« Allen County Public Library and WeRelate.org Announce Partnership | Main | Ancestry.com Adds the United States-Canadian Border Crossings Collection »

March 27, 2007

Comments

Feed You can follow this conversation by subscribing to the comment feed for this post.

Infinite Ancestors

I'd avoid simple combinations of basic personal information, as these bits of easily-gathered information can be a great head start to a hacker's dictionary.

Lifehacker just had an article today pointing to some good password tips:

http://www.lifehacker.com/software/passwords/how-passwords-get-cracked-247355.php

An excellent in-depth resource is a January 11th article by Bruce Schneier, "Choosing Secure Passwords":

http://www.schneier.com/blog/archives/2007/01/choosing_secure.html

Paul K. Graham

I like that trick about using the first letters of words in a sentence. That's a great idea. One thing I do is mix upper and lowercase letters, which adds an extra layer of complexity.

Norman B North

A password like "23october1892" is more cryptic than a lot of passwords, but still uses a word than can be found in any dictionary. This makes the password more difficult to crack, but not as difficult as it could be.

I like to mix characters like "$", "&", "@" among my other characters, although some web sites cannot accommodate such symbols.

Another approach is to use a password manager that is capable of generating a hard-to-guess series of alphanumeric characters. RoboForm is one of these. It is capable of generating pseudorandom passwords nearly as long as one wishes to create (like 25 or more), and to remember them in an encrypted password file that uses one unique password of its own that can be remembered.

Marilyn

I use the name of the thing I was doing when I first went into the site and substitute 1 for i,or 0 for o, and put capital letters if it is a place. eg flight to Warsaw , Poland, the password might me P0land. I've also used whole phrases eg haveag00dtime for a holiday site.

Paul Smith

Every password you use should be unique. In other words, you should use a different password on every site on which you register. Roboform, mentioned earlier, is the ONLY way to do this effectively and efficiently without having to remember tons of information.

Additional thoughts:

1. Mix capital and lowercase letters.

2. Do NOT use the @ sign. It makes your password look like an email address which can be trying at times especially when pasted into a spreadsheet (see #2). Everything else is good if the web site will accept it.

3. Use the longest password the site will accept. Some limit to 15 characters while others will let you use 35 or more. Take advantage of every character.

4. I copy every Roboform generated password into an excel spreadsheet along with the URL and the login name (they aren't always the same) and I keep that spreadsheet in encrypted form on both my computers and a USB memory key which is always in my pocket. Since I work from home, I keep a fourth copy on my son's system in California (offsite in case of disaster (along with my genealogy database, financial records, etc.)).

Ernst Stjernberg

I think the internet has gone password crazy ! I know that a lot of sites need to have a registration process to avoid spammers - which has happened several times on a genealogy forum I frequent. But,do you really need an industrial strength password to register at a site to get a newsletter? I don't think so and I have one simple password for many such sites that do not involve any financial transactions. I don't think many hackers are interested in my newsletter subscriptions. I do agree that for banks and other such sites, it makes sense to have a good password and I use many of the suggestions given in previous comments. However, lets keep password use in perspective and don't go overboard where there is no need.

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been saved. Comments are moderated and will not appear until approved by the author. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment

Comments are moderated, and will not appear until the author has approved them.

Receive FREE daily newsletter updates by email

  • Enter your email address


    Click here to see a typical e-mail message you will receive.

    I promise that:

    1. I will never sell, rent, or give away your address to any outside party, ever;
    2. I will never send you any unrequested e-mail, besides newsletter updates; and
    3. All unsubscribe requests are honored immediately, period.

My Photo

Search This Site for Past Articles

Meet Dick Eastman in Person

November 2009

Sun Mon Tue Wed Thu Fri Sat
1 2 3 4 5 6 7
8 9 10 11 12 13 14
15 16 17 18 19 20 21
22 23 24 25 26 27 28
29 30          

Amazon Kindle

Offers

Blog powered by TypePad

Amazon Picks

Receive daily newsletter updates by email

  • Enter your Email


    Preview

    (Don't worry, I hate spam as much as you do and you will be able to UNSUBSCRIBE within seconds at any time!)