1 / 18

Strong Passwords

Strong Passwords. How to make your passwords work for you…. Linda A. LeBlanc IT Security Support IS&T. Once upon a time…. DO! Pick a password you can remember! Make it REALLY hard to guess. Use upper and lower characters. DON’T! Write your password down ANYWHERE!

danika
Télécharger la présentation

Strong Passwords

An Image/Link below is provided (as is) to download presentation Download Policy: Content on the Website is provided to you AS IS for your information and personal use and may not be sold / licensed / shared on other websites without getting consent from its author. Content is provided to you AS IS for your information and personal use only. Download presentation by click this link. While downloading, if for some reason you are not able to download a presentation, the publisher may have deleted the file from their server. During download, if you can't get a presentation, the file might be deleted by the publisher.

E N D

Presentation Transcript


  1. Strong Passwords How to make your passwords work for you…. Linda A. LeBlanc IT Security Support IS&T

  2. Once upon a time….

  3. DO! Pick a password you can remember! Make it REALLY hard to guess. Use upper and lower characters DON’T! Write your password down ANYWHERE! Make them similar to each other. Use klingon or Elvish (Elven?) The (old) Do’s & Don’ts of Passwords

  4. Let’s be realistic… • How many passwords do you have? • Don’t forget your ATM, Insurance Phone Tree, your Bank Account Test question… • How are we supposed to remember them ALL???

  5. We know you write them down….somewhere. • Underneath your keyboard? • In your top desk drawer? • On your monitor?(Please say it’s on the back at least!) • The little notebook marked PASSWORDS? • The sheet of paper folded and sticking out of the dictionary above your head?

  6. The Dilemma: • I’m supposed to remember but it’s not supposed to be a word in any language & it’s supposed to be hard to guess. • If I forget it, there’s no way to recover it because I can’t write it down. • My dog’s (cat’s)name isn’t a word, and has upper and lower case characters.

  7. New, more realistic rules… • Use letters, numbers, special characters (upper and lower case). • If you must write them down, separate the password from the account name, and keep them somewhere secure. • Similarity and composition are not the same. (brainiac23 & brainiac12 are similar; fre:sZib61 and glii:tZul72 are composed in the same way)

  8. Risk Assessment & Reality You have to decide for yourself what level of risk you are willing to assume when choosing how to secure your passwords.

  9. We’re always scheming… Develop password generation methods that work for you, and are easy to replicate. Number/letter substitutions, nonsense sounds Passphrases and acronyms Group by account type. (what’s good for mail, might not be sufficient for the IRA)

  10. Exhibit A: My Father

  11. One Password, Many Places… Insecure accounts sharing a password with sensitive data accounts. One FIVE letter word.

  12. A new method… • The Book of Psalms • Chapter and Verse • Preserve Case, Punctuation • Annotate account w/matching chapter verse pair.

  13. Exhibit B: My Bohemian Sister

  14. w0rDz not words! • Use nonsense sounds that are pronounceable. • Build a word with all the requirements • Substitute a number for a vowel • Use the number combination for the vowels to identify the password.

  15. More Ideas: • Your favorite formulas? • Chemical compounds? (EtOH is a little too simple) • What else?

  16. Last Writes… • Establish a password generation method for yourself. • Find a place to keep your passwords and keep them secure. • Never reuse passwords EVER. Build a fresh one.

  17. T he End (of passwords as we know them?)

  18. More information and handouts are available from ITSS Email: leblancl@mit.edu

More Related