rings, Gandalf struggled mightily to open the gates of the Mines of Moria. He didn’t know the password. Merry, of course, solved the riddle in a trice. The password was “friend.”
With all due respect to Gandalf and the Dwarf Lords, “friend” is a lousy password.
A study by Security.org states that two in three people use the same password across multiple accounts, one in three have shared passwords with their friends, and nearly 40% have been hacked. Multiple studies show that the three most common passwords are “123456”, “qwerty” and “password.” Apparently, the Dwarf Lords aren’t the only ones with a problem.
Now that you’ve had time to plan and implement your backup and recovery strategy, let’s talk about password management. I very strongly recommend that you follow sound password management practices. Compromised passwords put your personal information, and your financial and other digital assets, at risk.
What are good password management practices? I recommend the following:
- Use a password manager. Password managers generate strong passwords and passphrases while also keeping them organized, secure and synchronized across multiple devices. They can be readily configured to autofill passwords in most web browsers. It’s also simple to cut and paste passwords into applications.
- Keep all your passwords and passphrases in your password manager. Delete them everywhere else. You should only need to remember one password, that being the password for the password manager itself. Make this password strong, easy to remember, and easy to type.
- Don’t save passwords in your browser when prompted to do so. Browsers provide poor protection for passwords.
- Backup your password database to an encrypted external drive. Although your password database is synchronized across all your devices, take no chances. You don’t want to lose it.
- Create a different password for every account. Would you have one key for your house, car, storage shed, safe deposit box and summer home? What if someone steals the key? Reusing passwords increases your risk of getting successfully hacked.
- Some websites offer the option to sign in using your account from another site. Google, Apple and Facebook are often cited. I recommend against this. In doing so, you are effectively using the same password for multiple sites, and if you’re concerned with your privacy, why tell Google, Apple and Facebook what other sites you are visiting?
- Use long, randomly generated passwords. People are predictable. Predicable passwords are easier to compromise. Short passwords are very easy to guess. There’s a whole industry dedicated to hacking passwords.
- Password managers generate strong random passwords and passphrases.
- Passwords should include uppercase and lowercase letters, numbers and punctuation. A strong generated password is “4$Erk6*Q%wPR*aQGiWMd”. Don’t panic. You’re not going to type this into a website. Your password manager will autofill the password, or you will cut and paste it.
- Some sites put constraints on the characters they will accept in a password and, for instance, may not permit punctuation. Length is more important than complexity. For technical reasons, the current guidance on minimum password length is 17 characters. I recommend 20 characters or more.
- Passphrases should contain 5 or more words of varying length. A passphrase may include capital letters or numbers. Spaces or hyphens may separate words. A strong passphrase is “user-handrail-oops9-stiffness-treading”.
- There is no need to change a password unless you believe it’s been compromised. This is a change from prior guidance that recommended you change your password every 90 days.
- Take advantage of two-factor authentication (2FA) where it’s offered. Two-factor authentication requires you to prove your identity in two different ways. I’ll discuss this further in a later post.
In summary, good password management requires using a password manager, creating a different password for every account, using long, randomly generated passwords or passphrases, and taking advantage of two factor authentication.
In the next several posts, I provide evaluation criteria for selecting a password manager, recommend two products, discuss 2FA in more detail, and finally suggest a plan to get from where you are today to the halcyon future of good password management.
Information provided in this post is subject to the disclaimer in the first post of this series.