My Pages

Friday, October 1, 2010

Rules for Strong Passwords

I hate having to make a complex password I can't remember. So here's a little information on what it takes to hack an eBay password and how you can create highly un-hackable password you can remember.

Rule #1 - Create a password longer than 4 characters
The more characters in a password, the harder it is to crack. You probably knew this already, but did you know that a password of 4 characters or less can be hacked instantly using any number of commercial programs?


Rule #2 - Use upper and lower case letters in your password plus digits
Lowercase letters are the easiest to break. Adding upper case letters increases the level of difficulty, but is still not the best solution. Adding a digit is also a good idea. See Rule #3 below.


Rule #3 - Incorporate the full set of ASCII characters in your password
What's an ASCII character? Anything on your keyboard is an ASCII character, but the characters above the numbers (!,@,#,$,%,^,&,*,(,)) are particularly useful in creating a powerful password. Here's an example. If my password is "ebay" a password-breaking program would crack this instantly. If my password is "ebay3" it would take 2 minutes to get into my account. If I added an uppercase letter and made my password "eBay3" it would now take 12 minutes to gain access. But if I added an ASCII character, "eBy!3" it will now take 4 hours to get into my account.


Rule #4 - Choose an uncommon or non-existent word
Common English words are subject to Dictionary attacks. This is where a password cracking program runs through every word in the dictionary to find your password. Even if you put two common words together to create one that is not an actual word, for example "sidebook," a dictionary attack can still find it.


Now, here's a simple way to create a secure password you can remember that complies with all the rules above. Think of a sentence that describes something you can remember. For example, "I live at 45 Maple Street in Ohio" or "My 3rd grade teacher was Mrs. Smith at Franklin. Then, create your password by taking the first letter or number from each word in the sentence. So, our first example would become "Il@45MSiO" and the second would be M3gtwMS@F.

Want to know how long it would take a program to crack those passwords? 44,530 years. Yes, it would take a program that long. If you remove the @ sign and replace it with the letter "a" it drops to 178 years, but still a very powerful password.

Now, make a resolution to keep your eBay account secure and change that flimsy password to something powerful!

No comments:

Post a Comment