Pages

Wednesday, October 5, 2016

So many Password!!!!

These days you need a password for everything you do online.  You need a computer password for the operating system.  You need one for email.  Then you need one for Facebook, Twitter, your bank account and the list goes on.  So my question to you is, do you have a different password for each service you log into or do you use the same password?  How secure is your password?  Do you ever change your passwords and if so how often?  These are questions we will look at today and I will give you ways to protect yourself.

Password Security

So you think you have a secure enough password do you.  Well think again!  On average over 98% of people do not have secure passwords and leave themselves open to hacking.   So what should you do and what rules should you follow.

All password should be at least 8 - 10 characters in length minimum.  Your password should contain uppercase and lowercase characters, numbers and symbols.  I can already hear you saying, "what, are you crazy?  How am I suppose to remember that?"  Well the answer is easily.  I have two ways for you to do this.  

Use a Password Manager like LastPass or KeePass

When creating a password you should never use any words that can be found in the dictionary.   Today's brute force crackers use the English dictionary as a source when hacking your password.   Your password should look something like Ak6$Bu8×$Z.  The easiest way to do this is with a password vault that can generate passwords like this for you.  I have used LastPass, an online solution, for a few years now.  You store each websites login credentials in your LastPass account.  You never have to remember your passwords as LastPass will have this information and type it in for you.  Cost is very cheap.  The key here is to ensure your LassPass login password is very secure and that you change it at least every 90 days.  This is an online option and I have never had any issues at all.  I also recommend setting up a 2-step verification for LastPass as well as any online account you have.  What this means is you enter your username and password in and once entered you are then prompted to enter a special one time code.  Most of these codes are either set to you in a text message and are only good for 30-60 seconds.  The other option is to associate your account with a code generator that will provide you a new code every 60 seconds.  This can be an app you install on your smartphone.

If you don't like the idea of a cloud based solution you can always use the free version, KeePass.  This is an actual software program you can download free of charge onto your phone or computer.  Security is very tight and it can generate a random password for you to use with each online account.  This program will also auto-populate your login screen with the correct credentials when you tell it to.  In all a great option when you need a different password for every online login account you have.

Again I cannot stress how important a 2-step verification is.  If your online account offers it, I highly recommend you take advantage of this option.  If anyone were to ever get your login password for any online account, they would be stopped at the 2-step verification page.

Change your password often

The easiest way to ensure that your password is safe and secure it to change it as often as you can.  I recommend every 60-90 days.  Anything more and you could run into problems.  I have clients that have used the same password for years.  This is a time bomb waiting to explode.  Also when changing your password, you should never use the same password as you have used before.  This is why a password generator is so nice.  It will always generate a random password that meets your criteria.

Has your online account been compromised?

Ever hear in the news that a large company has had their website hacked and account information has been compromised.  This happens more then you think.  If you use the same password in several sites, it is not hard for a hacker that has your login info from a hacked site to access other online accounts you have.  This is exactly why it is important to have a different and secure password at all sites with a  2-Step Verification.

If you want to see whether an email address you have is associated with a hacked site, check out this link.  Enter any email address you use to log into an online account and it will tell you if you belong to any site that has been hacked.  Also sign up with your email account to be notified immediately if an online account you are associated with has been hacked.  You may be surprised in what you find.


At the end of the day your user account and password is your life.  If you don't take care you could be opening your life up to hackers around the world.  Be careful and monitor your accounts as well as you monitor your home security.  Well do your best.