{"id":34334,"date":"2019-02-04T12:58:47","date_gmt":"2019-02-04T04:58:47","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=34334"},"modified":"2019-02-04T13:00:05","modified_gmt":"2019-02-04T05:00:05","slug":"memorable-passwords-stronger-than-constant-change-say-kaspersky-lab-researchers","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2019\/02\/04\/memorable-passwords-stronger-than-constant-change-say-kaspersky-lab-researchers\/","title":{"rendered":"Memorable passwords stronger than constant change, say Kaspersky Lab researchers"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>To mark Change Your Password Day, 2019, Kaspersky Lab\u2019s security researchers are advising users that unique, memorable passwords are stronger and more effective than regularly changing account passwords when it comes to keeping data secure online. The researchers have shared some easy steps that people can follow to create their own series of unique passwords. They also recommend installing a password management tool that does the hard work of remembering passwords for you.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Passwords are an established method of authentication for online accounts, but creating passwords that are both secure and memorable is not always easy, and is becoming harder as people have more online accounts. If you create simple passwords that you are unlikely to forget, the risk of an attacker cracking it are higher.&nbsp; However, if you create a more complex password, you are more likely to forget it, so the chances are high that you will stick to just one or two and reuse them for multiple websites.<br><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Kaspersky Lab researchers estimate that the greatest vulnerability of passwords is their re-use. As the recent<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.troyhunt.com\/the-773-million-record-collection-1-data-reach\/\"> release<\/a> of more than 700 million email addresses and millions of unencrypted passwords showed, data from different breaches can easily be combined and used in \u2018credential stuffing\u2019 attacks, where hackers use victims\u2019 email\/password combinations to break into their other accounts that have the same password.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This risk is not reduced by changing passwords, but by making them strong. Further, this strength should be built not on complexity but on uniqueness.<br><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cThere is a lot of confusion about what a strong password actually means. Many websites now demand complex passwords comprising at least eight or more upper and lower case letters, numbers and special characters. This is what many users have come to equate with a \u2018strong\u2019 password, and it can seem pretty daunting,\u201d\u00a0said\u00a0David Jacoby, Security Researcher in Kaspersky Lab\u2019s Global Research and Analysis Team (GReAT).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cThe good news is that strong doesn\u2019t have to mean scary! When you look at the issue from a security perspective, you can see that passwords are generally strong if they are unique to you and to one account. There are easy ways of making them unique, yet memorable, so that they cannot be used to breach other accounts, even if the details are exposed in a data breach.\u00a0 Further, there are secure password management tools available, including\u00a0<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"http:\/\/www.kaspersky.com\/password-manager\">Kaspersky Password Manager<\/a>\u00a0that make it easy to safely create and use dozens of unique passwords,\u201d added Jacoby.<br><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The following steps will help you to create unique, memorable passwords that are strong:<\/strong><br><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Step 1: Create your \u2018static string\u2019 (the part of the password that doesn\u2019t change)<br><\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>Think of a phrase, song lyrics, quotes from a movie, nursery rhyme, or similar that is memorable to you.<\/li><li>Take the first letter from the first three to five words.<\/li><li>Between every letter add a special character: @ \/ # etc.<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">From now on, you can base all of your unique passwords on this one string.<br><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Step 2: &nbsp;Add the power of association<br><\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>When you think of the online accounts you need a password for (Facebook, Twitter, eBay, dating sites, online banking, shopping, or gaming sites etc.), write down for each the first word that you associate with that site.<\/li><li>For example, if you are creating a password for Facebook, you might associate Facebook with the blue color in the logo: so, then you can simply append the word \u201cblue,\u201d maybe in all caps, at the end of your static string. <\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cFor example, if the phrase you think of is \u2018Twinkle Twinkle Little Star, How I Wonder What You Are,\u2019 and the special character that you want to use is \u2018#\u2019, then your password for Facebook would be something like:\u00a0T#T#L#S#Hblue.\u00a0 It makes no real sense when you look at it, or if someone gave it to you. But, since it\u2019s personal to you, you understand the system used to generate your passwords, and you associate the word with the site, it\u2019s easy for you to remember,\u201d\u00a0\u00a0explained by David Jacoby.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The best way to back up, remember and securely auto-fill passwords is through a password management tool, like <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"http:\/\/www.kaspersky.com\/password-manager\">Kaspersky Password Manager<\/a>.&nbsp; Kaspersky Password Manager is a secure password saver and password protection solution that allows you to create strong, unique passwords for all your online accounts, while only having to remember one master password to access them. The most secure password manager solutions, including Kaspersky Password Manager, offer robust encryption features, so there is little threat of your data being breached by a third party.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The researchers have shared some easy steps that people can follow to create their own series of unique passwords. They also recommend installing a password management tool that does the hard work of remembering passwords for you.<\/p>\n","protected":false},"author":6,"featured_media":34335,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19,26],"tags":[117,54],"class_list":["post-34334","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","category-opinions","tag-kaspersky-lab","tag-security"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/34334","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=34334"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/34334\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/34335"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=34334"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=34334"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=34334"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}