12-27-2004

Password recommendations

I would advise the reader of this document to take care in the selection of passwords to use on your computer, and on the Internet. Many times the only defence between you and people that want to take advantage of you and your resoruces is your password.

1. Length: The longer a password is, the more secure it is. A suggested minimum is 6 characters, with at least 8 being preferred.

2. Character selection: At the bare minimum, your password should incorporate both alpha characters (A-Z, a-z) and numeric characters (0-9). It is also desirable to include punctuation.

3. The password should not include a normal word. You can substitute numbers like 0(zero) for O(capitol "o"), and 1(one) for lower case "l".***

4. It may be helpful to use a form of sentence to make your password easier to remeber, such as "1forU2.", which is read as "One for you two."

5. It is NOT advisable to use one password for all situations, as once that one password is breached, your entire identiy is at risk.

6. It is advisable to change your password from time to time, as the longer you use a given password, the higher the chances are that someone will acquire it.

7. Do not use any data in your password that is public knowlege, or easily determined. Such as: your birthdate, your childrens birthdate, your spouces birthdate, social security numbers, telephone numbers, address, etc...

8. When entering your password, be aware of your surroundings. One common method of obtaining your password is called "shoulder surfing". "Shoulder surfing" is when the party interested in obtaining your password looks over your shoulder when you are typing in your password.

9. NEVER put your password('s) on a note taped to your monitor.

10. Make shure you follow appropriate PC maintainence proceedures as they pertain to anti-virus, malware, and anti-adware applications. One form of malware is a program known as a key logger. The key logger captures your keystrokes and reports them via the internet to the party that provided the malware. Obiously, this can be used to collect not only passwords, but also credit card, on-line banking, and other account information.

*** The rational behind this is that there are 52 alpha characters, 10 numeric characters, and up 128 punctuation/symbol characters. The time it takes to crack a password is directly related to the number of possible characters in each position of the password. As length and complexity increase, so does security.


Back