Fun With Passwords
Every six months or so we like to lay upon you the benefits of using secure passwords. And every six months or so, we know our advice is falling on deaf ears. But we’re nothing if not intrepid.
Today, we’re going to have fun with passwords. So even if you don’t take our warnings about using secure passwords seriously, you’ll have fun with this password-o-meter we are about to let you feast your eyes upon.
We’re doing to intro the site first and then we’re going to show you some examples; a show and tell kind of thing.
The site is called My1Login.com. On the site there’s a password-o-meter (we made that word up – phrase up?) with which you can test the strength of your passwords. It will show you how long it would take to crack you passwords using the standard hacker tools that guess billions of combinations a second – and yours might be one of those combinations, especially if it is a weak password.
Here’s what the folks at My1Login have to say about Passwords – my their words not fall upon blind eyes:
Is it actually safe to use Password Checkers?
If you’re reading this section, then good – the quickest way to get hacked online is to be too trusting or assume websites are automatically safe. It’s good to be cautious and it’s never a good idea to enter your legitimate credentials into any website you are not confident about. The ones to watch especially are those who ask you to input your credentials.
So, why is this Password Strength Meter safe?
The passwords you type never leave your browser and we don’t store them (You can disconnect your internet connection and then try it if you wish)
All the checking is done on the page you’re on, not on our servers
Even if the password was sent to us, we wouldn’t actually know who you were anyway – so couldn’t match it up to any usernames or any websites you may visit
We’re in the business of making people more secure online and the last thing we want to see is passwords being transmitted across the internet insecurely.
How does My1Login’s Password Strength Checker work?
The password strength calculator uses a variety of techniques to check how strong a password is. It uses common password dictionaries, regular dictionaries, first name and last name dictionaries and others. It also performs substitution attacks on these common words and names, replacing letters with numbers and symbols – for example it’ll replace A’s with 4’s and @’s, E’s with 3’s, I’s with 1’s and !’s and many more. Substitution is very typical by people who think they’re making passwords stronger – hackers know this though so it’s one of the first things hacking software uses to crack a password
The password strength meter checks for sequences of characters being used such as “12345” or “67890”
It even checks for proximity of characters on the keyboard such as “qwert” or “asdf”.
Common mistakes and misconceptions
Replacing letters with digits and symbols. This technique is well known to hackers so swapping an “E” for a “3” or a “5” for a “$” doesn’t make you much more secure
That meeting the minimum requirements for a password makes it strong. By today’s standards, an 8-character password won’t make you very secure
That it’s fine to use the same password a lot as long as it’s strong – what if the website is hacked? Do you know how the website stores your password? What if they store it in plaintext?
Weak practices – storing passwords in the notes field on your phone, does it auto sync to the cloud, iCloud or Dropbox.
Putting them in a spreadsheet, even password protecting a spreadsheet doesn’t keep the information safe. Check out our blog on this and other security subjects. https://blog.my1login.com/
What makes a strong password?
A strong password is one that’s either not easily guessed or not easily brute forced. To make it not easily guessed it can’t be a simple word, to make it not easily cracked it needs to be long and complex. Super computers can go through billions of attempts per second to guess a password. Try to make your passwords a minimum of 14 characters.
A passphrase is simply a password, that’s longer, it could be a sentence, with spaces and punctuation in it. The benefit of a passphrase is that typically they’re easier to remember, but more difficult to crack due to their length. For every additional character in the length of a password or passphrase, the time it would take to break increases exponentially. Ultimately that means that having a long password or passphrase can make you far more secure than having a short one with some symbols or numbers in it.
Now for the fun:
Above, we generated a 15-character password using the password generator in LastPass. I don’t even think EB will still be around 73 trillion years ago. It the box at the top we’re showing you the password because we could not care less. It’s not our password.
But let’s just say you’re the fussy type and you don’t think 73 trillion years is good enough – you’re the kind that always wants bigger, better, newer, etc. You are the key who always wants more. How about 509 billion trillion years? As you can see it’s a pass phrase that I can actually remember as long as I remember EB was born in 1906.
Above you can see a password that would only take a hacker 27.08 seconds to crack. And we’ll bet you that someone reading this has a very similar password and they use that password on more than one site. Is it YOU?
OK now let’s go to extreme.Do you think hackers will be around six trillion trillion years from now? Don’t think so! As you can see all I did was take a line from a Beatles’s song and put dollar signs at each end. That’s called a passphrase…and it’s something I can remember – even hum or sing to myself…or if you like, call me and I’ll sing it to you. Rock on, Paul.
Are you ready to have fun testing your passwords and experimenting with very secure yet easy to remember passphrases. OK you can test your passwords by heading to this page .
Oh, yes, and one more thing, they offer a free password manager too. If you don’t have one, you need one. There is no way the average human brain can remember different passwords for dozens of Web sites – especially long strong ones. Yes, EB? Perhaps there are savants out there who can, that’s true. Yes, EB, maybe even Las Vegas card counters. But that’s not most of us, you know!