How to Select a Password


Your password is KEY to your website's Lock. Selecting and implementin password may mean difference in hacked and secured website.

Selecting a good password is critical and it depends at parts on the product for which the password will be used. Below are some good practices on how to pick a strong and more secure password:

Basics
  • Use at least eight characters, more characters than 8 would be even better.
  • Use a random mixture of characters, upper and lower case, numbers, punctuation, spaces and symbols. e.g I would use & or $ etc between segments of my password.
  • Don't use a word found in a dictionary, English or foreign.
  • Never use the same password twice.
  • Choose a password that you can remember so that you don't need to keep looking it up.
  • Choose a password that you can type quickly, reducing chance of someone discovering it by looking over your shoulder.
  • Never be contended, always be suspicious that it can be taken away.

Dont's

  • Don't use passwords based on name, nickname, birthdate, wife's name, pet's name, friends name, home town, phone number, social security number, car registration number, address etc. This includes using just part of your name, or part of your birthdate.
  • Don't use passwords based on things located near you. Passwords such as "computer", "monitor", "keyboard", "telephone", "printer", etc. are useless.
  • Don't ever be tempted to use one of those oh so common passwords that are easy to remember but offer no security at all. e.g. "password", "letmein".
  • Don't just add a single digit or symbol before or after a word. e.g. "apple1"

Protecting Password

  • Never store your password on your computer except in an encrypted form. Note that the password cache that comes with windows (.pwl files) is NOT secure, so whenever windows prompts you to "Save password" don't.
  • Don't tell anyone your password, not even your system administrator
  • Never send your password via email or other unsecured channel
  • Yes, write your password down but don't leave the paper lying around, lock the paper away somewhere, preferably off-site and definitely under lock and key.
  • Be very careful when entering your password with somebody else in the same room.

How would a potential hacker get hold of my password anyway?

  1. Steal it.  May be your co-worker or friend or passerby can find it lying in your note book. This is common way of passwords compromise. So keep it safe, preferablly remembe it, do not write it. Also remember not to type in your password when somebody could be watching.
  2. Guess it. Ha, keep guessing is one trick, house #, wife / children name, data of birth, car # etc can be simply hacked.
  3. A brute force attack. This is where every possible combination of letters, numbers and symbols in an attempt to guess the password. While this is an extremely labour intensive task, with modern fast processors and software tools this method is not to be underestimated. A Pentium 100 PC might typically be able to try 200,000 combinations every second this would mean that a 6 character password containing just upper and lower case characters could be guessed in only 27½ hours.
  4. A dictionary attack. A more intelligent method than the brute force attack described above is the dictionary attack. This is where the combinations tried are first chosen from words available in a dictionary. Software tools are readily available that can try every word in a dictionary or word list or both until your password is found. Dictionaries with hundreds of thousands of words, as well as specialist, technical and foreign language dictionaries are available, as are lists of thousands of words that are often used as passwords such as "qwerty", "abcdef" etc.

The best method for choosing passwords

  1. Make up a sentence you can easily remember. Some examples:
    • I have two kids: Jack and Jill.
    • I like to eat Dave & Andy's ice cream.
    • No, the capital of Wisconsin isn't Cheeseopolis!
  2. Now take the first letter of every word in the sentence, and include the punctuation. You can throw in extra punctuation, or turn numbers into digits for variety. The above sentences would become:
    • Ih2k:JaJ.
    • IlteD&A'ic.
    • N,tcoWi'C!

webhosting company

  • 69 Users Found This Useful
Was this answer helpful?

Related Articles

How Do you Know that You are Being Hacked

Why someone would hack my website: Most website owner would like to know the answer to the...

How to Protect your website from Hacking

How to Protect a Website from Hacking: Accept Respobsibilty: This is first step, do you know...

10 Tips for WP Security

WordPress security should not be taken lightly else you keep getting attacks one after the other....

Tips for WordPress Security

WP is one of the common installation today and probably one of the most hacked ones as well. I am...

Web Site Infection

Web Site Infections is hurting many domains on the net. The infection rate is high in WP, Joomla...