Techsplained: How to Create a Secure Password

If you enjoyed this video we have many more on our YouTube Channel to help you improve your tech knowledge, give you advice and even โ€œHow Toโ€ videos.

Power up your passwords to keep your business data safe. 

In this Techsplained video, AJ explains how to power up your password security game to keep your business data safe.  

If youโ€™re like me then youโ€ฏprobablyโ€ฏhave quite a few different online accounts for different stores, services, social media and more. Many of these include hack-worthy information like your date of birth or social security data, or even bank and credit card details, soโ€ฏitโ€™s important that youโ€ฏkeep these accounts secure.

However, at the point at which weโ€™re creating our passwords, our mind is often more on getting the account set up quickly than ensuring weโ€™re creating a secure password. Thatโ€™s where the problems start, and thatโ€™s why in this Techsplained weโ€™re talking about password security.

So you should be asking yourself; โ€œAre my passwords secure?โ€, โ€œAre they complex enough?โ€, โ€œAm I using some of the weakest passwords?โ€ & โ€œHow can I tell if my passwords are known to hackers?โ€ฏโ€.

Thankfully, those questions arenโ€™t as difficult to answer as it may seem. So, letโ€™s have a look at this in more detail and give you some password security tips.

What are some of the least secure passwords?

Believe it or not there are many,โ€ฏ manyโ€ฏpeople who use such simple and unsecure passwords that you donโ€™t need an AI-powered supercomputer to guess them.  

Even today, some of the most popular passwords include: 

  • Password (or Pa55word)โ€ฏ 
  • Wordpassโ€ฏ(or Wordpa55)โ€ฏ 
  • Password1 (or Password12345)โ€ฏ 
  • Quertyโ€ฏ(orโ€ฏqwertyuiop, orโ€ฏytrewq)โ€ฏ 

Or any variation of these with concurrent or repeating numbers.โ€ฏ 

And these are just a fewโ€ฏof the most common,โ€ฏleast secure passwords.โ€ฏ 

NordPass, creators of the Nordpass password manager (more about that later), publish a list of the 200 most common passwords every year, along with an estimate of how long it would take a regular hacker to crack them. You might not be surprised that perennial bad password favourite โ€œ123456โ€ was top for 2020, but you might be more surprised that โ€œashleyโ€, โ€œsunshineโ€ and โ€œjacket025โ€ all make the top 50. The vast majority of these simple, non-complex password would take less than a second to crack. 

So now we know what makes a weak password, what classifies as a secure password?โ€ฏ 

What makes a Strong Password?

Letโ€™s jump back to that scenario where youโ€™re sat at your computer raring to buy that cool new thing, and all that stands in your way is the creation of a new password. 

 Letโ€™s go through a few simple steps to get you quickly to a stronger password. 

Firstly, do not useโ€ฏyourโ€ฏnameโ€ฏor a family memberโ€™s name (such as the โ€œAshleyโ€ mentioned above). You may think this seems unrelated to you (in a data sense anyway), but with reams of data floating around the dark web, itโ€™s not always as hard as you would hope to connect the dots. 

Start by choosing a random word. Donโ€™t worry, thatโ€™s not your password, weโ€™re going to make it more secure! Letโ€™s, for the sake of this example, choose a simple word like:

house

The first layer of complexity to add to it is to mix up the cases.  Useโ€ฏupper andโ€ฏlower caseโ€ฏlettersโ€ฏmixed throughout the word. So letโ€™s look at that again now: 

HoUse 

Better, but still too simple. Letโ€™s add some numbers. However, we shouldnโ€™t just dump them on the end, like we saw in many of the Nordpass examples. Letโ€™s spread them throughout the word, and avoid using repeating or consecutive numbers. How does that look now? 

62HoUse7 

Getting better. Next letโ€™s add some special characters. These are the characters on your keyboard that arenโ€™t letters or numbers, such as @ or $. Letโ€™s sprinkle a few on: 

62HoU$e7 

What we could do here is to mix some numbersโ€ฏ&โ€ฏcharacters together.

62HoU$37 

Finally, we should be using a password of at least 8 characters, more if possible. The best way to achieve this is to start with a longer word, or even a whole phrase, and then apply the steps weโ€™ve just gone through. 

Oh, and one final thing, never reuse passwords across different accounts. 

I know what youโ€™re thinking. If my password is so complex now, why canโ€™t I reuse it? 

Well, letโ€™s find out. 

Why shouldnโ€™t you reuse passwords?

Unfortunately, even the most complex passwords arenโ€™t immune to theft.โ€ฏ 

Yourโ€ฏpasswords could still be leaked to hackers if theโ€ฏwebsite whichโ€ฏyour account isโ€ฏwithโ€ฏis hacked itself and user details stolen.โ€ฏEven web giants like eBay and Adobe have suffered breaches in which almost their entire account lists where leaked. 

If this happens, evenโ€ฏthe mostโ€ฏsecure password could be compromised and leaked on to the dark web for cybercriminals toโ€ฏfind and use.โ€ฏ 

If this is theโ€ฏcase, the cybercriminals can use that password to access your other accountsโ€ฏusing the same details.โ€ฏ And ifโ€ฏthatโ€ฏpassword is reused with your email providerโ€ฆโ€ฏthen hackers instantlyโ€ฏhave the ability toโ€ฏfind which other account are linked to that email address. From there they can resetโ€ฏallโ€ฏofโ€ฏyour passwords by using the password reset feature for many popular websites. 

By using new unique passwordsโ€ฏfor every account ensures that all yourโ€ฏaccountsโ€ฏare willโ€ฏstay more secure.โ€ฏ 

But,โ€ฏif, like me, you have more than 400 accounts, or at least 100 like the average person does, how on earth can you keep track of them all?โ€ฏ 

Using Password Managers to securely store your passwords.

Password Managers allow you to store your passwordsโ€ฏsecurely and allow you to access your stored passwords from anywhere via a Mobile App, Computer App orโ€ฏWeb Browserโ€ฏ 

Someโ€ฏpassword managers,โ€ฏsuch as 1PasswordMyGlue and LastPassโ€™s Business plan even allow you to store Two Factor Authentication codesโ€ฏagainst password records. This helps you to keep your accountsโ€ฏevenโ€ฏmore secureโ€ฏand gives you easy access to all the information you will need to log in securely to your accounts. Just remember to use a unique password forโ€ฏyourโ€ฏPassword Manager.โ€ฏ 

To learn more about Two Factor Authentication (2FA) take a look at our What if Two Factor Authentication video. 

Passwords stored in password managers are usually secured behind 256-bit AES encryption, which is one of the most reliable and widely used encryption algorithm techniques. This ensures that, without a decryption key, your passwords would be almost impossible to view as plain text. 

Most Password Managers also offer unique password generation functions to allow you to create new, random and highly-secure passwords every time you create a new online account. 

Some,โ€ฏsuch as 1Password, also require you to create a security key of more than 30 characters as well as your email and password, for an extra level of unguessable security. Some even offer the ability to unlock with an authentication code on top of this! 

 This might seem like replacing one problem with another, but itโ€™s still a lot easier to remember a password, 30-character key and numerical PIN than it is to remember 100 unique passwords! 

If youโ€™d like to know more about Passwordโ€ฏManagers leave us a comment and we might cover this in a future Techsplained. 

What else can I do to stay safe online?

Creating complex and unique passwords really does help protect you against some of the most common online attack types, like password-guessing attacks where computers are uses to guess thousands of passwords a minute. 

Unfortunately, even with the most secure passwords in the world, websites still get hacked, and when this happens stolen account information is often released on the dark web where it can be bought and used by other hackers in targeted attacks. 

If you could find out when your account details appear on the dark web, then youโ€™d be able to change your password and make your account secure once again. 

And, thankfully, you can! 

Here at One2Callโ€ฏwoffer anโ€ฏactive Dark Web Monitoringโ€ฏservice which scans to see if your account information has been leaked on the dark web. As soon as we spot details related to your email address or web domain, weโ€™ll let you know, and weโ€™ll also offer advise on how to stop your accounts from being leaked in future. 

You can learn more about our Dark Web Monitoring service here. 

Alternatively, use the contact form below to arrange time with our consultants during which they can give you advice about theโ€ฏservicesโ€ฏwe offer to protect your business.โ€ฏMention this article for a freeโ€ฏone-offโ€ฏ Dark Web Reportโ€ฏfor your businessโ€ฏdomain 

Move to One2Call manage for your IT Support and your Microsoft Office 365 andโ€ฏwe can also implementโ€ฏpassword policies for your business to enforce strong passwords andโ€ฏfor themโ€ฏto be reset on a regular basis.โ€ฏโ€ฏ 

When combined with active dark web monitoring we can temporarily disable accounts that show up on the dark web to protect you and your business from potential attacks.โ€ฏ 

For more info on email security take a look at our email security pages. 

Weโ€™ll also be producing more content on this and other tech topics in future, so be sure to subscribe to our socials and subscribe to Techsplained and TechBytes to be the first to know about future content. 

                             

We hope you have found this information useful. Leave us a comment over on our YouTube Channel to let us know what you think or to ask a question. 

FREE Business Dark Web Scan

By clicking "submit", you agree to One2Callโ€™s Terms of Use as detailed in their Privacy Policy (www.one2call.net/privacy). You consent to receive emails, phone calls and/or SMS messages from One2Call in relation to your enquiry or order, and for marketing purposes upon opt in. Message frequency depends on your activity. You may opt-out by texting "STOP" to any SMS sent from One2Call or by clicking โ€œUnsubscribeโ€ on any marketing email sent by One2Call. Message and data rates may apply for any SMS sent.

Testimonials

Tracy Lilley, Ecclesfield Primary School

Responsive, friendly service. Very customer focused, polite and eager to help. Would definitely recommend and will use again.

Mick, MS International

Easy to get hold of and down to earth.

Rob Watt, Straaltechniek

Quick and easy. Pawel always great to deal with.