Sometimes it is necessary to update a password or sometimes you can't use the default one you use for everything. For things you use regularly I recommend at minimum changing your password every three months, especially for anything that has sensitive information. Not that passwords are all guessable, I love my base one, but I did see 2014 top dumb passwords list and was surprised at how easy some are, including numbers 1 and 2 respectively 123456 and password (http://www.cnet.com/news/worst-passwords-of-2014-are-just-as-awful-as-you-can-imagine/).
If you don't want the hassle of changing all of your passwords, most online services have two factor (basically a number that changes every 30 seconds). So long as you have an accurate time it works nicely. I have seen private ones get blocked by firewalls because the ntp service could not reach the server.
So here are a couple of suggestions for varying strength in passwords.
Simple:
Go to a dictionary (physical book or online) and find a random word (thumb the page for a few seconds and stop after about 3-7 then find a word on the page or choose a random word from your favorite dictionary site). Convert that word into leet (1337) there are various methods of doing this, including online converters that you choose the conversion. Generally I only use a few @ for a $ for s and 3 for e to keep it simple.
Find a poem you like and choose the first letters of each word, or line.
Write a poem and do the same.
Add a ... or ,,, or ??? etc at the end of your current password - (this actually increases it's complexity significantly)
http://creativitygames.net/random-word-generator is a site that I often use as it lets you pick a number of random words.
http://watchout4snakes.com/ is another good one that gives you options to make a phrase etc.
More Complex:
Convert a phrase to leet from your favorite quotes, books, etc.
Grab multiple words in the dictionary (3 to 4 is generally a good amount of security) and throw in random numbers and symbols.
http://www.robertecker.com/hp/research/leet-converter.php
This is my favorite leet converting site. Mostly because it lets you pick a few things thus making it more random or pre-generated if you are lazy ^.^
Most complex:
Use a random alpha numeric and symbol generator (the utility here is from a personal developer I know http://www.maxoutput.com/)
It is actually a networking utility (I use that aspect of it the most) but the fact that it creates random passwords has been a bonus. It even does more than one at once.
From my experience I believe generally 10 to 12 characters minimum is sufficient, but beefier the better.
If you are anything like me you have many variations on your password and cannot always keep straight which one is which. Well I have 3 solutions:
Classic little black book - no one looks for these any more, you can get one for about a dollar at the store for notes and such and just choose a page for passwords.
KeePass - If you don't like carrying notebooks around but always have a flash drive you can use Key Pass. the nice thing about it is it lets you organize everything as well. It does however take a password to open so in reality you only need to remember 1 password so you can access everything else. You can also make notes about each item. It includes a random password creator which is (I think) intended for use as you are making accounts.
Passpack - So I recently started using this because of work. It is nice in that you can share your password with people if you want as well as has 2 layers of passwords before you get to actually see the passwords. The other nice thing is it is online. A simple account is free to use with limited sharing etc but I found I didn't need more than that. You create an account, Then you create what they call a packing key (they recommend using a sentence). Then you can view things, search the database they have and even "hide" things from people peeking over your shoulder. They even include a generator as well I found out the other day.
https://www.passpack.com/online/
I mostly use KeePass as I have used that one the longest and am most comfortable with it.
This one was a bit long but hopefully people will be encouraged to beef up their security a bit.


No comments:
Post a Comment