Most Website Security Breaches come from uninstalled patches
Website Security Services by Computer Concierge
Selecting Passwords

Inside This Site

Home
Website security report
Security Reporting
Security Maintenance
Selecting Passwords
Search Engines
Products / Services
Contact Us
 


Inside this Section
Up ] Website security report ] Security Reporting ] Security Maintenance ] [ Selecting Passwords ] Search Engines ] Products / Services ] Contact Us ]

Selecting Passwords

Rationale

The object when choosing a password is to make it as difficult as possible for a cracker to make educated guesses about what you've chosen. This leaves him no alternative but a brute-force search, trying every possible combination of letters, numbers, and punctuation. A search of this sort, even conducted on a machine that could try one million passwords per second (most machines can try less than one hundred per second), would require, on the average, over one hundred years to complete.

What Not to Use

bulletDon't use your login name in any form (as-is, reversed, capitalized, doubled, etc.).
bulletDon't use your first or last name in any form.
bulletDon't use use your spouse's or child's name.
bulletDon't use other information easily obtained about you. This includes license plate numbers, telephone numbers, social security numbers, the brand of your automobile, the name of the street you live on, etc.
bulletDon't use a password of all digits, or all the same letter. This significantly decreases the search time for a cracker.
bulletDon't use a word contained in (English or foreign language) dictionaries, spelling lists, or other lists of words.
bulletDon't use a password shorter than six characters.

What to Use

 
bulletDo use a password with mixed-case alphabetic characters.
bulletDo use a password with nonalphabetic characters, e.g., digits or punctuation.
bulletDo use a password that is easy to remember, so you don't have to write it down.
bulletDo use a password that you can type quickly, without having to look at the keyboard. This makes it harder for someone to steal your password by watching over your shoulder.

Method to Choose Secure and Easy to
Remember Passwords

 
bulletChoose a line or two from a song or poem, and use the first letter of each word. For example, ``In Xanadu did Kubla Kahn a stately pleasure dome decree'' becomes ``IXdKKaspdd.''
bulletAlternate between one consonant and one or two vowels, up to eight characters. This provides nonsense words that are usually pronounceable, and thus easily remembered. Examples include ``routboo,'' ``quadpop,'' and so on.
bulletChoose two short words and concatenate them together with a punctuation character between them. For example: ``dog;rain,'' ``book+mug,'' ``kid?goat.''

 
Excerpts from
IMPROVING THE SECURITY OF YOUR UNIX SYSTEM
David A. Curry, Systems Programmer
Information and Telecommunications Sciences and
Technology Division
ITSTD-721-FR-90-21
 
 Website Security Services provided by Computer Concierge Intl.
Copyright 2003, All Rights Reserved