{"id":403,"date":"2017-05-09T15:00:52","date_gmt":"2017-05-09T15:00:52","guid":{"rendered":"https:\/\/eset-blog.aist.fun\/a-short-history-of-the-computer-password\/"},"modified":"2019-05-29T12:00:28","modified_gmt":"2019-05-29T12:00:28","slug":"a-short-history-of-the-computer-password","status":"publish","type":"post","link":"https:\/\/blog.eset.ee\/et\/en\/2017\/05\/09\/a-short-history-of-the-computer-password\/","title":{"rendered":"A short history of the computer password"},"content":{"rendered":"<p class=\"wls-paragraph\">The password is nothing new. In fact, it has been around for centuries. Way before Hotmail, Skype and Netflix were prompting you to create a secure code with a funky username, the Romans reportedly used passwords as a way to convey important military messages between troops.<\/p>\n<p class=\"wls-paragraph\">Essentially, it was a simple way to protect information. Fast forward a few thousand years and enter Fernando Corbat\u00f3.<\/p>\n<p class=\"wls-paragraph\">Widely regarded as the godfather of the modern computer password, he introduced the idea to computer science while working at the Massachusetts Institute of Technology (MIT) in 1960.<\/p>\n<p class=\"wls-paragraph\">The university had developed a huge Compatible Time-Sharing System (CTSS) that all researchers had access to. However, they shared a common mainframe as well as a single disk file.<\/p>\n<p class=\"wls-paragraph\">To help keep individual files private, the concept of a password was developed so that users could only access their own specific files for their allotted four hours a week \u2013 hey, computer time was limited back in the 60s.<\/p>\n<p class=\"wls-paragraph\">Although the password was less than perfect, something <a href=\"https:\/\/www.wired.com\/2012\/01\/computer-password\/\" target=\"_blank\" rel=\"noopener noreferrer\">Corbat\u00f3 is the first to admit<\/a>, it went on to become the go-to method for computer security, both in the personal and corporate spheres, due to its simplicity (although this would later be seen as one of its faults).<\/p>\n<h2><strong>Hashing, salt and cryptology<\/strong><\/h2>\n<p class=\"wls-paragraph\">In those early days of computing, the use of passwords in this sense was fairly limited, mainly to guys like Corbat\u00f3&nbsp;and his team who were among the first to really explore the power of computers.<\/p>\n<p class=\"wls-paragraph\">However, as the world wide web exploded in the 90s, more and more people began using the internet on a regular basis, creating reams of sensitive data and information in the process.<\/p>\n<p class=\"wls-paragraph\">But even before the web went into overdrive, early computer scientists were working on a way to make passwords more secure. And, to do that, computer science took a leaf from cryptology.<\/p>\n<p class=\"wls-paragraph\">Working for Bell Labs in the 70s, cryptographer Robert Morris devised \u201chashing\u201d; the process by which a string of characters is transformed into a numerical code that represents the original phrase.<\/p>\n<p class=\"wls-paragraph\">Hashing was adopted in early unix-like operating systems, which are widely used today across the world in mobile devices and workstations. Apple\u2019s macOS, for example, uses unix, while the PlayStation 4 uses Orbis OS, a unix-like operating system.<\/p>\n<p class=\"wls-paragraph\">Adding yet another level of security, modern password databases can also employ \u201csalting\u201d to further encrypt a password whereby random data&nbsp;is inserted before the password, and then the resulting string is hashed.<\/p>\n<p class=\"wls-paragraph\">This, however, doesn\u2019t stop a simple password from being guessed: the main aim is to stop a leaked password or multiple passwords (for example, in the event a database has been breached) from being cracked and used.<\/p>\n<p class=\"wls-paragraph\">But back when Corbat\u00f3 devised the password, security wasn\u2019t such a huge issue: hacking, as we understand it today, didn\u2019t really appear until the 80s.<\/p>\n<p class=\"wls-paragraph\">Now, it\u2019s a different story: almost everything is online.<\/p>\n<p class=\"wls-paragraph\">From banking and shopping, to TV and music, we keep our data safe with a string of digits and letters. But how safe is it? Even huge companies <a href=\"https:\/\/www.welivesecurity.com\/2014\/05\/22\/ebay-breach-news-posted-data-dump-valid-password-reset-issues\/\" target=\"_blank\" rel=\"noopener noreferrer\">eBay<\/a> and <a href=\"https:\/\/www.welivesecurity.com\/2016\/05\/20\/millions-people-compromised-2012-linkedin-data-breach\/\" target=\"_blank\" rel=\"noopener noreferrer\">LinkedIn<\/a> have been attacked in recent years, compromising the passwords of their users.<\/p>\n<h2><strong>The pros and cons of the password<\/strong><\/h2>\n<p class=\"wls-paragraph\">There are a couple of seemingly intrinsic problems with passwords. One, it seems to be that short ones are easy to remember but easier to guess. Two, longer ones are harder to crack but harder to remember.<\/p>\n<p class=\"wls-paragraph\">Keeping so many different passwords can be difficult too. Just think about how many online accounts the average person has: online banking, personal email, iTunes, Skype, Amazon \u2026 the list goes on and on.<\/p>\n<p class=\"wls-paragraph\">This has led many people to just use one or two passwords across the board. This, of course, poses a major problem: if attackers work it out, they then have access to everything.<\/p>\n<p class=\"wls-paragraph\">Another issue is the choice of the password itself. Shockingly, <a href=\"https:\/\/www.welivesecurity.com\/2016\/01\/20\/weak-passwords-continue-pose-huge-security-threat\/\" target=\"_blank\" rel=\"noopener noreferrer\">SplashData found<\/a> that a great many people still used \u201cpassword\u201d or \u201c123456\u201d as the key to their sensitive data \u2013 it\u2019s not going to take a cybercriminal much effort or time to crack that code now, is it?<\/p>\n<h2><strong>The password is dead \u2026 long live the password<\/strong><\/h2>\n<p class=\"wls-paragraph\">Passwords do, of course, provide a level of security, and despite the likes of Bill Gates saying <a href=\"https:\/\/www.cnet.com\/uk\/news\/gates-predicts-death-of-the-password\/\" target=\"_blank\" rel=\"noopener noreferrer\">it was dead way back in 2004<\/a>, most companies with online portals still use them.<\/p>\n<p class=\"wls-paragraph\">So how can you make your passwords more secure? Well, there are a few options.<\/p>\n<p class=\"wls-paragraph\">The people behind <a href=\"https:\/\/passwordday.org\/\" target=\"_blank\" rel=\"noopener noreferrer\">World Password Day<\/a>, an initiative focused on improving password strength, suggest that each account should have its own unique password to avoid this very issue.<\/p>\n<p class=\"wls-paragraph\">Creating strong passwords in the first place is also crucial. Codes that combine words and numbers, avoid obvious personal information and that are eight or more letters in length generally work best.<\/p>\n<p class=\"wls-paragraph\">Users can also adopt a \u201cpasscode\u201d strategy for increased security or adopt <a href=\"https:\/\/www.welivesecurity.com\/tag\/two-factor-authentication\/\" target=\"_blank\" rel=\"noopener noreferrer\">two-factor authentication<\/a>, where a password is only one step in gaining access to sensitive data.<\/p>\n<p class=\"wls-paragraph\">Further, moving beyond passwords is recommended \u2013 passphrases, for example, <a href=\"https:\/\/www.welivesecurity.com\/2016\/05\/05\/forget-about-passwords-you-need-a-passphrase\/\" target=\"_blank\" rel=\"noopener noreferrer\">offer users better security<\/a> courtesy of longer and complex sentences, while still being easy to remember.<\/p>\n<p><strong><span class=\"block_quote_right\">\u201cThe three golden rules to ensure computer security are: do not own a computer; do not power it on, and do not use it.\u201d<\/span><\/strong><\/p>\n<p class=\"wls-paragraph\">If all this password malarkey seems a bit much, you could take a leaf from the late cryptographer Robert Morris (father of Robert Morris Jr, <a href=\"https:\/\/www.welivesecurity.com\/2016\/11\/02\/flashback-tuesday-morris-worm\/\" target=\"_blank\" rel=\"noopener noreferrer\">author of the Morris Worm<\/a>). Besides his contributions to password hashing the above tips, he had a slightly more unusual suggestion for computer security:<\/p>\n<p class=\"wls-paragraph\">\u201cThe three golden rules to ensure computer security are: do not own a computer; do not power it on, and do not use it.\u201d<\/p>\n<p class=\"wls-paragraph\">A little too extreme perhaps \u2026<\/p>\n<p class=\"wls-paragraph\">&nbsp;Source: <a id=\"community-tab\" class=\"publisher-nav-color\" href=\"https:\/\/www.welivesecurity.com\/2017\/05\/04\/short-history-computer-password\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-action=\"community-sidebar\" data-forum=\"welivesecurity\"><span class=\"community-name\"><strong>WeLiveSecurity<\/strong><\/span><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The password is nothing new. In fact, it has been around for centuries. Way before Hotmail, Skype and Netflix were prompting you to create a secure code with a funky username, the Romans reportedly used passwords as a way to convey important military messages between troops. Essentially, it was a simple way to protect information. [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":1808,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[2880],"tags":[],"class_list":["post-403","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-digital-security"],"acf":[],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/403","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/comments?post=403"}],"version-history":[{"count":0,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/403\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/media\/1808"}],"wp:attachment":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/media?parent=403"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/categories?post=403"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/tags?post=403"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}