{"id":456,"date":"2019-01-10T14:12:58","date_gmt":"2019-01-10T14:12:58","guid":{"rendered":"https:\/\/eset-blog.aist.fun\/new-years-resolutions-get-your-passwords-shipshape\/"},"modified":"2019-05-29T11:35:33","modified_gmt":"2019-05-29T11:35:33","slug":"new-years-resolutions-get-your-passwords-shipshape","status":"publish","type":"post","link":"https:\/\/blog.eset.ee\/et\/en\/2019\/01\/10\/new-years-resolutions-get-your-passwords-shipshape\/","title":{"rendered":"New Year\u2019s resolutions: Get your passwords shipshape"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">In case there are some blank entries in your laundry list of New Year\u2019s resolutions, we have a few tips for a bit of cybersecurity \u2018soul searching\u2019. Here\u2019s the first batch, looking at how you can fix your good ol\u2019 passwords.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Many of us entered 2019 with a boatload of New Year\u2019s resolutions. Doing more exercise, fixing unhealthy eating habits and saving more money are all highly respectable goals in their own right, but could it be that they don\u2019t go far enough in an era with countless apps and sites that scream for letting them help you reach your personal goals, which apparently also implies \u2013 you guessed it \u2013 reach your New Year\u2019s resolutions?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Now, you may want to add a&nbsp;few more weighty and yet fairly effortless habits on top of those well-worn choices. Here are a&nbsp;handful of tips for \u2018exercises\u2019 that will do good for your cyber-fitness.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>I won\u2019t pass up on stubborn passwords<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Passwords have a bad rap, and deservedly so: they suffer from weaknesses, both in terms of security and convenience, that make them a less-than-ideal&nbsp;<a href=\"https:\/\/www.welivesecurity.com\/2016\/05\/03\/authentication-101\/\">method of authentication<\/a>. However, much of what the Internet offers is dependent on your signing up for this or that online service, and the available form of authentication almost universally happens to be the username\/password combination.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As the keys that open online accounts (not to speak of many devices), passwords are often rightly thought of as the first \u2013 alas, often the only \u2013 line of defense that protects your virtual and real assets from intruders. However, passwords don\u2019t offer much in the way of protection unless, in the first place, they\u2019re strong and unique to each device and account.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But what constitutes a strong password? A pass<em>phrase<\/em>! Done right, typical passphrases are generally both more secure and more user-friendly than typical passwords. The longer the passphrase and the more words it packs the better, with seven words providing for a solid start. With each extra character (not to mention words), the number of possible combinations rises exponentially, which makes simple brute-force password-cracking attacks far less likely to succeed, if not well-nigh impossible (assuming, of course, that the service in question does not impose limitations on password input length \u2013 something that is, sadly, still far too common).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>I\u2019ll have no sympathy for the passphrase-cracker<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image\"><a  href=\"https:\/\/www.welivesecurity.com\/wp-content\/uploads\/2019\/01\/shut-2644555_1920-e1546937436964.jpg\" data-rel=\"lightbox-gallery-0\" data-rl_title=\"\" data-rl_caption=\"\" data-magnific_type=\"gallery\" title=\"\"><img decoding=\"async\" src=\"https:\/\/www.welivesecurity.com\/wp-content\/uploads\/2019\/01\/shut-2644555_1920-1024x552.jpg\" alt=\"shut\" class=\"wp-image-120794\"\/><\/a><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Another caveat is that it\u2019s better to refrain from phrases that have made it into the everyday lexicon. Entire books, famous quotes, or lyrics \u2013 sing, \u2018<a href=\"https:\/\/youtu.be\/ZRXGsPBUV5g?t=103\">Pleased to meet you, hope you guess my name\u2019<\/a>&nbsp;as a bit of an extreme example that is not to be taken literally \u2013 already tend to be part of the fodder of password-cracking tools. The individual words should be in random order and, ideally, sprinkled with special characters and character substitution, all the while retaining a hidden meaning and memorability to its creator. For practical guidance about creating your passphrases, you may want to refer to this&nbsp;<a href=\"https:\/\/youtu.be\/q5DYkzOrz_I\">short video tutorial<\/a>&nbsp;or to&nbsp;<a href=\"https:\/\/www.welivesecurity.com\/2016\/05\/05\/forget-about-passwords-you-need-a-passphrase\/\">this article<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Then, of course, there is the need for each passphrase to be distinct for each account, so that a leak of one of your passphrases doesn\u2019t reverberate through your other and possibly more valuable accounts. Alas, the dangerous practice of&nbsp;<a href=\"https:\/\/www.welivesecurity.com\/2018\/05\/03\/recycling-reuse-password\/\">password recycling<\/a>&nbsp;is ubiquitous, and attackers can exploit it hands-down with an automated technique known as \u2018<a href=\"https:\/\/www.welivesecurity.com\/2018\/02\/26\/login-attempts-attackers-invade-accounts\/\">credential stuffing<\/a>\u2019.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It\u2019s quite likely that you use too many online accounts to remember a distinct passphrase for each of them. In which case, it\u2019s worth considering a reputable password vault\/manager that encrypts your password storage and takes away much of the pain that password management involves. Of course, such a tool can also generate randomized and complex passwords and passphrases for you.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">While then you should need to remember only one master password that, ultimately, opens all your online accounts, the pressure will be on the sturdiness and uniqueness of this one key to your digital kingdom \u2013 so it\u2019s back to the suggestions above.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>I won\u2019t skip the second step<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Another trouble with passwords\/passphrases may arise when they are not only the first, but actually the&nbsp;<em>only<\/em>&nbsp;line of defense for your account security. When that barrier crumbles \u2013 commonly through a phishing attack or by attackers somehow working out your login details \u2013 an extra authentication factor that does not rely on \u2018something you know\u2019 may very well foil your adversaries.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.welivesecurity.com\/2014\/02\/11\/two-factor-authentication-what-is-it-and-why-do-i-need-it\/\">Two-factor authentication<\/a>&nbsp;(2FA), or multi-factor authentication (MFA), is an excellent way of boosting the security of your accounts, especially when coupled with hardware keys or dedicated apps, and less so with&nbsp;<a href=\"https:\/\/www.welivesecurity.com\/2016\/08\/09\/nist-time-move-sms-2fa\/\">SMS-borne 2FA<\/a>. &nbsp;Although many online services provide 2FA options, few require its use. However, the adoption of 2FA has been on the rise and it\u2019s never been easier to jump on the practice. Regardless if its implementation, signing up for 2FA&nbsp;<a href=\"https:\/\/twofactorauth.org\/\">wherever you can<\/a>&nbsp;is well worth the little extra effort, as it can help in various scenarios, including when you never fell prey to a cyberattack compromising any of your passwords.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In fact, it\u2019s quite probable that some of your authentication details will be, or have already been, stolen and posted online or made available for sale on underground marketplaces. The source of these password leaks include the many security breaches that have blighted online services, retailers,&nbsp;<a href=\"https:\/\/www.welivesecurity.com\/2018\/11\/30\/marriott-starwood-data-breach-response\/\">hotel chains<\/a>&nbsp;and the like. Additionally, the targeted entity may have protected the users\u2019 passwords with weak hashing and salting functions, or even stored the passwords in plain text. Worse still, the service provider, let alone you, may not know until quite a while later that hackers pilfered the often poorly secured data, or purchased them on the dark web, so you had no shot at taking any ad-hoc defensive measures. Again, this is also where that extra authentication factor will usually thwart any account-takeover attempts.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In fact, go ahead and see for yourself on&nbsp;<a href=\"https:\/\/haveibeenpwned.com\/\">Have I Been Pwned?<\/a>&nbsp;whether any of your online accounts may have been part of a known breach. Aside from the almost 5.7 billion compromised accounts that the site indexes, it also has a cache of more than half a billion publicly&nbsp;<a href=\"https:\/\/haveibeenpwned.com\/Passwords\">leaked or stolen passwords<\/a>&nbsp;in clear text that have been revealed in past breaches, so you can check yours against the database, too.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>I\u2019ll use fewer passwords<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image\"><a  href=\"https:\/\/www.welivesecurity.com\/wp-content\/uploads\/2014\/01\/passwordsecurity2000-e1546937661639.jpg\" data-rel=\"lightbox-gallery-0\" data-rl_title=\"\" data-rl_caption=\"\" data-magnific_type=\"gallery\" title=\"\"><img decoding=\"async\" src=\"https:\/\/www.welivesecurity.com\/wp-content\/uploads\/2014\/01\/passwordsecurity2000-1024x795.jpg\" alt=\"Password (Rex)\" class=\"wp-image-28688\"\/><\/a><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Surely a mistake, right? Well, it may sound counterintuitive, but fixing your passwords may also imply needing fewer of them in the first place. More precisely, it means cutting ties with the services you no longer use, so that you needn\u2019t \u2018look after\u2019 your accounts with them. We all have set up accounts that we no longer use. Indeed, we may have racked up quite a few of them over the years, including some we barely remember. However, the adage \u2018the internet never forgets\u2019 fits here too, and forgetting is something you shouldn\u2019t do, either.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The trouble with unused accounts is that each of them \u2013 even if only a vestige of your much younger self \u2013 is a potential source of danger. The service may suffer a breach exposing your password or may be sold to new owners whose intentions might not exactly be honest. Or, if miscreants take over your account, they might be able to use it to break into one of your highly valued accounts, be it by gathering private information about you, or through your failing to use a unique password for each account. Or they can just as well use it to spew out spam.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But what doesn\u2019t exist can\u2019t be taken over, can it? Feel no remorse: just dispatch those accounts to a better place and never look back. There are even services that promise to scale back your online footprint in bulk; that is, without you having to recall or comb through and then manually shut down each inactive account. Using a service just to help kill online accounts may not be for everybody, however, as essentially you need to take the developers of such tools at their word.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">While you\u2019re cutting the clutter, consider severing ties also with third-party apps and services that are associated with your accounts on social and other major sites, especially the apps that you no longer use. These apps, too, can be misused as other entry points for illicit data collection or even worse. To pull the plug on their access to your account and data, navigate to the privacy and\/or security settings of your online service(s) of choice; from there, it usually takes only a click or two.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Next up<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Staying safe online isn\u2019t going to become any easier this year, and we\u2019ll be back in a few days with more tips for beefing up your personal security. Next time, we\u2019ll focus mainly on a couple of easy ways to boost the security of your wireless network.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Source: <a href=\"https:\/\/www.welivesecurity.com\/2019\/01\/08\/new-years-resolutions-passwords-shipshape\/\">Welivesecurity<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In case there are some blank entries in your laundry list of New Year\u2019s resolutions, we have a few tips for a bit of cybersecurity \u2018soul searching\u2019. Here\u2019s the first batch, looking at how you can fix your good ol\u2019 passwords. Many of us entered 2019 with a boatload of New Year\u2019s resolutions. Doing more [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":1862,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[2880],"tags":[],"class_list":["post-456","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-digital-security"],"acf":[],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/456","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/comments?post=456"}],"version-history":[{"count":0,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/456\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/media\/1862"}],"wp:attachment":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/media?parent=456"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/categories?post=456"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/tags?post=456"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}