Using the same password everywhere
The easiest way to remember a password is to use only one, but that’s also the fastest route to disaster. Once a successful phishing attack captures that password – and studies have found that 25% of the time people don’t detect a phishing email – the attacker can breach all your other accounts using the same password.
At a minimum, you should use different and secure passwords in any situation where your identity or financial information could be compromised. Randomly generated passwords for critical personal or financial information is a must.
Varying passwords with a single character
This is a trap many people fall into when asked to change their passwords; they comply by changing a “12” to a “13.” Password-guessing programs are wise to this trick and can sniff it out in seconds.
A variation of this dangerous practice is to include a non-alphanumeric character by tacking “!” onto the end of your existing password. Non-alphanumeric characters should be used within the password, not at either end.
Using personal information in passwords
Avoid using names of relatives, celebrities, sports teams, pet or any other common terms in your passwords. Cracking software automatically looks for the most common combinations like Yoda123. Don’t think that you can protect yourself by invoking personal information like the name of a loved one or your high school mascot. Social networks make it straightforward to find that that information.
You also shouldn’t assume that adding a string of characters to a common name is protection enough. Password crackers know this trick and cycle through combinations of common names and numbers until they hit the right one.
The only truly safe password is one with random – or seemingly random – sets of characters.
Sharing passwords with others
You might have the strongest password in the world, but if you share it with someone you can’t guarantee that THEY are protecting it well. Your passwords are for your eyes only.
Using passwords that are too short
A decade ago, a five- or six-character password was enough to beat most cracking programs, but computers are so much faster now that a six-character password can be guessed by a brute-force attack. Think 8 characters at a minimum, with 12 being best. Pass phrases are even better.
Storing passwords in plain text
One easy way to remember passwords is to store them in a spreadsheet or mail them to yourself. Bad idea. With ransomware criminals hold your data hostage until you pay them a ransom. In the meantime, they can scour your hard drive looking for anything that resembles a password list (or social security number, etc.).
Using recognizable keystroke patterns
“1qaz2wsx” may seem like a pretty tough password to guess until you look at your keyboard and notice the pattern (hacking programs know this). A random series of letters and numbers must be truly random to have a chance.
For ways to manage and generate passwords, see this previous blog posting
*Much of the content for this posting was cribbed from an article from Keeper Security. The original, unedited version may be found here.