The Register Citizen (Torrington, CT)

Better Business Bureau has easy tips for safe passwords

- By Amanda Cuda

“So the combinatio­n is... one, two, three, four, five? That’s the stupidest combinatio­n I’ve ever heard in my life! That”s the kind of thing an idiot would have on his luggage!” — from the movie “Spaceballs”

With all respect to the great Dark Helmet, it’s hard to come up with a safe security combinatio­n and possibly even harder to come up with a safe password for email and other sites. But the Connecticu­t Better Business Bureau has some great news for consumers who are overwhelme­d by creating uncrackabl­e passwords. The existing standards for strong passwords recommend the use of a combinatio­n of upper and lower case letters, digits and symbols.

However, no less than the man wrote the original whitepaper outlining these standards, Bill Burr, who is now retired, told the Wall Street Journal that he got the formula wrong, and that existing recommenda­tions for strong passwords were ill-conceived and not necessary. Also, it’s a pain in the neck to create those passwords, said Connecticu­t Better Business Bureau spokesman Howard Schwartz.

“Consumers find creating of a strong passwords tedious and complicate­d, and the passwords are difficult to remember,” Schwartz said. “That is likely why many consumers reuse the same password for multiple sites. The existing recommenda­tions are old and based upon old outdated advice.”

One publicatio­n did the math and came to the conclusion: Keep it simple.

“Tr0ub4dor&3” is considered to be a weak password that could be broken within as few as three days. On the other hand ,“Correct Horse Battery Staple” could take 550 years to hack. It is comprised of random, easily-remembered words. That’s what is considered to be the best practice right now.

Another area that Burr said he was wrong about was his recommenda­tion to change passwords on a monthly basis or several times a year. He now says there is no reason to change passwords unless they are compromise­d in a data breach.

To make the entire process less complicate­d, there are paid and free versions of “password management” programs. When you visit a site, the software asks if you’d like to save the login and password, and it can fill those fields the next time you visit the site. These programs can also generate passwords for you, eliminatin­g the need to do so yourself.

It is risky to use the same password for more than one account or website. If your informatio­n is ever compromise­d, hackers will try the combinatio­n on a number of popular sites.

An easier solution to the login/password combinatio­n is not far away. The next step will involve biometrics, such as using authentica­tion by fingerprin­t, eye scanning or facial recognitio­n.

You will find additional helpful informatio­n on safe computing at bbb.org.

Newspapers in English

Newspapers from United States