The Oklahoman

Change your password

Though Twitter says there’s no indication of stolen or misused passwords, the company is recommendi­ng users change theirs as a precaution.

- AP Technology Writer BY ANICK JESDANUN

Yet another service is asking you to change your password.

Twitter said Thursday that it discovered a bug that was storing passwords in an internal log in plain text, without the usual encryption.

Though Twitter says there's no indication that anyone has stolen or misused those passwords, the company is recommendi­ng a change as a precaution.

Here are some tips on coming up with a new password and safeguardi­ng your account — even if your password is compromise­d.

Complexity counts

Don't even think of using "password" as your password. Picking any common word as your password should be avoided because it's easily guessed using software that tries out every word in the dictionary.

However, you can get a good password by combining two or more words, such as "rocketcale­ndar." Sprinkle in some numerals and punctuatio­n marks, and make some of those letters in caps, and you've got a strong password. So "rocketcale­ndar" becomes "rocket44!calendaR." (But don't use that one; the fact that it's in this article means hackers probably already have it in their databases.)

Some services will even require your passwords to have certain characteri­stics. As you type a new password on Twitter, the service will tell you whether it's "Too Obvious" or "Weak." Go for "Very Strong."

Keep passwords fresh

Each service should have its own password. If you use "rocket44!calendaR" on Twitter, don't use it on Facebook. Once hackers get your password on one service, they'll try it on other services, too. Outsmart them by using a fresh password each time. It can be as simple as adding the first three letters of the service's name, so Twitter gets "rocket44!calendaRtw­i" and Facebook gets "rocket44!calendaRfa­c."

You can turn to a password-manager service to help you keep track of various passwords, though make sure the one you use hasn't had its own security problems. If you're storing passwords in a spreadshee­t or other document on your computer, be sure to protect it with its own password (Microsoft Office lets you encrypt files). Avoid naming the file "passwords." Call it "badmovies" or something innocuous.

Reset and refresh

Some security experts recommend that you change your passwords frequently, though treat that advice with caution. When there's a breach, it doesn't matter whether that password is two weeks or two years old. And if you change passwords too often, you risk forgetting them and falling back on simpler, less-secure passwords.

A better safeguard

You can ignore much of this if you just do one thing: Turn on two-factor authentica­tion, which Twitter calls "login verificati­on." You'll get a text with a code each time you try to log in from a new device or browser.

 ??  ??
 ?? [AP FILE PHOTO] ?? Twitter says it discovered a bug that stored passwords in an internal log in an unprotecte­d form.
[AP FILE PHOTO] Twitter says it discovered a bug that stored passwords in an internal log in an unprotecte­d form.

Newspapers in English

Newspapers from United States