Chattanooga Times Free Press

How often should you change your passwords?

-

Q Internet security and change of passwords; how often does BBB suggest passwords be changed?

A. Good question and requires serious considerat­ion. When was the last time you reviewed the passwords to your bank or credit card accounts, email or social media accounts? A year ago? Five years ago? Does it matter? Honestly yes, but there is also such a thing as changing them too often.

Passwords should be changed if they are all the same, if they are too easy to guess, or if they are forgotten or compromise­d. However, changing your passwords too often isn’t a great idea either because they can easily be forgotten. Even the Federal Trade Commission admits that people don’t need to change their passwords as often as they think.

BBB is here to tell consumers what makes a good password and why using multiple passwords is important.

THINK OF YOUR PASSWORDS AS WALLS

Think of passwords like a wall between free access to your personal informatio­n and the world. If you put up a strong wall, it will be difficult for others to break down. If you put up multiple strong walls for different informatio­n, they will be even harder to break down. But if you only put up one weak wall, anyone can break it down.

DON’T MAKE YOUR PASSWORDS EASY TO GUESS

An example of a weak password is one that is easy to guess - informatio­n that anyone can find. A strong password has at least twelve characters, mixed with uppercase and lowercase letters, numbers and symbols.

Commonly used passwords are your pet’s name, your mother’s maiden name, the town you grew up in, your birthday, your anniversar­y, etc. Surprising­ly, the answers to these common passwords can typically be found online. Even if you don’t consider yourself an active user of social media or the Internet, your informatio­n is out there on one forum or another. Even for passwords that require numbers along with letters, people tend to stick to simple patterns like 0000, 1111, 1234, etc.

MAKE THEM CREATIVE

Running low on creative ideas for different passwords? Try using song lyrics. Not only is it basically impossible for hackers to guess what song you are using, it’s even harder for them to guess which lyrics you’re using on top of that.

USE A “PASSPHRASE”

Instead of using a single word, use a passphrase. Your phrase should be relatively long, around 20 characters, and include random words, numbers and symbols. Use something that you will be able to remember but others could not guess; such as PurpleMilk#367JeepDog$.

Use multiple passwords. Using different passwords for different accounts is also important. While it may be easier to remember one password for every account, it’s much easier for hackers to break down one wall rather than multiple walls. If hackers can figure out one password, even if it’s to something harmless like your Instagram account, they then know the password to every single account you own. This includes websites where you shop online, banking accounts, health insurance accounts, email accounts you name it.

USE MULTI-FACTOR AUTHENTICA­TION

When it’s available and supported by accounts, use two-factor authentica­tion. This requires both your password and an additional piece of informatio­n when logging in. The second piece is generally a code sent to your phone, or a random number generated by an app or token. This will protect your account even if your password is compromise­d.

CONSIDER A PASSWORD MANAGER

A written list would be best, but if you’re worried of losing it, write a list on your phone and label it as something other than ‘PASSWORDS’. Keep the list updated, organized and secretive.

Still not convinced? Consider a reputable password manager to store your informatio­n. These easy-to-access apps store all your password informatio­n and security question answers in case you ever forget. However, don’t forget to use a strong password to secure the informatio­n within your password manager.

SELECT SECURITY QUESTIONS ONLY YOU KNOW THE ANSWER TO

Many security questions ask for answers to informatio­n available in public records or online, like your zip code, mother’s maiden name, and birth place. That is informatio­n a motivated attacker can easily obtain. Don’t use questions with a limited number of responses that attackers can easily guess - like the color of your first car.

If you received notificati­on from a company about a possible breach, it is always best practice to change that password and any similar passwords immediatel­y.

Jim Winsett is president of the Better Business Bureau in Chattanoog­a

 ??  ?? Jim Winsett
Jim Winsett

Newspapers in English

Newspapers from United States