Avoiding Password Hell

Some people seem to think that long, complicated passwords that change frequently are great for security. They couldn't be more wrong.

By sjvn  2 comments

After pointing out that running multiple anti-virus or firewall programs on the same PC is a really bad security idea, some of my readers reminded me that that's not the only common, but stupid, idea people have about security. Another far too popular, and dumb, idea is that making users use long, complicated passwords that change frequently is good for security. No, it's not.

As Jonathan Yarmis, a research fellow at the research company Ovum, pointed out to me, "My favorite is onerous password requirements. 17 letters, characters and numbers. Changed every 30 days. No repeats nor anything similar. GUARANTEES that the person has to write it down within 5 feet of their computer."

Yep, he's got that right. If you make your password policy a major pain-in-the-rump you'd just make it a sure thing that no one will use their passwords safely. Yarmis isn't make his example up. I knew one company where the passwords had to be 20-characters long and changed every month. Of course, no one at that business took their password policy seriously and, sure enough, they had their servers raided within a year.

If you make basic security hard to do, you only make certain that it won't be used. It's really that simple.

Of course, writing down your passwords may not be that awful an idea. As no less a figure than security guru Bruce Schneier wrote, "Simply, people can no longer remember passwords good enough to reliably defend against dictionary attacks, and are much more secure if they choose a password too complicated to remember and then write it down. We're all good at securing small pieces of paper. I recommend that people write their passwords down on a small piece of paper, and keep it with their other valuable small pieces of paper: in their wallet."

Notice though that he said to keep in your wallet, or some other reasonably secure location. I mean, you may not notice if a piece of paper on your desk disappears, but you'll certainly know if your wallet goes missing.

But what about if you have to deal with dozens of passwords for multiple Web sites? You could put those passwords on paper, but with as many passwords as we're stuck with using these days that can quickly become a pain in its own right.

At the same time, the last thing you want to do is to make those classic mistakes of using your name, wife's name, etc. as a password. That's just asking for someone to get into your accounts.

What I use these days for managing my mess of passwords are password managers. Some operating systems, like Mac OS X and Linux, have programs such as KeyChain to help you keep track of your passwords while maintaining their security. There are also standalone programs like the open-source KeePass for Windows and 1Password for Mac OS X to make life easier.

Specifically for Web use, I highly recommend Xmarks. This add-on program for most of the major Web browsers-Internet Explorer, Chrome, Firefox, and Safari-not only can securely track your passwords for you, it also lets you keep a common set of bookmarks for all your computers. I started using Xmarks because of this latter feature, but as time has gone on I've grown to appreciate its password management functionality.

No matter what you use though the point for keeping passwords useful is to both make them easy to use and secure. If you neglect either part, you might as well forget about securing your systems. Only by balancing ease of access and password strength will you be able to keep either your own, or your company's, PCs safe.

2 comments

    Anonymous 2 years ago
    My company required change password every 28 days.Rules: Number + Char (upper and lower case) + Symb and Min 9 Words and can't be repeated..For me, it just make less security rather than change it every 3 months.. who can remember those password unless they using dictionary word ??
    Anonymous 2 years ago
    Have dozens of passwords to remember? Get and use Roboform. It's free and you only have to type in your password once. You can even encrypt the program so you only have to remember one password if you so desire. And when you have to change your password, Roboform pops up so you can tell it to remember the new one. The program is also handy in that you click in the password which pretty much defeats keystroke loggers.

      Add a comment

      Post a comment using one of these accounts
      Or join now
      At least 6 characters

      Note: Comment will appear soon after you have activated your account.
      Obscene/spam comments will be removed and accounts suspended.
      The information you submit is subject to our Privacy Policy and Terms of Service.

      ITworld LIVE

      SecurityWhite Papers & Webcasts

      White Paper

      Overcome Top 7 Admin Challenges of Active Directory

      As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable, enforceable processes that reduces administrative overhead and enables robust, customizable reporting and auditing capabilities. Brought to you by NetIQ.

      White Paper

      Insiders Can Ruin Your Company. Take Action.

      Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in organizations worldwide. This white paper from NetIQ, discusses key technology solutions that help to prevent and detect insider threats.

      White Paper

      Top Solutions and Tools to Prevent Devastating Malware

      Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring (FIM) tools that provide immediate alerts. This white paper has been brought to you by NetIQ, the leader in solving complex IT challenges.

      White Paper

      Streamline Compliance and Increase ROI

      Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will help your business gain the maximum return on investment possible while aligning your compliance programs.

      White Paper

      X-Ray of the PCI Process-4 Proactive Steps

      This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into creating a compliant and secure IT environment. Follow these four proactive steps now before your next audit. Brought to you by NetIQ.

      See more White Papers | Webcasts

      Ask a question

      Ask a Question