Changes for page Password Security and Hygiene
Last modified by Chase Eckert on 2026/08/19 16:32
From version 3.1
edited by Lauren Keller
on 2019/01/22 12:00
on 2019/01/22 12:00
Change comment:
There is no comment for this version
To version 22.1
edited by steve@remc1_org
on 2021/02/25 05:09
on 2021/02/25 05:09
Change comment:
There is no comment for this version
Summary
-
Page properties (2 modified, 0 added, 0 removed)
-
Objects (1 modified, 0 added, 0 removed)
Details
- Page properties
-
- Author
-
... ... @@ -1,1 +1,1 @@ 1 -XWiki. lkeller@remc1_org1 +XWiki.steve@remc1_org - Content
-
... ... @@ -1,19 +1,47 @@ 1 -=== {{idname="Passwords-Are-Complicated"/}}Passwords Are Complicated===1 +=== === 2 2 3 - The bestpasswords are easy to remember and hard to break. This is no mean feat, as the two do not normallycoexist; if a password is too difficult to remember & meaning it meets complexity requirements & it will likely wind up on a [[sticky note stuck to your monitor or in a desk drawer>>url:https://www.nngroup.com/articles/security-and-human-factors/||shape="rect"]].3 +{{toc/}} 4 4 5 -=== {{id name=" Bad-Passwords-Are-Not-Secure"/}}Bad Passwords AreNotSecure===5 +=== {{id name="Good-Passwords-Are-Hard-To-Find"/}}Good Passwords Are Hard To Find === 6 6 7 - Ifyou needproof,payavisitto[[';~~-~~-haveibeenpwned?>>url:https://haveibeenpwned.com/||shape="rect"]]andenteryouremailaddress.Oraddresses.Optionally,youcancheck whether[[yourpasswordhas beencompromised>>url:https://haveibeenpwned.com/Passwords||shape="rect"]].7 +The best passwords are easy to remember, hard to break, and changed regularly. This can be a problem; if a password is too difficult to remember – meaning it meets complexity requirements and is long enough to withstand attempts to crack it – it will likely wind up on a [[note in your desk drawer or taped to your monitor>>url:https://www.nngroup.com/articles/security-and-human-factors/||shape="rect"]]. 8 8 9 - [[Ifthatdoesn'tconcern you, it should>>url:https://arstechnica.com/information-technology/2019/01/hacked-and-dumped-online-773-million-records-with-plaintext-passwords/||shape="rect"]]. The average personhas about 25onlineaccounts and most people [[recycle their passwords>>url:https://www.google.com/search?q=how+many+people+use+the+same+password+for+multiple+accounts&rlz=1C1GCEA_enUS798US798&oq=how+many+people+use+the+same+password+for+multiple+accounts&aqs=chrome..69i57.9127j0j7&sourceid=chrome&ie=UTF-8||shape="rect"]].Ifyou are among them, a single breach couldinvalidate all thesecurity a "good" passwordwould otherwise provide. It doesn't matter how strong a password happens to be; if it appears on-line you can never use it safely.9 +=== {{id name="How-Do-I-Choose-A-Good-Password?"/}}How Do I Choose A Good Password? === 10 10 11 - ==={{id name="What-Is-A-Good-Password?"/}}What IsAGoodPassword?===11 +Arguably, the best advice comes from someone that understands how passwords are cracked; [[both are explained here>>url:https://www.schneier.com/essays/archives/2008/11/passwords_are_not_br.html||shape="rect"]]. Once you have a password, you can check how strong it is: [[this one works through your browser>>url:https://random-ize.com/how-long-to-hack-pass/||shape="rect"]] so you don't need to upload your sensitive information anywhere. If it's good, use it and remember to change it ([[it's not as bad as it sounds>>url:https://blog.lastpass.com/2018/08/often-change-password.html/||shape="rect"]]). 12 12 13 - Asmentioned above: easy torememberand hard tobreak. Here'swhy they seldomcoincide. Tocheck how good your passwordis; you can use any numberof tools. I happentolike [[thisone>>url:https://random-ize.com/how-long-to-hack-pass/||shape="rect"]].13 +=== {{id name="Compromised-Accounts-And-Passwords"/}}Compromised Accounts And Passwords === 14 14 15 - ==={{idname="Un-Complicate-Your-Passwords"/}}Un-ComplicateYourPasswords===15 +We hear about high-profile breaches; if you are affected by one of these, the parties responsible for keeping your information safe will eventually contact you and let you know what you can do about it. 16 16 17 - Ourbrainscanonlyholdsomuch.[[Inthissurvey>>url:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC3515440/||shape="rect"]],72%of the263 participantshaddifficultyrememberingtheirpasswords.Theresults,aswe alreadyknow,iswe reuseand writedownpasswords.There aretechniquesforrememberingimportant thingslikepasswords,butwhen wecan expectwe'llhaveto[[rememberevenmorepasswordsin the coming years>>url:https://techxplore.com/news/2018-12-passwords-ready.html||shape="rect"]],youmaywanttosimplifythisaspect ofyourlife.17 +But [[it has been reported>>url:https://arstechnica.com/information-technology/2019/01/hacked-and-dumped-online-773-million-records-with-plaintext-passwords/||shape="rect"]] that [[nearly a Billion compromised email accounts>>url:https://www.forbes.com/sites/kateoflahertyuk/2019/01/17/collection-1-breach-how-to-find-out-if-your-password-has-been-stolen/#28c21b512a2e||shape="rect"]] are published online. If you wonder whether yours is among them, head to [[';~~-~~-have i been pwned?>>url:https://haveibeenpwned.com/||shape="rect"]] and enter an email address. If you find yours, change your password for every account that uses that email address or password. You can also check whether [[one of your passwords has been compromised>>url:https://haveibeenpwned.com/Passwords||shape="rect"]] and sign up for notifications in the event a future breach or 'sensitive' data dump exposes your information. 18 18 19 -[[A reputable password manager>>url:https://www.google.com/search?rlz=1C1GCEA_enUS798US798&ei=-WRHXNO-C-W4jwSQioSgBw&q=reputable+password+manager&oq=reputable+pass&gs_l=psy-ab.3.0.0l3j0i22i30.45653.48290..49139...0.0..0.72.802.14......0....1..gws-wiz.......0i71j0i131j0i67j0i131i67.CLekXIwJqKw||shape="rect"]] can help. They are available for your phone as well as your computer. [[If you can create one memorable, reasonably strong password>>url:https://boingboing.net/2014/02/25/choosing-a-secure-password.html||shape="rect"]] to access all the rest of your passwords, you will never have to plaster your monitor with sticky notes for any passer-by to see. 19 +[[image:attach:check_your_accounts.jpg||height="250"]] 20 + 21 +=== {{id name="Why-It-Matters"/}}Why It Matters === 22 + 23 +The average person has about 25 online accounts and most people [[recycle their passwords>>url:https://www.google.com/search?q=how+many+people+use+the+same+password+for+multiple+accounts&rlz=1C1GCEA_enUS798US798&oq=how+many+people+use+the+same+password+for+multiple+accounts&aqs=chrome..69i57.9127j0j7&sourceid=chrome&ie=UTF-8||shape="rect"]]. If you are among them, a single breach could affect all accounts using a common email address/username or password. It doesn't matter how strong a password happens to be; if it's already online you can never use it safely. 24 + 25 +=== {{id name="What-To-Do"/}}What To Do === 26 + 27 +Our brains can only hold so much. [[In this survey>>url:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC3515440/||shape="rect"]], 72% of the 263 participants had difficulty remembering their passwords. The result, as we already know, is we reuse and write down passwords. There are techniques for remembering passwords, but we can [[expect to need even more passwords>>url:https://techxplore.com/news/2018-12-passwords-ready.html||shape="rect"]] in the coming years. 28 + 29 +REMC1 is always looking at security; you've probably heard us mention 2-factor authentication and password managers. Reputable password managers are available for your phone as well as your computer. If you already use [[LastPass>>url:http://lastpass.com||shape="rect"]] – which we recommended – they offer [[a way to verify password strength>>url:https://support.logmeininc.com/lastpass/help/use-the-security-challenge-lp030011||shape="rect"]] and see if your data has been compromised. 30 + 31 +[[image:attach:password_managers.jpg||height="250"]] 32 + 33 +\\ 34 + 35 +=== {{id name="2-Step-Verification-(2-factor-or-multi-factor-authentication)"/}}2-Step Verification (2 factor or multi-factor authentication) === 36 + 37 +This feature provides an additional layer of security in case your password is compromised. REMC1 highly recommends that staff, especially administrative and administrative assistant staff, utilize this feature for their Google Account. Learn more about this at the [[Google Account Help Section on Setting up 2-Step Verification>>url:https://support.google.com/accounts/answer/185839?hl=en&ref_topic=7189195||shape="rect"]], our [[wiki page>>url:https://confluence.remc1.net/display/PS/Configuring+2-step%282-factor%29+authentication+for+Google||shape="rect"]], or viewing our [[video tutorial>>url:https://mistreamnet.eduvision.tv/Share.aspx?q=CT1wecDsedCLqkXQGflKaw%253d%253d||shape="rect"]]. 38 + 39 +=== {{id name="Questions?"/}}Questions? === 40 + 41 +REMC1 is always looking at security and you've probably heard us mention 2-factor authentication and password managers. 42 + 43 +REMC staff is happy to answer any questions you have on potential spoofing, viruses, malware, and security. 44 + 45 +\\ 46 + 47 +\\
- Confluence.Code.ConfluencePageClass[0]
-
- id
-
... ... @@ -1,1 +1,1 @@ 1 -1718 16001 +17189545