HOW TO SET UP A STRONG PASSWORD

Many password breaches and website hacks usually make our passwords unsafe after some time. For these reasons, it is advisable to change our passwords frequently. How often you change your password may depend on you, and how you handle your digital security.

SECURITY CONCERNS ABOUT THESE SITES?

Passwords have come to stay with us, from our mobile phones, TVs, and Cars to doors, as a result of cyber threats, we always need some form of authentication. We now live in a world where password is part of our daily lives.

HOW STRONG IS YOUR PASSWORD? 

Passwords are usually private strings of characters that are mostly encrypted and used to authenticate access to some resource. It is always good to note that no password whatsoever in the field of digital computing is uncrackable. All passwords can be cracked given enough tools, time, and resources. Most of the cracking tools are available online, but the challenge lies with the resources and time. The strength of your password determines how long it will take a threat actor to crack it, therefore one of the best ways is to keep your passwords longer with all kinds of characters. It could be a passphrase (password phrase e.g. "d3 $ King 1z back"). 
Though equivalent tools keep popping up to compete with the complexity of passwords and passphrases, some websites and security firms provide free services to check how safe our passwords are, and how long it may take a threat actor to crack them.
Of all these threats, at times passwords get leaked without our involvement. Imagine saving your login credentials on a certain website, and later the website gets hacked, chances will be that your password is stolen and that becomes more dangerous if it is leaked or sold. Hackers and crackers keep a huge database of passwords that can be used for attacking or cracking purposes.
It is safe to check periodically if your password has been compromised, is good enough, is available online, and is safe to use.

CHECKING IF YOUR PASSWORD HAS BEEN COMPROMISED

There are several ways of checking if your password is safe. First, let's check if the passphrase(d3$King1zback) is available online.

Kaspersky provides a free online password checker tool to see if your password has been leaked and also checks the strength to see how long it will take a cracking software to crack it.

Kaspersky online password checker
Kaspersky password checker

As indicated, the password provided above is clean such that it is not available in any compromised or leaked password database online and it will take about 37 years to crack it!

Another good online service for checking if your passwords are safe is the "havibeenpwned" service which has been running for a while now. It's one of the earliest services that checks if your email has been compromised but now added password checkers. It doesn't come with brute-forcing checker.

havibeenpwnd password checker
havibeenpwnd password checker

The password tested is "11223344" and as indicated, it has been used 363,840 times in leaked password databases. In reality; the exact figure could be 3 times more, but since some may not have been exposed, only this figure is seen now. What the indication above means is that 11223344 is a very weak password and can be guessed or used against a target easily hence it must never be used. 

Another interesting tool that checks password strength is provided by security.org, this tool checks your password strength and reports how long it will take a cracking tool to expose your password.

security.org password checker
security.org password checker

The password being tested is "besTm@n$" and according to the tool, it will take a good computer approximately 2 hours with a good processing power to crack it. 

SECURITY CONCERNS ABOUT THESE SITES?

One may ask? How safe are these websites themselves? For a user to test his passwords there? These websites don't know who you are and do not save the passwords you type. They do not know which websites you use and cannot tell or predict your username(s). Since no one can log in to websites you are registered on without usernames and more recently 2FA ( 2 Factor Authentications) if activated, they are presumed safe!
Give it a try, and see how safe your current password is, you may be surprised!
password checkers
password checkers

SOME BAD PASSWORD PRACTICES?

  • Never set passwords in the evening or the night (you are likely to forget)
  • Never include your date of birth in your password 
  • Never include your relative's name in your password
  • Never use a 4-letter password
  • Never use only lower or upper case letters in your password
  • Never use your phone number in your password
  • Never use your child's birthday in your password
  • Never use a date as your password.
Your password must always be something unpredictable!



 

Comments

Popular posts from this blog

DON'T BUY A PEN DRIVE WITHOUT READING THIS!

THINGS THEY DON'T TELL YOU ABOUT CYBERSECURITY

PEN DRIVE FRAUD ALERT: VERIFY YOUR USB STORAGE WITH THESE TESTS