Advertisement

We need your help now

Support from readers like you keeps The Journal open.

You are visiting us because we have something you value. Independent, unbiased news that tells the truth. Advertising revenue goes some way to support our mission, but this year it has not been enough.

If you've seen value in our reporting, please contribute what you can, so we can continue to produce accurate and meaningful journalism. For everyone who needs it.

Shutterstock/Skylines

You know the advice about changing passwords often? You're likely doing it wrong

We’re not exactly great at coming up with new and original passwords.

WHEN IT COMES to password security, you’re sometimes told to change your password regularly so your account is safe from anyone who tries to access it.

The logic is as follows. If you’re changing it regularly, then it’s harder to guess what your password is and therefore harder to access your account.

It turns out it’s a flawed idea according to one security expert, the US Federal Trade Commission’s chief technologist Lorrie Cranor, who confirmed it at a security conference in Las Vegas recently.

The problem with this advice is it assumes you’ll change your password completely. Most people won’t go to that effort. Instead, they’ll just change a character in their old password.

They might replace a small character with a capital letter, or just add an extra letter or number to the end. Instead of a new password, they are using a slightly modified version of an old password.

“The UNC (University of North Carolina) researchers said if people have to change their passwords every 90 days, they tend to use a pattern and they do what we call a transformation,” Cranor said at the event. “They take their old passwords, they change it in some small way and they come up with a new password.”

The research she’s referring to a UNC study from 2010 which looked at 10,000 expired accounts from employees or students who were required to change their passwords every three months (they obtained the cryptographic hashes which protect these accounts).

The data included the last password used and passwords that changed over time. One of the most common patterns they found was how how often people would just change or add a character to their existing password.

These slight changes are what hackers and other bad actors rely on as they’re easy to guess. Developing a program which automatically guesses the most common passwords is usually one way for someone to gain access to accounts.

That’s not to say you shouldn’t change your password ever, but the aim is to make it long and random. Also, if you’re reusing the same one for different sites – which is a terrible idea – you should change that immediately. Using a password manager to help remember complex passwords is one of the best ways of solving this.

Read: Another major security flaw has been discovered on Android phones >

Read: Want to try out new phone features before anyone else? Sign up for beta testing >

Readers like you are keeping these stories free for everyone...
A mix of advertising and supporting contributions helps keep paywalls away from valuable information like this article. Over 5,000 readers like you have already stepped up and support us with a monthly payment or a once-off donation.

Close
6 Comments
    Install the app to use these features.
    Mute Alan Hanley
    Favourite Alan Hanley
    Report
    Aug 8th 2016, 4:01 PM

    Password…. password1…. password12…. password123…

    36
    Install the app to use these features.
    Mute Just Himself
    Favourite Just Himself
    Report
    Aug 8th 2016, 4:05 PM

    The logic behind changing passwords every 90 days isn’t because it make it more difficult to guess, it’s so that if your password becomes compromised there is a limited window for when it’s effective. The idea behind it being 8 characters long and 90 days maximum age was that (at the time) computational power to guess an 8 character password, either through brute force or attacking a hash, didn’t really exist to break it within 90 days so even if someone was trying guess your credentials they couldn’t within the window that the password was valid. At the end of the 90 day period they would need to restart from scratch. The problem with this line of thinking is that it’s 20 years old now and technology has overtaken it. We need longer passphrases rather than passwords and we should have the expire less frequently, maybe once a year. Encouraging people to make unique passphrases which are easier to remember. Also consider the fact that biometrics are not the solution to all password solutions, it’s not suitable for all types of accounts and where possible utilise two factor authentication (2FA), 2FA helps defeat a massive amount of attack scenarios.

    34
    Install the app to use these features.
    Mute Elma Phudd
    Favourite Elma Phudd
    Report
    Aug 8th 2016, 6:44 PM

    Sorry, too much sense there. Please find another forum for sense. Journal is here for people to spout complete gibberish and call each other names.

    36
    Install the app to use these features.
    Mute Jim Redmond
    Favourite Jim Redmond
    Report
    Aug 8th 2016, 6:08 PM

    Try LastPass…

    4
    Install the app to use these features.
    Mute casey
    Favourite casey
    Report
    Aug 8th 2016, 4:40 PM

    The amount of times I had to bring my laptop to the PC doctor because I couldn’t remember my password. Not changing it again, this one I will remember plus it’s such a weird password I doubt that anyone would guess it.

    2
Submit a report
Please help us understand how this comment violates our community guidelines.
Thank you for the feedback
Your feedback has been sent to our team for review.
JournalTv
News in 60 seconds