Industry Insights

Blog, Tip of the Week

Tip of the Week: How to Make Your Credentials More Memorable

by | Wednesday, December 18th, 2019

Let’s face facts: as critical to your security as they are, passwords are the worst. Of course, since they are so dangerous, you need to make sure all of the ones you use are as secure as possible, so we’ve assembled some practices that may help you tip the scales in your favour. Spoiler alert: the current password may not be your first choice for much longer.

What Not to Do

There’s a tricky balance to strike when devising a password. On the one hand, you want it to be sufficiently secure, but on the other, you don’t want to make it too difficult to get back in for yourself, either.

This is probably the reason that so many password rules and best practices are broken and ignored: user convenience.

Let’s take a look at the top 15 results of some data compiled by the United Kingdom’s National Cyber Security Centre with the help of the security website Have I Been Pwned, regarding the most commonly breached passwords:

  1. 123456 
  2. 123456789 
  3. qwerty 
  4. password
  5. 1111111 
  6. 12345678 
  7. abc123 
  8. 1234567 
  9. Password1
  10. 12345 
  11. 1234567890
  12. 123123 
  13. 000000 
  14. Iloveyou
  15. 1234

Just glancing over this list, you can very easily see how a few of the simplest password quality rules are broken – common words, common number strands, and hardly any mix of alphanumeric characters.

It is probably also a safe bet that a person who would use a password like this would also be the person to repeat their password across accounts. This means that if one of their accounts were breached, they all would be rendered insecure. 

Of course, now that we’ve clearly outlined the problem, we have a proposed strategy to help fix it.

Using a Truly Random Passphrase

One way that you can improve upon password security is known as the passphrase. Instead of using random characters, random words are used, helping to make it both more complicated and easier to remember.

The webcomic xkcd does an excellent job of explaining it:

However, this opens us up to new issues – like the very human instinct to stick to a pattern of some sort. Useful for survival, not so great when you’re looking for true randomness.

This is why an IT professional named Arnold Reinhold developed a new method of generating a passphrase, called Diceware.

Taking a die, roll it five times, taking note of the numbers you’ve gone. Whatever the 5-digit number you produced was, find it on the official Diceware word list. That is now the first word of your passphrase. Repeat this process until you have six or seven words in your passphrase. This helps eliminate human bias from the selection process, making this process as random as possible.

Demonstrating Diceware in Action

Rolling a die, I came up with 45656. Diceware says that’s “pleat.”

My next roll came up 13211. “Bach.”

34663, making the following word “Julie.”

32135 means the next name is “gulp.”

32565, for a final name “choice” of “Hera.” 

So, my new passphrase is “pleatBachJuliegulpHera.” Gibberish, yet still far more memorable than the alternative system.

Remembering All These Passphrases

So, with the “random” part of our concerns addressed, there is still the concern that remembering so many different passphrases may be a bit much to ask. This is why we recommend that you combine your use of passphrases with the use of a password manager.

These handy programs secure all of your passwords (or passphrases) in a secure vault, ready for you to access with a single master password (or passphrase). As a result, as long as you can remember one passphrase, you can use the password manager to handle the rest of your accounts.

For help in implementing all of this (or with any other assistance with your business’ information technology), give Compudata a call at 1-855-405-8889. What other tips would you like us to cover? Let us know in the comments, and subscribe, so you don’t miss it!

A Glimpse Into What Compliance Looks Like for Businesses

It’s easy to see all the reasons why you should make data regulations and compliance a priority. After all, you want to ensure you don’t violate the trust and security of your customers, as well as the integrity of your operations. If you make even one mistake, it...

AI Search Isn’t There Yet

People do this all the time: if they don’t know an answer, they just make something up that sounds right. It turns out AI has the same bad habit. A Study Put AI Search to the Test, and It Did Not Go Well Researchers at the Tow Center for Digital Journalism (part of...

Remote Work Is Great, but There Are Some Pitfalls

Do you have employees working remotely? If you do, the real question is, are you doing everything you can to keep them productive and secure? Remote work is awesome, but it comes with its fair share of risks. Today, we get into how to competently confront them. Remote...

Hiring IT is Hard (Here’s How to Make It Easier)

Do you have someone on your staff who can handle most IT-related issues for your business? If not, we’re sure your organization feels it in more ways than one. The issues that come from not having IT help are only made more frustrating when it comes time to find IT...

Let’s Take the Lid Off of CAPTCHA

We've officially reached the point where humans have to prove they're, well, human just to access websites. One of the most common ways to do this? CAPTCHA. CAPTCHA stands for Completely Automated Public Turing test to tell Computers and Humans Apart. It might sound...

Automation Isn’t Always the Best Business Option

Automation makes sense from an operations standpoint, and people see this despite the many who advocate for scaling back to save jobs. For every task that can be completed, however, less than half can be automated. When you consider all the tasks that a human might be...

More Reading from Industry Insights:

AI Search Isn’t There Yet

People do this all the time: if they don’t know an answer, they just make something up that sounds right. It turns out AI has the same bad habit. A Study Put AI Search to the Test, and It Did Not Go Well Researchers at the Tow Center for Digital Journalism (part of...

Hiring IT is Hard (Here’s How to Make It Easier)

Do you have someone on your staff who can handle most IT-related issues for your business? If not, we’re sure your organization feels it in more ways than one. The issues that come from not having IT help are only made more frustrating when it comes time to find IT...