top of page
Search

What is in a Password?

Passwords are ubiquitous in terms of modern information security. So ubiquitous that we rarely consider our password policies. We assume a password good enough for five years ago is good enough today. However, offensive cyber capabilities are rapidly advancing and leaving your comfortable, familiar standard vulnerable to hacking.


The standard has been 8 characters. Password is 8 characters. So is Pass1234, adm1n23!, and p@ssw0rd.  


Assuming you're properly protected because your password fits the standard, changes frequently and uses complexity is risky. 


There are a few problems with the “standard” password:


  1. Password cracking algorithms and raw computing power have advanced incredibly.


In 1995, an 8 character password may have fit the bill, but since then we have seen massive advances. We appreciate the business advantages of Moore’s law, and enjoy looking at our Pentium processors in the Intel Museum. However, Moore’s law has benefited the bad guys too, and they have put it to work in the modern hacker toolkit, including password hackers. 


Your normal 8 character password can be cracked on a laptop in seconds regardless of complexity.



  1. Frequent password changes do more harm than good


Changing your password every 90 days, or even every 30 seems like a way to increase security. According to most studies, this actually has an opposite effect. Some NIST guidelines even recommend not having an expiration period for passwords, and only change them as needed. NIST SP 800-171 requires some sort of password definition in IA.L2-3.5.7:


Enforce a minimum password complexity and change of characters when new passwords are created

[a] password complexity requirements are defined;

[b] password change of character requirements are defined;

[c] minimum password complexity requirements as defined are enforced when new passwords are created;

[d] minimum password change of character requirements as defined are enforced when new passwords are created.


IA.L2-3.5.8 also requires some rules around reuse of passwords:

Prohibit password reuse for a specified number of generations

[a] the number of generations during which a password cannot be reused is specified

[b] reuse of passwords is prohibited during the specified number of generations.



One research paper from the Carlton School of Computer Science said it well, 


“Many security policies force users to change passwords within fixed intervals, with the apparent justification that this improves overall security. However, the implied security benefit has never been explicitly quantified. In this note, we quantify the security advantage of a password expiration policy, finding that the optimal benefit is relatively minor at best, and questionable in light of overall costs.”


Some companies have taken the approach of short password, short expiration to make it simpler. This makes passwords more easily hackable, and easily forgettable. 



  1. Don’t use obvious or common phrases or names


Having short and frequent passwords might cause you to get uncreative with your passwords. Using common phrases or obvious words might be easy to remember, but will make your account much easier to hack.


  • Don’t use keyboard patterns. Qwertyuiop is on the list of top 100 passwords and will be a standard in password cracking attack. 1q2w3e4r5t is not good either.

  • Don’t use password, admin, 123456, gmail, login … any phrase obvious to you is obvious to a hacker.

  • Don’t use your name, birthday, or company name.

  • Don’t use the same password for everything. Someone hacks your newspaper subscription account with password123 - not good. Someone hacks your bank account with password123 - really bad!



What makes a good password?


No matter what: the longer the password, the better. Length is the single most important characteristic of the security of a password. Even without complexity like adding a special character, longer is better, and short reset periods only encourage users to defeat security principles by having easy to crack passwords, writing and posting them, and reusing the same weak passwords repeatedly.


So, what should companies and individuals be thinking of when setting their passwords? Here are some quick hints on how you might easily craft memorable, and very hard to crack passwords.


  1. Use a favorite phrase. Not common, but a favorite. Perhaps an inside joke, or something your family or boss would always say.

  2. Use a favorite song. If you love the classics, The Sound of Music is a good example. These could be: DoeADeerAFemaleDeerRayADropOfGoldenSun, Dadafdradogs1965. Catchy and easy to remember, but hard to guess.

  3. Use a famous quote. More classics for you: The Princess Bride and Winston Churchill. MyNameisInigoMontoyaYKMFPTD or Anybodywantapeanut?Inconcievable! 1945Neverevergiveup or Ifyouaregoingthroughhell1955. 

  4. Remember special characters are always good, but length is the most important attribute. [ and ] are the least used special characters according to some research. You can try using them to frame your passphrase.

  5. Change your methods. Mypassword2019 to Mypassword2020 is not a good strategy. High-end nation-state hackers can take your password from a previous breach and use it to crack your current password. 

  6. Use more complex passwords for higher risk logins. Your newsletter subscription or login to your grocery store points getting hacked might not be the end of the world (depending on how many points you have…), but for your banking or company accounts, complexity is crucial.

  7. Visit https://haveibeenpwned.com/ to see if your account has been seen on the dark web.


Consider if it's time to rethink your password policy. Compliance standards do mandate requirements and expirations, but a shorter time and special characters do not guarantee security improvements. Do you know your company’s password requirements? How long have you been using your password? Do you have a go-to password that needs retiring?



 
 

contact@cybersecgru.com‪                                                                                                                  (727) 316-5720‬

bottom of page