Welcome to Bits & Bytes! My name is Steve Shannon, and Iâm the IT Director and Lead Developer here at PromoCorner. This new monthly blog will explore a range of tech topics that are applicable to both the promotional products industry and the world at large. The first topic I want to start with is one Iâve had quite a lot of professional experience with and is pretty universal to everyone. Specifically, letâs talk a bit about passwords.
We all use them. We all forget them from time to time. And many of us (myself included) have likely committed at least one of the cardinal sins of online security:
Never write down your password in a publicly accessible area
Never use passwords that are easily guessable through social engineering
Never, under any circumstances, reuse the same password over and over
But with so many accounts and logins to keep track of these days, remembering and maintaining our passwords can feel like quite a burden without resorting to bad habits like the ones listed above. As such, itâs easy to forget that we use passwords for a reason: they are our first (and sometimes only) line of defense in protecting our digital well-being.
The repercussions of having your account hacked or your personal information stolen should be obvious, so I wonât rehash them here. Instead, I want to go over some easy solutions for lessening the burden of password management.
What is a âgoodâ password?
First off, itâs important to understand what distinguishes a good password from a bad one. The key to a good password isnât complexity; itâs size. Simply put, the longer the password, the better it is. Not long ago passwords with 8 characters were considered good enough, but things have changed. Computers are faster and more powerful, which means hackers and other bad actors are better equipped than ever to crack passwords through simple trial-and-error. Every extra character you include in your password decreases the likelihood of it being cracked exponentially, so the point is to make it long enough that there are so many possibilities that even multiple computers working in tandem wouldnât be able to guess them all. Most online services with login requirements now permit passwords with 32 characters or more.
Now, 32 characters sounds like a lot to remember, but who said they have to be random characters? A computer trying to guess your password through brute force canât by itself distinguish between any of the following potential 8-character passwords:
Z49na6m!
secret23
abc12345
password
As far as a computer is concerned, each one of those passwords (even the word âpasswordâ) has the same statistical chance of being the correct one. Seriously! Mathematically speaking, each of those passwords is equally secure. But the problem is that not all of those passwords are as easy for a human user to remember. And, of course, we wouldnât actually use âpasswordâ because itâs on a list of the most commonly used passwords and thus is way too easy to guess.
With that in mind though, letâs now generate some potential 32-character passwords:
RKBUQaF2XWvXeyagH2c3H5jkfUALFhY3
Fva+)&NTM8x~SZNWF,WP'KQ=k,^72B\(
Iâmonlyhappywhenitâscomplicated!
dragon horse manatee whale zebra
You probably see where Iâm going with this. Each of these 32-character passwords holds up well against a brute force attack, but the last two examples are much easier to remember for a human user, to the point that you may not even need to write them down.
Itâs a common misconception that a good password must be a complex mix of uppercase and lowercase letters, numbers and special characters like exclamation points. Certainly, good passwords can include those things, but in truth a good password should be one that best exemplifies the adage of âsecurity through obscurityâ for everyone except its creator. Arguably, the best way to get there is by increasing your passwordâs length, not just its complexity.
But even if we know what makes a good, secure password, how do we then apply that knowledge to a thousand different login accounts without reusing the same password?
A Possible Solution: Password Managers
A common solution to help avoid password reuse is to employ a password manager service like Dashlane, BitWarden, or even Google. These services store all your login information and secure it behind a single, super-secure âmasterâ password; you can then use the various plugins or apps these services offer to automatically pull up and/or prefill your login info for any account you need access to.
There are many benefits to using a password manager: they limit the number of passwords you need to remember to just one; theyâre computer and browser independent so you can access your passwords from anywhere; and they often include backups of your data, and usually allow easy exports if you also want to maintain a localized hard copy.
However, there are some downsides. Not every service offers a free solution, and installing browser plugins or phone apps may be a hassle for some users. Additionally, using a password manager means storing a copy of all your passwords in one single place. This of course requires a certain degree of trust for the service you choose, not just that theyâre reputable but that theyâre adequately equipped to protect your data against hackers. Unfortunately, recent events prove that even the most trusted and popular password managers arenât immune to security threats.
One such password manager called LastPass has been around since 2008. If youâve seen their name in the news lately, itâs likely because LastPass announced that they had been hacked and had their usersâ personal data stolen by someone who tricked one of their employees into giving up their password. Itâs just one of a growing list of large corporate data breaches in recent years; itâs also an unfortunate example of how even having a good password as a first line of defense isnât always enough to protect yourself.
That aside, if you, like me, sour at the idea of outsourcing your password management, then I have another (arguably better) solution for you.
A Better Solution
To quickly reiterate, the following passwords are all equally secure, mathematically speaking:
mysecret1
mysecret2
mysecret3
The only thing that we changed is the number at the end, but as far as a computer trying to crack passwords is concerned, those passwords are all different.
So, letâs say you have two email accounts, one for personal use and one for business. Youâre anxious to start using good passwords, and youâre resisting the temptation to make the passwords for these accounts the same, but youâre worried about constantly forgetting them. How about this?:
Theyâre both 32-characters long, easy to remember, and yet different from each other. Better still, the passwords themselves tell you which email account theyâre for, so thereâs no confusion as to which is which. Conveniently for this example, the words âpersonalâ and âbusinessâ have the same number of letters, but itâs not about having passwords that are all the same length; itâs about having passwords that are all different but still secure. By applying this concept, you can create any number of secure passwords that are easy for you to remember by using your own personal mnemonics or phrases.
Personally, when Iâm creating a new password, I like to construct them from two parts. The first part is a random-looking string of 12 characters that is actually very easy for me to remember, and the second part is a word or phrase relevant to the account itâs being created for, typically a pun or something that Iâm reminded of when thinking about whatever it is Iâm logging into. It essentially looks like this (but not exactly this):
Twitter account: 3j9ErLp12nW elon sucks
Instagram account: 3j9ErLp12nW instamash potatoes
Bank account: 3j9ErLp12nW money is a double-edged sword
And so forth. Thatâs just my system, but the idea is to come up with a system that works best for you. If you use a consistent method to construct your passwords, you wonât have to commit any more of those cardinal sins of online security, and youâll never have to worry about forgetting a password ever again.
Steve Shannon has spent his entire professional career working in tech. He is the IT Director and Lead Developer at PromoCorner, where he joined in 2018. He is, at various times, a programmer, a game designer, a digital artist, and a musician. His monthly blog "Bits & Bytes" explores the ever-evolving realm of technology as it applies to both the promotional products industry and the world at large. You can contact him with questions at steve@getmooresolutions.com.