In Depth
Technology
Passwords
Dealing with 'password inflation'
Oct. 1, 2007
By Joanna PachnerCBC News
W0t, @ga1n!? Every month (if you're lucky), corporate information technology forces you to change your e-mail, network and other log-in passwords.
On top of that, there are numerous websites and accounts that demand passwords for access. A recent survey by RSA Security, a Bedford, Mass., consulting company that advises businesses on security issues, found that one in five business people are juggling more than 15 passwords.
Managing this "password inflation" leads people to get lazy, using easily guessed words or dates and writing them down where they can easily be found. Two-thirds of the respondents to RSA's study said they knew co-workers who kept their passwords on pieces of paper, and 40 per cent have seen passwords on Post-it notes stuck on workstations. The study also found that at some large companies, as many as half of all requests flowing into IT help desks involved forgotten or compromised passwords.
Passwords people choose are, on average, very weak. People are underestimating the level of ingenuity and determination on the part of hackers.
— Telus security expert Richard Reiner
"For business, passwords are a huge concern," says Richard Reiner, chief security and technology officer for Telus Security Solutions. "Passwords people choose are, on average, very weak. People are underestimating the level of ingenuity and determination on the part of hackers."
In fact, research shows that more than half of all passwords can be cracked within a few minutes, he says.
Choosing a password
Strictly from a security perspective, the best passwords involve lengthy combinations of numbers, letters and punctuation marks. The worst are those comprising any piece of information that can be associated with you, such as your birth date or phone number. But any word or combination of words in the dictionary can easily be cracked by hackers' software utilities.
Those who use the same password for many accounts invite the most danger.
"The risk is that one site they use might be hacked, compromising all their other accounts," Reiner says.
The most effective security solutions combine a password with a biometric reader or an ID fob — a small electronic key that allows access to a computer — or, as Reiner puts it, "something you know and something you have."
Reiner recommends two password-creation techniques. One is to download software such as the free Acerose Password Vault. You install it on your computer, create one strong password that logs you into the program, then the software automatically generates and/or remembers all your other passwords.
The other approach for creating hard-to-crack passwords is to think of a familiar phrase — a line from a favourite song or a private joke, for example — then figure out a pattern of scrambling the letters. For instance, the password could use the first letter of the first word in the phrase, second letter of the second word, and so on.
Password-creation techniques
Here are some other suggestions, culled from a range of sources, for devising passwords that are both secure and easy to remember:
- Use the calendar. Type in the month, year and a few letters to identify the account, such as "sep06Budgt." The following month, change "sep" to "oct." No repetitions. No-brainer.
- Add characters. Take the name of the account or website, then add, say, the last four digits of a familiar phone number (though never your own). That might produce "bizblog9485."
- Use mnemonics on random passwords. If you get a password assigned, don't change it — just find a way to remember it. Say you got "4tgGw39DK." That could become, "For the great Google warrior 39 Donna Karens." Not poetry, but say it a few times and it turns into a mental tattoo. You can get random character strings from free online utilities like Passnerd.com and BizFormBar.com.
- Combine small, misspelled words. To make a password easier to remember, use words starting with the same letter and perhaps related meaning (hyheihallo), then perhaps capitalize the first letters (HyHeiHallo) or break the words up with numbers (Hi1Hei2Hallo3), or substitute numbers for some letters (h1h3ihall0).
- Use first letters of a phrase. "mygolfhandicapis6," for example, would become "mghi6."
- Devise a code. Nothing techy here, just a simple scrambling system. For example, if your password phrase is "MyHandicapIs6," move one key to the right for each character: "
- Keypad scramble. Take a name or phrase you can easily remember, then type it using the phone keypad. "MyHandicapIs6" could become “my4263422747six."
- Scramble words. For instance, alternate the letters of each word, so "MyHandicapIs6" could become "MHI6yasndicap."
- Use special keys. Hold down the shift or alt key as you type part of your password. With the Alt key down on every third character, our handicap password becomes "my·anðicåpis§."
- Add spaces. Assuming the company's or website's password protocol allows it, it's a good way to foil dictionary searches. You might have "myhan dicapi s6."
- Remove vowels. "Mhndcps6."
The beauty of using these approaches is that this way, you can surreptitiously reuse a single password. Then, when you run out of tricks, you'll just need to get your handicap down to five.
Menu
Technology
- Green machines
- Disk drive: Companies struggle with surge in demand for storage
- Open season: Will court decision spur Linux adoption?
- Analogue TV
- Video games: Holiday season
- Video games: Going pro
- Guitar Hero
- Parents' guide to cheap software
- Working online
- Laptop computers for students
- Technology offers charities new ways to attract donations
- The invisible middleman of the game industry
- Data mining
- Two against one
- The days of the single-core desktop chip are numbered
- Home offices
- Cyber crime: Identity crisis in cyberspace
- Yellow Pages - paper or web?
- Robotics features
- iPhone FAQ
- Business follows youth to new online world
- A question of authority
- Our increasing reliance on Wikipedia changes the pursuit of knowledge
- Photo printers
- Rare earths
- Widgets and gadgets
- Surround Sound
- Microsoft's Shadowrun game
- Dell's move to embrace retail
- The Facebook generation: Changing the meaning of privacy
- Digital cameras
- Are cellphones and the internet rewiring our brains?
- Intel's new chips
- Apple faces security threat with iPhone
- Industrial revolution
- Web developers set to stake claim on computer desktop with new tools
- Digital photography
- Traditional film is still in the picture
- HD Video
- Affordable new cameras take high-definition mainstream
- GPS: Where are we?
- Quantum computing
- What it is, how it works and the promise it holds
- Playing the digital-video game
- Microsoft's forthcoming Xbox 360 Elite console points to entertainment push
- Online crime
- Botnets: The end of the web as we know it?
- Is Canada losing fight against online thieves?
- Malware evolution
- Money now the driving force behind internet threats: experts
- Adopting Ubuntu
- Linux switch can be painless, free
- Sci-fi projections
- Systems create images on glass, in thin air
- Power play
- Young people shaping cellphone landscape
- Digital cameras
- Cellphone number portability
- Barriers to change
- Desktop to internet
- Future of online software unclear: experts
- Complaining about complaints systems
- Canadian schools
- Multimedia meets multi-literacy age
- Console showdown
- Comparing Wii, PS3 and Xbox 360 networks
- Social connections
- Online networking: What's your niche?
- Virtual family dinners
- Crackdown
- Xbox 360 console game
- Vista and digital rights
- Child safety
- Perils and progress in fight against online child abuse
- Biometric ID
- Moving to a Mac
- Supply & demand
- Why Canada misses out on big gadget launches
- Windows Vista
- Computers designed for digital lifestyle
- Windows Vista
- What's in the new consumer versions
- Cutting the cord
- Powering up without wires
- GPS and privacy
- Digital deluge
- RFID
- Consumer Electronics Show
- Working online
- Web Boom 2.0 (Part II)
- GPS surveillance
- Hits and misses: Best and worst consumer technologies of 2006
- Mars Rovers
- Voice over IP
- Web Boom 2.0
- Technology gift pitfalls to avoid
- Classroom Ethics
- Rise of the cybercheat
- Private Eyes
- Are videophones turning us into Big Brother?
- Windows Vista
- Cyber Security
- Video games: Canadian connections to the console war
- Satellite radio
- Portable media
- Video games
- Plasma and LCD
- Video screens get bigger, better, cheaper
- Video games:
- New hardware heats up console battle
- High-tech kitchens
- Microsoft-Novell deal
- Lumalive textiles
- Music to go
- Alternate reality
- Women and gadgets
- High-tech realtors
- The itv promise
- Student laptops
- Family ties
- End of Windows 98
- Bumptop
- Browser wars
- Exploding laptop
- The pirate bay
- Stupid mac tricks
- Keeping the net neutral
- PS3 and WII at E3
- Sex on the net
- Calendars, online and on paper
- Google, ipod and more
- Viral video
- Unlocking the USB key
- Free your ipod
- In search of
- Xbox
- Sony and the rootkit
- Internet summit
- Electronic surveillance