What If The Answer To A Secure Password Is Not Actually A Password?

We seem to be forever hearing about various cyber breaches these days, millions of email addresses dumped here, thousands of individuals’ personal information compromised there, the list goes on.

Yet, despite the apparent sophistication of many cyber attacks reported by the media, a significant number of these occur for a very simple reason – weak user passwords. We are constantly told to choose a ‘secure’ password and can be given a (somewhat extensive) list of requirements. The problem with this approach? Although these are generally more secure than the likes of ‘password’, ‘Titanic’ or even ‘Titanic12’, we simply can’t remember them.

As awareness around this area of cyber security increases, people do seem to be generally becoming more conscious of the importance of choosing stronger passwords. However, one aspect that causes a lot of confusion is that people are given different advice by different people. Consumers and businesses are left wondering who to believe and what in fact is the best approach to choosing passwords that are both complex and memorable? What does constitute a ‘secure’ password?

Password vs passphrase

passphrase is a short sentence consisting of multiple words. By creating short sentences, people are not forced into having to remember lower-case here, upper-case there, substituted letters for numbers etc. By creating a passphrase, you’re creating a token for keeping your sensitive information secure (at least to a point) that ticks two of the boxes for an ideal password – length and memorability. The additional length makes it exponentially more complex, and therefore vastly more time-consuming for a hacker to access the plaintext value and use it for malicious purposes.

However, as effective as this is, it’s not completely fool proof for two reasons: phrases or sentences still have to be remembered, and not all websites and apps support them. I’ve found it rather surprising that many websites I’ve penetration tested don’t allow spaces in passwords. In these cases, I’ve simply used hyphens or underscores as a substitute, which, although not recommended, is an improvement over simple passwords.

Click to view all articles for the EPIC:
Or click to view the full company profile:
Facebook
Twitter
LinkedIn
Falanx Cyber Security

More articles like this

Falanx Cyber Security

Ethical Phishing

Are your staff prepared for cyber attacks that are designed to coax sensitive information from them? Let us find out. Phishing is more prevalent than ever and becoming increasingly more sophisticated. We can help you minimise

Falanx Cyber Security

Why do I need Continuous Vulnerability Scanning (CVS)?

In 2021, the US-CERT Vulnerability database recorded 18376 vulnerabilities. That’s an average of more than 50 common vulnerabilities and exposures (CVEs) per day. With cyber criminals constantly scanning the internet looking for CVEs to exploit, if

Falanx Cyber Security

Does accountancy have a cybersecurity blind spot?

Leading ethical hacker Rob Shapland joins the AccountingWEB podcast to explain why cybercriminals are targeting the profession and what accountants can do to stop them. With recent hacks on high-profile accounting firms making headlines and the current geopolitical

Falanx Cyber Security

Loan security and Cyber security

Are proper cybersecurity measures on your investment checklist? Cybercriminals are attracted to money, which is why wherever there are investments and growth, the hackers are there doing everything they can to find a way in. This

Falanx Cyber Security

Cybersecurity risks in the rail sector

The level of cybercrime continues to grow at an unprecedented rate in the UK and across the globe, with UK Government figures showing that nearly 40% of businesses surveyed had suffered cyber security breaches or attacks

Falanx Cyber Security

Why many UK businesses still aren’t cyber ready

Recent UK government research shows that just under half of all businesses aren’t seeking advice on cyber security threats While 69% of businesses in the financial sector sought advice in the last 12 months, a quarter

Falanx Cyber Security

Global food supply chain at risk from malicious hackers

Modern “smart” farm machinery is vulnerable to malicious hackers, leaving global supply chains exposed to risk, experts are warning. It is feared hackers could exploit flaws in agricultural hardware used to plant and harvest crops. Agricultural

Falanx Cyber Security

Lack of skills is the number one issue in cybersecurity

Lack of skills is the number one issue in the cybersecurity industry, according to Andrew Elliot, deputy director, cyber security innovation and skills at the Department for Digital, Culture, Media and Sport (DCMS), speaking during the Secure

Falanx Cyber Security

Falanx Group develop partnership to provide M-EDR to UK customers

Falanx Group Limited (LON:FLX), the AIM listed cyber security business, has today announced that ESET, Grove and Falanx Cyber are working together to promote Managed-Endpoint Detection and Response (M-EDR) solutions and services to customers across the region.

Falanx Cyber Security

Cyber: a growing UK boardroom priority

Cybersecurity is a growing priority for company directors in the UK but that may not be translating into improvements in their business’ cyber resilience, according to a new study. The results of the UK government’s cybersecurity breaches

Falanx Cyber Security

Business unity is essential to beat cyber attacks

In the spring of 2021, America’s Colonial Pipeline – the 5,500-mile fuel superhighway, which supplies half the East Coast’s petrol and diesel – abruptly shut down for six days. The cause was a cyber-attack, launched by