New Password Standards | Data Security | Ohio CPA 公司 | 意图 CPA-安全的赌博软件

Passwords: Turns Out We’ve Been Doing It Wrong This Whole Time

 

How To Create A Better Password

Editor’s Note: Hackers will continue to look for new ways to outsmart their targets so, 在回应, we must remain vigilant when it comes to protecting ourselves and our organizations. The strength of our passwords is key in our efforts to thwart cyber attacks and data breaches. This article was originally published in 2017. However, the message is just as important and valuable as ever. Now then, let’s all improve our password practices!


Ever wonder who’s responsible for today’s password protocol? Think about the rules we’ve all grown to know and tolerate … like using special characters, changing passwords regularly, incorporating irregular capitalization, and making sure to include at least one number … who came up with these standards and how did they determine their effectiveness?

* Drum roll please *

That would be the National Institute of Standards and Technology.

This organization set a precedent when it published “NIST Special Publication 800-63, Appendix A” back in 2003. It was at that time that the security requirements listed in that publications became standard issue for today’s digital identity guidelines. 回想起来, 比尔伯尔, NIST manager at the time, admitted that much of the 2003 document was somewhat misguided.

In 2017, several notable security experts took a stab at revising the document. This new version effectively rewrites the rules when it comes to defining the “right” way to craft secure passwords.

Think Smarter, Not Harder

事实证明, Burr and his colleagues had been proposing the use of passwords that actually make them harder for humans to remember, but easier for computers to crack. The crazy password concoctions proposed might seem secure on the surface, but most people end up using the same techniques – and that is what makes them easy for hackers to predict and algorithms to target.

Choose Long-Term Relationships

When it comes to the practice of regularly updating your passwords, the experts now tell us that changing passwords 每90天 is a terrible idea. This almost forces users to make easy-to-crack passwords. When prompted to change their password, people tend to get lazy (shocker) and just change their existing password slightly in order to remember it (i.e., P@ W0rd123美元美元! P@ W0rd456美元美元!).


听...... 集169, “The 网络安全 Battle Plan For Businesses,” on 意图 & 比较靠谱的赌博软件’ award-winning 播客, unsuitable on 意图 Radio, featuring Paul Hugenberg III.

New Password Best Practices

Instead of using the password protocol that was passed down in the NIST’s original document, make it a point to adopt a password strategy that’s actually designed to keep your sensitive data out of the hands of hackers.

  1. Make your passwords longer and leave out the special characters and numbers (unless the website requires it). Trying to remember crazy combinations doesn’t help you out security-wise and makes the password more difficult to remember.
  2. 相反, use phrases with punctuation and spaces 作为密码. 如果可以的话, make the sentence nonsensical and memorable, which will make it almost impossible for systems to make sense of. For example, according to the experts, “Cp@4m3!” could likely be hacked in three days. “Silly button holes drink lemonade,” written as a single phrase, on the other hand, might take 550 years to crack.
  3. Forget about updating your password 每90天. Unless you know the password is weak or was issued automatically, it’s probably safe to leave it alone.

And for those who use password managers to generate cryptographically secure passwords on the fly, you’re still generally in the clear. However, it’s still important to have one hard-to-crack master password. Use the new guidelines to craft passwords that will truly keep your data secure.

Looking for more ways to protect your company from cybercrime? 电子邮件的意图 & 比较靠谱的赌博软件 to speak with a cybersecurity expert today.

By Travis Strong, CISA (伍斯特哦)