Blog Layout

Your password may not be secure — update it now

Engage Team • August 7, 2020

The problem

The issue isn’t that the NIST advised people to create easy-to-crack passwords, but their previous advice inadvertently made people create weak passwords using predictable capitalization, special characters, and numbers, like “P@ssW0rd1.”

Such a password may seem secure, but the strings of characters and numbers could easily be compromised by hackers using common algorithms.

What’s more, the NIST also recommended that people change their passwords regularly, but did not specify how and when to change them. Since many people thought their passwords were already secure because they’ve included special characters in them, most only added or changed one character.

The NIST essentially forced everyone to use passwords that are hard for humans to remember but easy for a hacker’s algorithm to crack.

Eventually, the institution admitted that this can cause more problems than solutions. It has reversed its stance on organizational password management requirements, and is now recommending banishing forced periodic password changes and getting rid of complexity requirements.

The solution

Security consultant Frank Abagnale and Chief Hacking Officer for KnowBe4 Kevin Mitnick both see a future without passwords. Both security experts advise enterprises to implement multifactor authentication in login policies.

This requires a user to present two valid credentials aside from a password to gain access to an account. This could be a code sent to the account owner’s smartphone, a login prompt on a mobile device, or a facial or a fingerprint scan. This way, hackers’ login efforts are futile unless they fulfill the succeeding security requirements.

Moreover, Mitnick recommended implementing long passphrases of 25 characters or more, such as “recedemarmaladecrockplacate” or “cavalryfigurineunderdoneexalted.” These are much more difficult to guess and less prone to hacking. As for the frequency of changing passphrases, it will depend on a company’s risk tolerance.

Simply put, passwords should be longer and include nonsensical phrases and English words that make it almost impossible for an automated system to crack.

You should also enforce the following security solutions within your company:

  • Single sign-on – allows users to securely access multiple accounts with one set of credentials
  • Account monitoring tools – recognizes suspicious activity and locks out hackers

When it comes to security, ignorance is your business’s kryptonite. If you’d like to learn about what else you can do to remain secure, just give us a call.


Published with permission from TechAdvisory.org. Source.

By Engage Team October 28, 2020
1. Arrange, sort, and prioritize
By Engage Team October 22, 2020
Understand the threats you’re facing
By Engage Team October 15, 2020
Phishing remains one of the top cyberthreats to businesses today. Because of this, Microsoft invests a lot of time into securing its email service. Among the many business solutions that Microsoft offers is email hosting through Outlook. This service is protected by Microsoft Defender for Office 365. Defender has many key features:
By Engage Team October 9, 2020
Be an early adopter
By Engage Team October 7, 2020
As its name suggests, Windows 10 Home is designed for home and personal use. It comes bundled with key Windows 10 features, such as the Microsoft Edge browser and the voice-enabled virtual assistant Cortana. It also gives access to Microsoft's cloud storage service OneDrive and provides 5 GB of cloud storage per individual user. However, Windows 10 Home doesn’t come with Office apps like Word, Excel, and PowerPoint. Instead, it gives you a 30-day free trial of Microsoft 365. In terms of security, Home has fairly basic protections. It has Windows Defender Antivirus software, Windows Hello biometric logins that use face or fingerprint authentication, and rudimentary device encryption to keep data breaches at bay. Those with multiple Windows devices will also love the mobile device management app, which allows them to track and control app usage for connected smartphones and tablets. To explore new apps, Home users can sign up for the Windows Insider program, but since this version is light on features, there is usually a limited selection of early release apps to play with.
By Engage Team October 5, 2020
What is a VPN?
By Engage Team September 23, 2020
Work on Word Online
By Engage Team September 18, 2020
Over the years, marketing automation has become more accessible to small businesses. Thanks to innovative cloud solutions, large and small enterprises can reap the benefits of automating tedious marketing tasks. Here are a few advantages to automating your small business’s marketing efforts.
By Engage Team September 16, 2020
Windows 10 offers a wealth of customization features designed to provide users with a truly personalized and intuitive experience. Whether it’s changing the color of your windows or rearranging the tiles on the Start menu, these features will make your Windows PC a better match for your needs and preferences. Check out some of them below.
By Engage Team September 14, 2020
Use separate email accounts
More Posts
Share by: