Any good password tips? Here are mine.

299°
Helpful
Neonman
  • Length is more important than complexity . This does not mean complexity is not important, just that length is more important. Shoot for length first, then complexity.
  • Avoid common substitutions, as they are baked into password cracking rule-sets. Common substitutions include: a = @, i = !, s = $, etc. Same with adding a 1 to the end of your password and capitalizing the first character. These are common patterns, and are well-known to crackers.
  • Instead of thinking "password" think "passphrase". A single dictionary word is extremely bad. Four to five random dictionary words, perhaps separated by spaces or special characters, is robust. The benefit of a passphrase is that it is easier for you to generate entropy while still remembering your key. Generating entropy through randomized characters is hard, and results in a hard to remember password, meaning you will likely end up with less entropy.
  • Avoid "password walking". This is using a password with adjacent keyboard characters (e.g. "qwerty", "1q2w3e4r", "1qaz2wsx", etc.)
  • Avoid any password present on a password blacklist. Ideally, this should be a baked-in process.
  • You should be using a different password for every website. At the very least, your e-mail password should be extremely strong and unique. If someone gets into your e-mail, they can simply reset every other password connected to that e-mail, regardless of how strong they are. Password re-use attacks are common. I cannot overstate the importance of this one tip.
  • SMS-based two-factor authentication (2FA) is better than nothing, but sim-swapping has made it inferior to other forms of 2FA and MFA. 
  • I, and my colleagues, and many others strongly recommend a (non-browser-based, audited) password manager. There still seems to be debate about password managers. I will only comment that most security professionals and government agencies encourage the use of them. They are not a panacea. Use them in combination with other positive security habits, like frequent backups and 2FA/MFA.


Expiring In 13 days
Top Comments
Deal Cadet Deal Cadet
Link Copied

Most basic yet under utilised password tip: Use an Open-source password manager.
24 Comments  |  
17 Dimers
  • Sort By
Deal Cadet Deal Cadet
Link Copied

Most basic yet under utilised password tip: Use an Open-source password manager.
Deal Cadet Deal Cadet
Link Copied
MKV29 wrote:

Most basic yet under utilised password tip: Use an Open-source password manager.

Bitwarden is my go-to password manager. I use it literally everywhere and I don't need to remember anything except the master password.

Glitterati Glitterati
Link Copied

Dashlane is My Choice 💝

Hunk Hunk
Link Copied
MKV29 wrote:

Most basic yet under utilised password tip: Use an Open-source password manager.

Use your memory 😊

Deal Cadet Deal Cadet
Link Copied
Expand
bikidas2060 wrote:

Use your memory 😊

haha
only works upto some extent
I use random generate passwords having various chars >15 len 
Diff pass for diff accounts - can't remember more than 5
Deal Cadet Deal Cadet
Link Copied
Expand
bikidas2060 wrote:

Use your memory 😊

Yes, I mean how hard can it really be to remember 100s of unique passwords/passphrases and usernames.
Hunk Hunk
Link Copied
Expand
Neo53 wrote:
haha
only works upto some extent
I use random generate passwords having various chars >15 len 
Diff pass for diff accounts - can't remember more than 5

I remember all the passwords for 30+ accounts. 👻

Hunk Hunk
Link Copied
Expand
MKV29 wrote:

Yes, I mean how hard can it really be to remember 100s of unique passwords/passphrases and usernames.

It's frustrating 

Deal Newbie Deal Newbie
Link Copied

Rule 1 - Keep the need for critical passwords to 1 a4 paper length

Rule 2 - Write them down on an a4 paper with an ink which will not get erased due to passage of time

Rule 3 - Keep updating that a4 paper

Rule 4 - Do not forget rules 1 to 3

Deal Cadet Deal Cadet
Link Copied
Expand
bikidas2060 wrote:

Use your memory 😊

Of the the banks which i used asks me to reset password for every 2 months and i cannot use last 6 passwords and no password sholud be half from previous passwords.. resetting password everytime is painfull.. buggers even asks to reset profile password. you cannot reset any one
Analyst Analyst
Link Copied

Apni wali bandi ka naam @123

I use it for demat to netbanking  ....

Change password along with subject in every 6 months 

Helpful Helpful
Link Copied
maruti234 wrote:

Rule 1 - Keep the need for critical passwords to 1 a4 paper length

Rule 2 - Write them down on an a4 paper with an ink which will not get erased due to passage of time

Rule 3 - Keep updating that a4 paper

Rule 4 - Do not forget rules 1 to 3

A4 paper length enough hoga ya chart le lu?
Deal Cadet Deal Cadet
Link Copied
Expand
akki.akki wrote:
khud ko bhi to yaad rehna chahiye na
Open source and credible Password manager will do that
I only remember few passwords which are most important (main gmail, pass manager, etc)
Analyst Analyst
Link Copied
garamjalebi wrote:
Apni wali bandi ka naam
Change password along with subject in every 6 months

😮

replyuser
Click here to reply
Reply