Securing your password

December 14, 2010 06:55 pm | Updated November 28, 2021 09:43 pm IST - London

Don’t have a multipurpose password, have different passwords for different online accounts.

Don’t have a multipurpose password, have different passwords for different online accounts.

Red faces at the U.S. gossip site Gawker: last weekend hackers hijacked the front page and released the usernames, e-mail addresses and encrypted passwords of 1.3 million registered users of Gawker and its affiliated sites.

They also decrypted 200,000 of the least secure passwords. So anyone could see not just the relatively simple password used by Gawker’s founder, Nick Denton — but the fact that he used the same one for other online accounts, including e-mail, Twitter and Gawker’s internal messaging system.

“More than 3,000 Gawker users chose ‘123456’ as their password,” says Michael Brunton-Spall, from the web team at the Guardian. “But lots of people used just one simple word — ‘starwars’, say, or ‘princess’ ‘Letmein’ was quite high up the list. And ‘trustno1’, which was Fox Mulder’s password in The X Files, was popular too.”

Bad mistake. “If you use the same insecure password for everything, you’re laying yourself open,” Brunton-Spall says. “Already Gawker users are complaining that their Twitter accounts have been hijacked. That’s embarrassing. But imagine if they were using the same password for their online bank.”

So here are Brunton-Spall’s top password tips. First, make it secure: two random words, preceded or separated by a number, make a memorable, hard-to-crack password (most people add a number at the end, making it much easier to hack). An alternative is to use the initial letters of the words that make up a favourite saying or song lyric — again, preceded or separated by a number.

Second, don’t have a multipurpose password. On the grounds that no one could remember an entirely different password for every site, you could try having three basic passwords — one for things financial, one for things professional, one for things social. Then you could drop in two letters from the name of the specific site: if, say, your basic social media password was shock7asset, your Facebook password might be fshock7basset. Or your Twitter one might be tshock6assetr. Easy, really.

0 / 0
Sign in to unlock member-only benefits!
  • Access 10 free stories every month
  • Save stories to read later
  • Access to comment on every story
  • Sign-up/manage your newsletter subscriptions with a single click
  • Get notified by email for early access to discounts & offers on our products
Sign in

Comments

Comments have to be in English, and in full sentences. They cannot be abusive or personal. Please abide by our community guidelines for posting your comments.

We have migrated to a new commenting platform. If you are already a registered user of The Hindu and logged in, you may continue to engage with our articles. If you do not have an account please register and login to post comments. Users can access their older comments by logging into their accounts on Vuukle.